2bits records
3 published records for vendor 2bits.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
17Monitor | CVE-2010-1074No exploit | Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitradrupal · drupal · CWE-79 | Medium4.3 | — | 1.3% | Mar 23, 2010 |
17Monitor | CVE-2025-10930No exploit | Currency - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-1102bits · currency · CWE-352 | Medium4.3 | — | 0.1% | Oct 29, 2025 |
14Monitor | CVE-2009-3782No exploit | Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpointsdrupal · drupal · CWE-200 | Low3.5 | — | 1.0% | Oct 26, 2009 |
- CVE-2010-107417Monitor
Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitra
MediumCVSS 4.3No exploitEPSS 1%drupal · drupalMar 23, 2010
- CVE-2025-1093017Monitor
Currency - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-110
MediumCVSS 4.3No exploitEPSS 0%2bits · currencyOct 29, 2025
- CVE-2009-378214Monitor
Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints
LowCVSS 3.5No exploitEPSS 1%drupal · drupalOct 26, 2009