Filtered by vendor Ag-grid Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-16009 2 Ag-grid, Angularjs 2 Ag-grid, Angularjs 2024-09-17 6.1 Medium
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
CVE-2024-38996 1 Ag-grid 2 Ag-grid-community, Ag-grid-enterprise 2024-08-02 9.8 Critical
ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVE-2024-39001 1 Ag-grid 1 Ag-grid-enterprise 2024-08-02 6.3 Medium
ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.