Known Vulnerabilities for Sa-token by Dromara
Listed below are 2 of the newest known vulnerabilities associated with "Sa-token" by "Dromara".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-35383 | Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-35091 | A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosyn... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-34990 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and p... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-34953 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token no... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-34931 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability th... | Not Provided | 2026-04-02 | 2026-04-03 |
| CVE-2026-34787 | Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exis... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-34613 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php a... | Not Provided | 2026-03-31 | 2026-04-01 |
| CVE-2026-34611 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php ... | Not Provided | 2026-03-31 | 2026-04-01 |
| CVE-2026-34581 | goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it i... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-34531 | Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation ... | Not Provided | 2026-04-01 | 2026-04-02 |