Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vaadin vaadin vulnerabilities and exploits
(subscribe to this query)
2.5
CVSSv3
CVE-2021-33604
URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 up to and including 2.6.1 (Vaadin 14.0.0 up to and including 14.6.1), 3.0.0 up to and including 6.0.9 (Vaadin 15.0.0 up to and including 19.0.8) allows local user to execute arbitrary JavaScri...
Vaadin Flow-server
Vaadin Vaadin
4.3
CVSSv3
CVE-2021-33609
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 up to and including 8.14.0 (Vaadin 8.0.0 up to and including 8.14.0) allows authenticated network malicious user to cause heap exhaustion by requesting too many rows of data.
Vaadin Vaadin
7.5
CVSSv3
CVE-2020-36320
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 up to and including 7.7.21 (Vaadin 7.0.0 up to and including 7.7.21) allows malicious users to cause uncontrolled resource consumption by submitting malicious email addresses.
Vaadin Vaadin
NA
CVE-2011-0509
Cross-site scripting (XSS) vulnerability in Vaadin prior to 6.4.9 allows remote malicious users to inject arbitrary web script or HTML via unknown vectors related to the index page.
Vaadin Vaadin
6.1
CVSSv3
CVE-2019-25028
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 up to and including 7.7.19 (Vaadin 7.4.0 up to and including 7.7.19), and 8.0.0 up to and including 8.8.4 (Vaadin 8.0.0 up to and including 8.8.4) allows malicious user to inject malicious ...
Vaadin Vaadin
4.3
CVSSv3
CVE-2021-33605
Improper check in CheckboxGroup in com.vaadin:vaadin-checkbox-flow versions 1.2.0 before 2.0.0 (Vaadin 12.0.0 before 14.0.0), 2.0.0 before 3.0.0 (Vaadin 14.0.0 before 14.5.0), 3.0.0 up to and including 4.0.1 (Vaadin 15.0.0 up to and including 17.0.11), 14.5.0 up to and including ...
Vaadin Vaadin-checkbox-flow
2.5
CVSSv3
CVE-2021-31404
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 up to and including 1.0.13 (Vaadin 10.0.0 up to and including 10.0.16), 1.1.0 before 2.0.0 (Vaadin 11 before 14), 2.0.0 up to and including 2.4.6 (Vaadin 14.0.0 up to and ...
7.8
CVSSv3
CVE-2021-31411
Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 up to and including 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 before 6.0 (Vaadin 15 before 19), and 6.0.0 up to and including 6.0.5 (Vaadin 19.0.0 up to and includin...
7.5
CVSSv3
CVE-2021-31405
Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 up to and including 2.3.2 (Vaadin 14.0.6 up to and including 14.4.3), and 3.0.0 up to and including 4.0.2 (Vaadin 15.0.0 up to and including 17.0.10) allows malicious users to caus...
2.5
CVSSv3
CVE-2021-31403
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 up to and including 7.7.23 (Vaadin 7.0.0 up to and including 7.7.23), and 8.0.0 up to and including 8.12.2 (Vaadin 8.0.0 up to and including 8.12.2) allows malicious use...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »