Exposição de Angular

JavaScript frameworks
42
score de exposição
118.464
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades do Angular soma 30 CVEs catalogadas, com zero registros de exploração ativa no catálogo KEV da CISA, taxa abaixo da média geral do catálogo. Não há falhas de severidade crítica no conjunto, e o maior valor EPSS observado é de aproximadamente 0,053, indicando probabilidade de exploração relativamente baixa em todo o portfólio. O ponto de atenção mais relevante é a concentração de falhas do tipo CWE-79 (Cross-Site Scripting), padrão dominante na base, e o volume expressivo de 18 CVEs surgidas nos últimos 90 dias, o que sugere um ciclo recente de descobertas que demanda acompanhamento próximo. A CVE mais perigosa atualmente identificada é a CVE-2022-25869, com EPSS de 0,0528, reforçando que, apesar da ausência de exploração confirmada, equipes que mantêm versões desatualizadas do framework devem priorizar a aplicação dos patches disponíveis.

CVEs

38 resultados
CVE-2022-25869MEDIUMAll versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to CroEPSS 7.3%CVE-2022-25844MEDIUMRegular Expression Denial of Service (ReDoS)EPSS 4.9%CVE-2024-21490HIGHThis affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split thEPSS 1.9%CVE-2023-26116MEDIUMVersions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fuEPSS 1.7%CVE-2023-26117MEDIUMVersions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to tEPSS 1.7%CVE-2023-26118MEDIUMVersions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> elementEPSS 1.7%CVE-2021-4231LOWAngular Comment cross site scriptingEPSS 1.2%CVE-2026-88060HIGHAngular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content ElementsEPSS 0.7%CVE-2025-66035HIGHAngular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLsEPSS 0.7%CVE-2026-54268HIGHAngular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)EPSS 0.6%CVE-2026-50178HIGHAngular: Remote Code Execution via JSDoc Hover Command Injection in VS Code Angular Language Service ExtensionEPSS 0.5%CVE-2026-88058HIGHAngular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content ElementsEPSS 0.5%CVE-2026-27970HIGHAngular i18n vulnerable to Cross-Site Scripting (XSS)EPSS 0.5%CVE-2026-22610HIGHAngular has XSS Vulnerability via Unsanitized SVG Script AttributesEPSS 0.4%CVE-2026-88056HIGHAngular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSREPSS 0.4%CVE-2026-50170HIGHAngular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCacheEPSS 0.4%CVE-2025-66412HIGHAngular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML AttributesEPSS 0.4%CVE-2026-50556HIGHAngular: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSREPSS 0.4%CVE-2026-88057MEDIUMAngular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compilerEPSS 0.4%CVE-2026-52725MEDIUMAngular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)EPSS 0.4%