Odoo kayıtları
odoo üreticisine ait 56 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %28,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-284 Improper Access Control22
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-267 Privilege Defined With Unsafe Actions5
- CWE-732 Incorrect Permission Assignment for Critical Resource4
- CWE-20 Improper Input Validation4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
56 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-10804İstismar yok | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication underodoo · odoo · CWE-306 | Kritik9,8 | — | %3,4 | 4 Tem 2017 |
40Planlayın | CVE-2018-14885İstismar yok | Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remoteodoo · odoo · CWE-284 | Kritik9,8 | — | %2,2 | 28 Haz 2019 |
39İzleyin | CVE-2023-48050İstismar yok | SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attenodoo · biometric attendance · CWE-89 | Kritik9,8 | — | %0,8 | 14 Ara 2023 |
37İzleyin | CVE-2018-15640İstismar yok | Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated prodoo · odoo · CWE-284 | Yüksek8,8 | — | %7,8 | 9 Nis 2019 |
37İzleyin | CVE-2018-14860İstismar yok | Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticatodoo · odoo · CWE-78 | Kritik9,1 | — | %2,2 | 3 Tem 2019 |
36İzleyin | CVE-2020-29396İstismar yok | A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows odoo · odoo · CWE-267 | Yüksek8,8 | — | %3,2 | 22 Ara 2020 |
36İzleyin | CVE-2019-11781İstismar yok | Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackeodoo · odoo · CWE-20 | Yüksek8,8 | — | %2,1 | 22 Ara 2020 |
36İzleyin | CVE-2018-15632İstismar yok | Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote odoo · odoo · CWE-20 | Kritik9,1 | — | %1,2 | 22 Ara 2020 |
36İzleyin | CVE-2021-44547İstismar yok | A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading todoo · odoo · CWE-267 | Kritik9,1 | — | %0,7 | 25 Nis 2023 |
35İzleyin | CVE-2017-10805İstismar yok | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the odoo · odoo · CWE-863 | Yüksek8,8 | — | %1,0 | 4 Tem 2017 |
35İzleyin | CVE-2024-12368İstismar yok | Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuthodoo · odoo · CWE-284 | Yüksek8,8 | — | %0,7 | 25 Şub 2025 |
34İzleyin | CVE-2021-23166İstismar yok | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and wodoo · odoo · CWE-267 | Yüksek8,7 | — | %0,6 | 25 Nis 2023 |
34İzleyin | CVE-2021-23186İstismar yok | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access andodoo · odoo · CWE-267 | Yüksek8,7 | — | %0,6 | 25 Nis 2023 |
33İzleyin | CVE-2019-11780İstismar yok | Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authentodoo · odoo · CWE-284 | Yüksek8,1 | — | %2,1 | 19 Ara 2019 |
32İzleyin | CVE-2018-14859İstismar yok | Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authodoo · odoo · CWE-284 | Yüksek8,1 | — | %1,0 | 3 Tem 2019 |
32İzleyin | CVE-2018-14863İstismar yok | Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated uodoo · odoo · CWE-284 | Yüksek8,1 | — | %1,0 | 3 Tem 2019 |
32İzleyin | CVE-2021-45111İstismar yok | Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to triggerodoo · odoo · CWE-284 | Yüksek8,1 | — | %0,8 | 25 Nis 2023 |
31İzleyin | CVE-2018-14733İstismar yok | The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expressionodoo · odoo · CWE-20 | Yüksek7,5 | — | %2,2 | 5 Tem 2019 |
30İzleyin | CVE-2021-23203İstismar yok | Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackodoo · odoo · CWE-284 | Yüksek7,5 | — | %0,9 | 25 Nis 2023 |
30İzleyin | CVE-2021-23178İstismar yok | Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online paymentsodoo · odoo · CWE-284 | Yüksek7,5 | — | %0,6 | 25 Nis 2023 |
29İzleyin | CVE-2024-34533İstismar yok | A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows aCWE-89 | Yüksek7,3 | — | %0,5 | 6 May 2024 |
29İzleyin | CVE-2024-34534İstismar yok | A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote atCWE-89 | Yüksek7,3 | — | %0,5 | 6 May 2024 |
