AngularJS是一款基于TypeScript的开源Web应用程序框架。 AngularJS 1.7.0 版本及以上版本存在安全漏洞,该漏洞源于它提供了一个自定义的区域规则,可以在posPre中赋值参数,攻击者利用该漏洞可导致正则表达式拒绝服务攻击(ReDoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | angular | next of 1.7.0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-24437 | 9.8 CRITICAL | Command Injection |
| CVE-2022-25767 | 9.8 CRITICAL | Remote Code Execution |
| CVE-2022-23923 | 8.6 HIGH | Sandbox Bypass |
| CVE-2022-25301 | 7.7 HIGH | Prototype Pollution |
| CVE-2022-25647 | 7.7 HIGH | Deserialization of Untrusted Data |
| CVE-2022-21144 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-21227 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-21167 | 7.5 HIGH | Arbitrary Code Execution |
| CVE-2022-22143 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-25850 | 7.5 HIGH | Server-side Request Forgery (SSRF) |
| CVE-2022-21189 | 7.3 HIGH | Prototype Pollution |
| CVE-2022-25842 | 6.9 MEDIUM | Arbitrary File Write via Archive Extraction (Zip Slip) |
| CVE-2022-25645 | 6.5 MEDIUM | Prototype Pollution |
| CVE-2022-26068 | 6.5 MEDIUM | Path Traversal |
| CVE-2022-21230 | 5.5 MEDIUM | Information Exposure |
| CVE-2022-21149 | 5.4 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2022-25349 | 5.4 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2022-29849 | Progress OpenEdge权限许可和访问控制问题漏洞 | |
| CVE-2022-28481 | CSV-Safe gem 安全漏洞 | |
| CVE-2021-31674 | Cyclos 4 PRO 跨站脚本漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet