VYPR

ag-grid

by ag-grid-community

CVEs (3)

  • CVE-2024-38996CriJul 1, 2024
    risk 0.57cvss 9.8epss 0.01

    ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2017-16009MedJun 4, 2018
    risk 0.40cvss 6.1epss 0.01

    ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.

  • CVE-2024-39001MedJul 1, 2024
    risk 0.34cvss 6.3epss 0.01

    ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.