28İzleyin | CVE-2017-9416Kavram kanıtı | Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local fiodoo · odoo · CWE-22 | Orta6,5 | — | %5,7 | 4 Haz 2017 |
27İzleyin | CVE-2017-10803Kavram kanıtı | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Dodoo · odoo · CWE-502 | Orta6,5 | — | %3,6 | 4 Tem 2017 |
27İzleyin | CVE-2018-14887İstismar yok | Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier odoo · odoo · CWE-20 | Orta6,5 | — | %1,8 | 28 Haz 2019 |
- CVE-2017-1080440Planlayın
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under
KritikCVSS 9,8İstismar yokEPSS %3odoo · odoo4 Tem 2017
- CVE-2018-1488540Planlayın
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote
KritikCVSS 9,8İstismar yokEPSS %2odoo · odoo28 Haz 2019
- CVE-2023-4805039İzleyin
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-atten
KritikCVSS 9,8İstismar yokEPSS %1odoo · biometric attendance14 Ara 2023
- CVE-2018-1564037İzleyin
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated pr
YüksekCVSS 8,8İstismar yokEPSS %8odoo · odoo9 Nis 2019
- CVE-2018-1486037İzleyin
Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticat
KritikCVSS 9,1İstismar yokEPSS %2odoo · odoo3 Tem 2019
- CVE-2020-2939636İzleyin
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows
YüksekCVSS 8,8İstismar yokEPSS %3odoo · odoo22 Ara 2020
- CVE-2019-1178136İzleyin
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attacke
YüksekCVSS 8,8İstismar yokEPSS %2odoo · odoo22 Ara 2020
- CVE-2018-1563236İzleyin
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote
KritikCVSS 9,1İstismar yokEPSS %1odoo · odoo22 Ara 2020
- CVE-2021-4454736İzleyin
A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading t
KritikCVSS 9,1İstismar yokEPSS %1odoo · odoo25 Nis 2023
- CVE-2017-1080535İzleyin
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the
YüksekCVSS 8,8İstismar yokEPSS %1odoo · odoo4 Tem 2017
- CVE-2024-1236835İzleyin
Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth
YüksekCVSS 8,8İstismar yokEPSS %1odoo · odoo25 Şub 2025
- CVE-2021-2316634İzleyin
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and w
YüksekCVSS 8,7İstismar yokEPSS %1odoo · odoo25 Nis 2023
- CVE-2021-2318634İzleyin
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and
YüksekCVSS 8,7İstismar yokEPSS %1odoo · odoo25 Nis 2023
- CVE-2019-1178033İzleyin
Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authent
YüksekCVSS 8,1İstismar yokEPSS %2odoo · odoo19 Ara 2019
- CVE-2018-1485932İzleyin
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows auth
YüksekCVSS 8,1İstismar yokEPSS %1odoo · odoo3 Tem 2019
- CVE-2018-1486332İzleyin
Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated u
YüksekCVSS 8,1İstismar yokEPSS %1odoo · odoo3 Tem 2019
- CVE-2021-4511132İzleyin
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger
YüksekCVSS 8,1İstismar yokEPSS %1odoo · odoo25 Nis 2023
- CVE-2018-1473331İzleyin
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression
YüksekCVSS 7,5İstismar yokEPSS %2odoo · odoo5 Tem 2019
- CVE-2021-2320330İzleyin
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attack
YüksekCVSS 7,5İstismar yokEPSS %1odoo · odoo25 Nis 2023
- CVE-2021-2317830İzleyin
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments
YüksekCVSS 7,5İstismar yokEPSS %1odoo · odoo25 Nis 2023
- CVE-2024-3453329İzleyin
A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a
YüksekCVSS 7,3İstismar yokEPSS %16 May 2024
- CVE-2024-3453429İzleyin
A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote at
YüksekCVSS 7,3İstismar yokEPSS %06 May 2024
- CVE-2017-941628İzleyin
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local fi
OrtaCVSS 6,5Kavram kanıtıEPSS %6odoo · odoo4 Haz 2017
- CVE-2017-1080327İzleyin
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the D
OrtaCVSS 6,5Kavram kanıtıEPSS %4odoo · odoo4 Tem 2017
- CVE-2018-1488727İzleyin
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier
OrtaCVSS 6,5İstismar yokEPSS %2odoo · odoo28 Haz 2019