Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-2742 An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.… Vaadin 14.14.1 / 23.6.7+ Fix from $1,6002026-03-10 MEDIUM 6.8 CVE-2026-2741 Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, … Vaadin 14.14.1 / 23.6.7+ Fix from $1,6002026-03-10 MEDIUM 6.5 CVE-2023-25499 When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0,… Vaadin 10.0.23 / 14.10.1+ Fix from $1,6002023-06-22 HIGH 7.5 CVE-2022-29567 The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through… Vaadin after 23.0.8 Fix from $1,9502022-05-24 MEDIUM 6.1 CVE-2021-33611 Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.… Vaadin after 14.4.4 Fix from $1,6002021-11-02 MEDIUM 5.3 CVE-2021-31412 Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.… Flow after 19.0.8 Fix from $1,6002021-06-24 HIGH 7.5 CVE-2021-31409 Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 th… Vaadin after 8.12.4 Fix from $1,9502021-05-06 HIGH 7.8 CVE-2021-31411 Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaad… Flow 2.5.3 / 14.5.3+ Fix from $1,9502021-05-05 HIGH 7.5 CVE-2021-31410 Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project s… Designer 4.6.4+ Fix from $1,9502021-04-23 HIGH 7.1 CVE-2021-31408 Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19… Flow 6.0.0 / 6.0.5+ Fix from $1,9502021-04-23 HIGH 7.5 CVE-2020-36320 Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attack… Vaadin 7.7.22+ Fix from $1,9502021-04-23 HIGH 7.5 CVE-2020-36321 Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 pr… Flow 2.4.2 / 5.0.0+ Fix from $1,9502021-04-23 HIGH 7.5 CVE-2021-31405 Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and… Flow 2.3.3 / 4.0.3+ Fix from $1,9502021-04-23 HIGH 7.5 CVE-2021-31407 Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaa… Flow 2.4.8 / 6.0.2+ Fix from $1,9502021-04-23 MEDIUM 6.5 CVE-2020-36319 Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensi… Flow 3.0.6 / 15.0.5+ Fix from $1,6002021-04-23 MEDIUM 6.1 CVE-2019-25028 Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 th… Vaadin 7.7.20 / 8.8.5+ Fix from $1,6002021-04-23 MEDIUM 6.1 CVE-2019-25027 Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13… Flow 1.0.11 / 1.4.3+ Fix from $1,6002021-04-23