Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2021-23263

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).
Attacker Value
Unknown

CVE-2021-23264

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
Attacker Value
Unknown

CVE-2021-31410

Disclosure Date: April 22, 2021 (last updated February 22, 2025)
Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request.
Attacker Value
Unknown

CVE-2021-31407

Disclosure Date: March 29, 2021 (last updated February 22, 2025)
Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.