In that screen-grab, Java , (which is not the same a JavaScript), is disabled by default : you have to give your permission for it to run, so is not a vulnerability if you only allow it to run on sites you trust. However your Flash addon is "always activate", so Flash is a vulnerability.
If you...