Known Vulnerabilities for Sa-token by Dromara
Listed below are 2 of the newest known vulnerabilities associated with "Sa-token" by "Dromara".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73842 json | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/clus... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73645 json | OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1,... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-73611 json | File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured wit... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73564 json | frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH e... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73501 json | kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validati... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-73482 json | phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administra... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73481 json | phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bounce... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-73431 json | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activat... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-73418 json | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the expo... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-73263 json | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content co... | Not Provided | 2026-08-12 | 2026-08-12 |