CVE-2026-54265
- EPSS 0.2%
- Veröffentlicht 22.06.2026 15:27:38
- Zuletzt bearbeitet 09.07.2026 15:39:01
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an issue in the @angular/compiler package allows bypassing DOM property sanitiz...
CVE-2026-50178
- EPSS 0.28%
- Veröffentlicht 22.06.2026 15:20:39
- Zuletzt bearbeitet 26.06.2026 02:57:57
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in c...
CVE-2026-52725
- EPSS 0.24%
- Veröffentlicht 22.06.2026 15:18:43
- Zuletzt bearbeitet 09.07.2026 15:38:38
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/core package allows bypassing script-exe...
CVE-2026-49241
- EPSS 0.16%
- Veröffentlicht 22.06.2026 15:16:14
- Zuletzt bearbeitet 26.06.2026 03:47:27
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension reads the custom TypeScript SDK paths typescript.tsdk and js/ts.tsdk....
CVE-2026-50557
- EPSS 0.2%
- Veröffentlicht 22.06.2026 15:11:48
- Zuletzt bearbeitet 09.07.2026 15:40:45
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22 and 19.2.22, an issue in the @angular/compiler and @angular/core packages allow...
CVE-2026-41423
- EPSS 0.31%
- Veröffentlicht 08.05.2026 13:06:59
- Zuletzt bearbeitet 12.05.2026 14:58:06
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Server-Side Request Forgery (SSRF) vulnerability exis...
CVE-2026-27970
- EPSS 0.47%
- Veröffentlicht 26.02.2026 02:03:43
- Zuletzt bearbeitet 15.07.2026 02:19:13
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular inter...
CVE-2026-22610
- EPSS 0.45%
- Veröffentlicht 10.01.2026 03:35:40
- Zuletzt bearbeitet 02.06.2026 14:16:45
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been ident...
CVE-2025-66412
- EPSS 0.4%
- Veröffentlicht 01.12.2025 22:35:59
- Zuletzt bearbeitet 02.06.2026 14:16:37
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the An...
CVE-2025-66035
- EPSS 0.65%
- Veröffentlicht 26.11.2025 22:18:35
- Zuletzt bearbeitet 02.06.2026 14:16:36
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HT...