Known Vulnerabilities for Flow by Vaadin
Listed below are 10 of the newest known vulnerabilities associated with "Flow" by "Vaadin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56425 json | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization f... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-56211 json | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds valida... | Not Provided | 2026-06-19 | 2026-06-19 |
| CVE-2026-55205 json | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/s... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-53982 json | Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to b... | Not Provided | 2026-06-12 | 2026-06-14 |
| CVE-2026-53808 json | OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent ... | Not Provided | 2026-06-11 | 2026-06-12 |
| CVE-2026-53782 json | Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS ... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-53723 json | Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe we... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-50751 json | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an un... | Not Provided | 2026-06-08 | 2026-06-09 |
| CVE-2026-49290 json | Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior t... | Not Provided | 2026-06-19 | 2026-06-19 |
| CVE-2026-49214 json | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control ... | Not Provided | 2026-06-11 | 2026-06-11 |