Known Vulnerabilities for Flow by Vaadin
Listed below are 10 of the newest known vulnerabilities associated with "Flow" by "Vaadin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67332 json | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clie... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67327 json | better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to a... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-65710 json | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLIC... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-65594 json | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was intr... | Not Provided | 2026-07-22 | 2026-07-23 |
| CVE-2026-65058 json | Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flo... | Not Provided | 2026-07-21 | 2026-07-30 |
| CVE-2026-64881 json | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command executio... | Not Provided | 2026-07-21 | 2026-07-24 |
| CVE-2026-64829 json | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained ... | Not Provided | 2026-07-22 | 2026-07-23 |
| CVE-2026-64626 json | AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder... | Not Provided | 2026-07-20 | 2026-07-22 |
| CVE-2026-64531 json | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs ... | Not Provided | 2026-07-27 | 2026-08-01 |
| CVE-2026-64528 json | In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung: Remove redundant port lock acquisi... | Not Provided | 2026-07-25 | 2026-07-25 |