Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vaadin vaadin vulnerabilities and exploits
(subscribe to this query)
1.2
CVSSv2
CVE-2021-33604
URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 up to and including 2.6.1 (Vaadin 14.0.0 up to and including 14.6.1), 3.0.0 up to and including 6.0.9 (Vaadin 15.0.0 up to and including 19.0.8) allows local user to execute arbitrary JavaScri...
Vaadin Flow-server
Vaadin Vaadin
5
CVSSv2
CVE-2020-36320
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 up to and including 7.7.21 (Vaadin 7.0.0 up to and including 7.7.21) allows malicious users to cause uncontrolled resource consumption by submitting malicious email addresses.
Vaadin Vaadin
4
CVSSv2
CVE-2021-33609
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 up to and including 8.14.0 (Vaadin 8.0.0 up to and including 8.14.0) allows authenticated network malicious user to cause heap exhaustion by requesting too many rows of data.
Vaadin Vaadin
4.3
CVSSv2
CVE-2011-0509
Cross-site scripting (XSS) vulnerability in Vaadin prior to 6.4.9 allows remote malicious users to inject arbitrary web script or HTML via unknown vectors related to the index page.
Vaadin Vaadin
4.3
CVSSv2
CVE-2019-25028
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 up to and including 7.7.19 (Vaadin 7.4.0 up to and including 7.7.19), and 8.0.0 up to and including 8.8.4 (Vaadin 8.0.0 up to and including 8.8.4) allows malicious user to inject malicious ...
Vaadin Vaadin
4
CVSSv2
CVE-2021-33605
Improper check in CheckboxGroup in com.vaadin:vaadin-checkbox-flow versions 1.2.0 before 2.0.0 (Vaadin 12.0.0 before 14.0.0), 2.0.0 before 3.0.0 (Vaadin 14.0.0 before 14.5.0), 3.0.0 up to and including 4.0.1 (Vaadin 15.0.0 up to and including 17.0.11), 14.5.0 up to and including ...
Vaadin Vaadin-checkbox-flow
1.9
CVSSv2
CVE-2021-31404
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 up to and including 1.0.13 (Vaadin 10.0.0 up to and including 10.0.16), 1.1.0 before 2.0.0 (Vaadin 11 before 14), 2.0.0 up to and including 2.4.6 (Vaadin 14.0.0 up to and ...
4.6
CVSSv2
CVE-2021-31411
Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 up to and including 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 before 6.0 (Vaadin 15 before 19), and 6.0.0 up to and including 6.0.5 (Vaadin 19.0.0 up to and includin...
5
CVSSv2
CVE-2021-31405
Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 up to and including 2.3.2 (Vaadin 14.0.6 up to and including 14.4.3), and 3.0.0 up to and including 4.0.2 (Vaadin 15.0.0 up to and including 17.0.10) allows malicious users to caus...
1.9
CVSSv2
CVE-2021-31403
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 up to and including 7.7.23 (Vaadin 7.0.0 up to and including 7.7.23), and 8.0.0 up to and including 8.12.2 (Vaadin 8.0.0 up to and including 8.12.2) allows malicious use...
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »