Записи Tryton
15 опубликованных записей вендора tryton.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-863 Incorrect Authorization3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-269 Improper Privilege Management1
- CWE-384 Session Fixation1
- CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2014-6633Эксплойта нет | The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.tryton · tryton · CWE-77 | Высокая8,8 | — | 2,6 % | 12 апр. 2018 г. |
32Наблюдать | CVE-2013-4510Эксплойта нет | Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write tryton · tryton · CWE-22 | Высокая7,8 | — | 2,2 % | 17 нояб. 2013 г. |
31Наблюдать | CVE-2022-26662Эксплойта нет | An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.xtryton · proteus · CWE-776 | Высокая7,5 | — | 2,0 % | 10 мар. 2022 г. |
31Наблюдать | CVE-2012-2238Эксплойта нет | trytond 2.4: ModelView.button fails to validate authorizationtryton · trytond · CWE-863 | Высокая7,5 | — | 1,8 % | 21 нояб. 2019 г. |
28Наблюдать | CVE-2025-66423Эксплойта нет | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor.tryton · trytond · CWE-863 | Высокая7,1 | — | 0,2 % | 29 нояб. 2025 г. |
26Наблюдать | CVE-2022-26661Эксплойта нет | An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.tryton · proteus · CWE-611 | Средняя6,5 | — | 1,4 % | 10 мар. 2022 г. |
26Наблюдать | CVE-2019-10868Эксплойта нет | In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6,tryton · trytond · CWE-862 | Средняя6,5 | — | 1,3 % | 4 апр. 2019 г. |
26Наблюдать | CVE-2025-66424Эксплойта нет | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export.tryton · trytond · CWE-863 | Средняя6,5 | — | 0,2 % | 29 нояб. 2025 г. |
23Наблюдать | CVE-2012-0215Эксплойта нет | model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Matryton · trytond · CWE-264 | Средняя5,5 | — | 2,0 % | 12 июл. 2012 г. |
23Наблюдать | CVE-2018-19443Эксплойта нет | The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances intryton · tryton · CWE-384 | Средняя5,9 | — | 1,1 % | 22 нояб. 2018 г. |
21Наблюдать | CVE-2016-1241Эксплойта нет | Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated usertryton · tryton · CWE-200 | Средняя5,3 | — | 1,6 % | 7 сент. 2016 г. |
21Наблюдать | CVE-2017-0360Эксплойта нет | file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "sametryton · tryton · CWE-269 | Средняя5,3 | — | 1,6 % | 4 апр. 2017 г. |
18Наблюдать | CVE-2016-1242Эксплойта нет | file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authentitryton · tryton · CWE-200 | Средняя4,4 | — | 1,8 % | 7 сент. 2016 г. |
17Наблюдать | CVE-2015-0861Эксплойта нет | model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authentictryton · trytond · CWE-264 | Средняя4,3 | — | 1,2 % | 13 апр. 2016 г. |
17Наблюдать | CVE-2025-66422Эксплойта нет | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.tryton · trytond · CWE-402 | Средняя4,3 | — | 0,3 % | 29 нояб. 2025 г. |
- CVE-2014-663336Наблюдать
The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %tryton · tryton12 апр. 2018 г.
- CVE-2013-451032Наблюдать
Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %tryton · tryton17 нояб. 2013 г.
- CVE-2022-2666231Наблюдать
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %tryton · proteus10 мар. 2022 г.
- CVE-2012-223831Наблюдать
trytond 2.4: ModelView.button fails to validate authorization
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %tryton · trytond21 нояб. 2019 г.
- CVE-2025-6642328Наблюдать
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %tryton · trytond29 нояб. 2025 г.
- CVE-2022-2666126Наблюдать
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %tryton · proteus10 мар. 2022 г.
- CVE-2019-1086826Наблюдать
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6,
СредняяCVSS 6,5Эксплойта нетEPSS 1 %tryton · trytond4 апр. 2019 г.
- CVE-2025-6642426Наблюдать
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %tryton · trytond29 нояб. 2025 г.
- CVE-2012-021523Наблюдать
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Ma
СредняяCVSS 5,5Эксплойта нетEPSS 2 %tryton · trytond12 июл. 2012 г.
- CVE-2018-1944323Наблюдать
The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in
СредняяCVSS 5,9Эксплойта нетEPSS 1 %tryton · tryton22 нояб. 2018 г.
- CVE-2016-124121Наблюдать
Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated user
СредняяCVSS 5,3Эксплойта нетEPSS 2 %tryton · tryton7 сент. 2016 г.
- CVE-2017-036021Наблюдать
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same
СредняяCVSS 5,3Эксплойта нетEPSS 2 %tryton · tryton4 апр. 2017 г.
- CVE-2016-124218Наблюдать
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenti
СредняяCVSS 4,4Эксплойта нетEPSS 2 %tryton · tryton7 сент. 2016 г.
- CVE-2015-086117Наблюдать
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authentic
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tryton · trytond13 апр. 2016 г.
- CVE-2025-6642217Наблюдать
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %tryton · trytond29 нояб. 2025 г.