Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vaadin vaadin vulnerabilities and exploits
(subscribe to this query)
4.6
CVSSv2
CVE-2021-31411
Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 up to and including 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 before 6.0 (Vaadin 15 before 19), and 6.0.0 up to and including 6.0.5 (Vaadin 19.0.0 up to and includin...
Vaadin Flow
Vaadin Vaadin
4.3
CVSSv2
CVE-2021-31412
Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 up to and including 1.0.14 (Vaadin 10.0.0 up to and including 10.0.18), 1.1.0 before 2.0.0 (Vaadin 11 before 14), 2.0.0 up to and including 2.6.1 (Vaadin 14.0.0 up to and inc...
Vaadin Flow
Vaadin Vaadin
5
CVSSv2
CVE-2020-36321
Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 up to and including 2.4.1 (Vaadin 14.0.0 up to and including 14.4.2), and 3.0 before 5.0 (Vaadin 15 before 18) allows malicious user to request arbitrary files stored outside of intended ...
Vaadin Flow
Vaadin Vaadin
4.3
CVSSv2
CVE-2019-25027
Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 up to and including 1.0.10 (Vaadin 10.0.0 up to and including 10.0.13), and 1.1.0 up to and including 1.4.2 (Vaadin 11.0.0 up to and including 13.0.5) allows malicious user to ...
Vaadin Flow
Vaadin Vaadin
1.9
CVSSv2
CVE-2021-31404
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 up to and including 1.0.13 (Vaadin 10.0.0 up to and including 10.0.16), 1.1.0 before 2.0.0 (Vaadin 11 before 14), 2.0.0 up to and including 2.4.6 (Vaadin 14.0.0 up to and ...
Vaadin Flow
Vaadin Vaadin
1.2
CVSSv2
CVE-2021-33604
URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 up to and including 2.6.1 (Vaadin 14.0.0 up to and including 14.6.1), 3.0.0 up to and including 6.0.9 (Vaadin 15.0.0 up to and including 19.0.8) allows local user to execute arbitrary JavaScri...
Vaadin Vaadin
Vaadin Flow-server
4
CVSSv2
CVE-2021-33609
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 up to and including 8.14.0 (Vaadin 8.0.0 up to and including 8.14.0) allows authenticated network malicious user to cause heap exhaustion by requesting too many rows of data.
Vaadin Vaadin
5
CVSSv2
CVE-2020-36320
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 up to and including 7.7.21 (Vaadin 7.0.0 up to and including 7.7.21) allows malicious users to cause uncontrolled resource consumption by submitting malicious email addresses.
Vaadin Vaadin
1.9
CVSSv2
CVE-2021-31403
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 up to and including 7.7.23 (Vaadin 7.0.0 up to and including 7.7.23), and 8.0.0 up to and including 8.12.2 (Vaadin 8.0.0 up to and including 8.12.2) allows malicious use...
Vaadin Vaadin
4.3
CVSSv2
CVE-2019-25028
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 up to and including 7.7.19 (Vaadin 7.4.0 up to and including 7.7.19), and 8.0.0 up to and including 8.8.4 (Vaadin 8.0.0 up to and including 8.8.4) allows malicious user to inject malicious ...
Vaadin Vaadin
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27802
template injection
CVE-2024-0044
code injection
CVE-2024-35474
CVE-2024-27857
CVE-2024-23251
CVE-2024-23692
physical
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »