2fauth kayıtları
2fauth üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %40
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2026-32133İstismar yok | 2FAuth has Blind SSRF in image parameter allows internal network access and more2fauth · 2fauth · CWE-918 | Yüksek7,8 | — | %0,5 | 11 Mar 2026 |
30İzleyin | CVE-2024-52598İstismar yok | 2FAuth vulnerable to Server Side Request Forgery + URI validation bypass in 2fauth /api/v1/twofaccounts/preview2fauth · 2fauth · CWE-79 | Yüksek7,5 | — | %0,6 | 20 Kas 2024 |
26İzleyin | CVE-2025-45731İstismar yok | A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other opera2fauth · 2fauth · CWE-362 | Orta6,5 | — | %0,3 | 24 Tem 2025 |
24İzleyin | CVE-2023-36816İstismar yok | Cross-Site Scripting (XSS) at Account creation in 2FAuth2fauth · 2fauth · CWE-79 | Orta6,1 | — | %0,5 | 3 Tem 2023 |
24İzleyin | CVE-2024-52597İstismar yok | 2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render2fauth · 2fauth · CWE-79 | Orta6,1 | — | %0,4 | 20 Kas 2024 |
- CVE-2026-3213331İzleyin
2FAuth has Blind SSRF in image parameter allows internal network access and more
YüksekCVSS 7,8İstismar yokEPSS %12fauth · 2fauth11 Mar 2026
- CVE-2024-5259830İzleyin
2FAuth vulnerable to Server Side Request Forgery + URI validation bypass in 2fauth /api/v1/twofaccounts/preview
YüksekCVSS 7,5İstismar yokEPSS %12fauth · 2fauth20 Kas 2024
- CVE-2025-4573126İzleyin
A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other opera
OrtaCVSS 6,5İstismar yokEPSS %02fauth · 2fauth24 Tem 2025
- CVE-2023-3681624İzleyin
Cross-Site Scripting (XSS) at Account creation in 2FAuth
OrtaCVSS 6,1İstismar yokEPSS %02fauth · 2fauth3 Tem 2023
- CVE-2024-5259724İzleyin
2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render
OrtaCVSS 6,1İstismar yokEPSS %02fauth · 2fauth20 Kas 2024