Known Vulnerabilities for Flow-server by Vaadin
Listed below are 1 of the newest known vulnerabilities associated with "Flow-server" by "Vaadin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77143 json | The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified.... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-75583 json | keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-73655 json | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy... | Not Provided | 2026-08-13 | 2026-08-18 |
| CVE-2026-73649 json | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-20... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-73247 json | Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/run... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-73235 json | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed ... | Not Provided | 2026-08-11 | 2026-08-12 |
| CVE-2026-72917 json | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. F... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-72669 json | The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the rout... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-72566 json | A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticate... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-70666 json | Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/aut... | Not Provided | 2026-08-18 | 2026-08-19 |