CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-104871 MEDIUM

Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows

CVSS 6.3 EPSS n/a Oct 2, 2026
CVE-2026-88060 HIGH

Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements

CVSS 8.6 EPSS 0.36% Sep 10, 2026
npm
CVE-2026-88059 MEDIUM

Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`

CVSS 4.0 EPSS 0.34% Sep 10, 2026
npm
CVE-2026-88058 HIGH

Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements

CVSS 8.6 EPSS 0.28% Sep 10, 2026
npm
CVE-2026-88057 MEDIUM

Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler

CVSS 5.3 EPSS 0.26% Sep 10, 2026
npm
CVE-2026-88056 HIGH

Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR

CVSS 8.6 EPSS 0.54% Sep 10, 2026
npm
CVE-2026-69151 HIGH

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

CVSS 7.6 EPSS 0.33% Aug 3, 2026
npm
CVE-2026-69149 HIGH

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

CVSS 8.6 EPSS 0.35% Aug 3, 2026
npm
CVE-2026-68945 HIGH

Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning

CVSS 8.8 EPSS 0.18% Aug 3, 2026
npm
CVE-2026-50171 HIGH

Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)

CVSS 8.2 EPSS 0.26% Jun 22, 2026
npm
CVE-2026-50184 MEDIUM

Angular: Request Credential & Cache Policy Stripping in Angular Service Worker

CVSS 5.7 EPSS 0.21% Jun 22, 2026
npm
CVE-2026-50169 MEDIUM

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

CVSS 5.7 EPSS 0.23% Jun 22, 2026
npm
CVE-2026-46417 HIGH

Angular: SSRF via Hostname Hijacking in @angular/platform-server

CVSS 8.8 EPSS 0.36% Jun 22, 2026
npm
CVE-2026-50168 HIGH

Angular: URL Parser Differential in @angular/platform-server leading to SSRF Allowlist Bypass

CVSS 8.8 EPSS 0.24% Jun 22, 2026
npm
CVE-2026-50170 HIGH

Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache

CVSS 8.2 EPSS 0.43% Jun 22, 2026
npm
CVE-2026-50556 HIGH

Angular: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR

CVSS 8.6 EPSS 0.41% Jun 22, 2026
npm
CVE-2026-50555 HIGH

Angular: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in @angular/platform-server

CVSS 8.6 EPSS 0.27% Jun 22, 2026
npm
CVE-2026-54264 HIGH

Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker

CVSS 8.3 EPSS 0.39% Jun 22, 2026
npm
CVE-2026-54268 HIGH

Angular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)

CVSS 8.2 EPSS 0.58% Jun 22, 2026
npm
CVE-2026-54267 HIGH

Angular Client Hydration DOM Clobbering & Response-Cache Poisoning

CVSS 8.6 EPSS 0.32% Jun 22, 2026
npm
CVE-2026-54266 HIGH

Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

CVSS 8.8 EPSS 0.13% Jun 22, 2026
npm
CVE-2026-54265 MEDIUM

Angular: Two-Way Property Binding Sanitization Bypass (XSS)

CVSS 5.3 EPSS 0.34% Jun 22, 2026
npm
CVE-2026-50178 HIGH

Angular: Remote Code Execution via JSDoc Hover Command Injection in VS Code Angular Language Service Extension

CVSS 8.7 EPSS 0.50% Jun 22, 2026
CVE-2026-52725 MEDIUM

Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)

CVSS 5.3 EPSS 0.40% Jun 22, 2026
npm
CVE-2026-49241 HIGH

Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code Extension

CVSS 8.7 EPSS 0.24% Jun 22, 2026

Showing 1 to 25 CVEs · page 1 (more available)