Known Vulnerabilities for Sf-users by Sloughflash
Listed below are 1 of the newest known vulnerabilities associated with "Sf-users" by "Sloughflash".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65598 json | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authen... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65596 json | n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credent... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65589 json | n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing pla... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65316 json | XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read exec... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-65054 json | MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metad... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-65016 json | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65013 json | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authen... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65011 json | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definit... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-64834 json | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_a... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-64829 json | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained ... | Not Provided | 2026-07-22 | 2026-07-22 |