Записи 2fauth
5 опубликованных записей вендора 2fauth.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 40 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2026-32133Эксплойта нет | 2FAuth has Blind SSRF in image parameter allows internal network access and more2fauth · 2fauth · CWE-918 | Высокая7,8 | — | 0,5 % | 11 мар. 2026 г. |
30Наблюдать | CVE-2024-52598Эксплойта нет | 2FAuth vulnerable to Server Side Request Forgery + URI validation bypass in 2fauth /api/v1/twofaccounts/preview2fauth · 2fauth · CWE-79 | Высокая7,5 | — | 0,6 % | 20 нояб. 2024 г. |
26Наблюдать | CVE-2025-45731Эксплойта нет | A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other opera2fauth · 2fauth · CWE-362 | Средняя6,5 | — | 0,3 % | 24 июл. 2025 г. |
24Наблюдать | CVE-2023-36816Эксплойта нет | Cross-Site Scripting (XSS) at Account creation in 2FAuth2fauth · 2fauth · CWE-79 | Средняя6,1 | — | 0,5 % | 3 июл. 2023 г. |
24Наблюдать | CVE-2024-52597Эксплойта нет | 2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render2fauth · 2fauth · CWE-79 | Средняя6,1 | — | 0,4 % | 20 нояб. 2024 г. |
- CVE-2026-3213331Наблюдать
2FAuth has Blind SSRF in image parameter allows internal network access and more
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %2fauth · 2fauth11 мар. 2026 г.
- CVE-2024-5259830Наблюдать
2FAuth vulnerable to Server Side Request Forgery + URI validation bypass in 2fauth /api/v1/twofaccounts/preview
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %2fauth · 2fauth20 нояб. 2024 г.
- CVE-2025-4573126Наблюдать
A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other opera
СредняяCVSS 6,5Эксплойта нетEPSS 0 %2fauth · 2fauth24 июл. 2025 г.
- CVE-2023-3681624Наблюдать
Cross-Site Scripting (XSS) at Account creation in 2FAuth
СредняяCVSS 6,1Эксплойта нетEPSS 0 %2fauth · 2fauth3 июл. 2023 г.
- CVE-2024-5259724Наблюдать
2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render
СредняяCVSS 6,1Эксплойта нетEPSS 0 %2fauth · 2fauth20 нояб. 2024 г.