Flow
This hub aggregates every CVE we track for Flow, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
26
CVEs tracked
0
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM17HIGH7LOW2
Monthly trend
0
0
1
0
0
0
0
0
2
0
0
0
0
1
0
0
1
0
2
1
0
0
1
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Flow.
- CVE-2026-57793WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability7.5
- CVE-2026-22683Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE8.8
- CVE-2026-2742Unauthorized session creation via reserved framework path access5.3
- CVE-2026-2741Zip Slip Path Traversal on Node Unpack6.8
- CVE-2026-1126lwj flow SVG File FormResource.java uploadFile unrestricted upload6.3
- CVE-2025-11655Total.js Flow SVG File unrestricted upload4.7
- CVE-2025-20972Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.6.2
- CVE-2025-20971Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.5.5
- CVE-2024-49407Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.4.6
- CVE-2024-34600Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.4.4
- CVE-2023-30094A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the se...5.4
- CVE-2023-21444Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.7.5
- CVE-2023-21443Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.7.5
- CVE-2021-31412Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-195.3
- CVE-2021-31411Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-196.3
Product normalization is registry-driven with AI assist and human review. How it works