Tryton kayıtları
tryton üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-863 Incorrect Authorization3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-269 Improper Privilege Management1
- CWE-384 Session Fixation1
- CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2014-6633İstismar yok | The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.tryton · tryton · CWE-77 | Yüksek8,8 | — | %2,6 | 12 Nis 2018 |
32İzleyin | CVE-2013-4510İstismar yok | Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write tryton · tryton · CWE-22 | Yüksek7,8 | — | %2,2 | 17 Kas 2013 |
31İzleyin | CVE-2022-26662İstismar yok | An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.xtryton · proteus · CWE-776 | Yüksek7,5 | — | %2,0 | 10 Mar 2022 |
31İzleyin | CVE-2012-2238İstismar yok | trytond 2.4: ModelView.button fails to validate authorizationtryton · trytond · CWE-863 | Yüksek7,5 | — | %1,8 | 21 Kas 2019 |
28İzleyin | CVE-2025-66423İstismar yok | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor.tryton · trytond · CWE-863 | Yüksek7,1 | — | %0,2 | 29 Kas 2025 |
26İzleyin | CVE-2022-26661İstismar yok | An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.tryton · proteus · CWE-611 | Orta6,5 | — | %1,4 | 10 Mar 2022 |
26İzleyin | CVE-2019-10868İstismar yok | In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6,tryton · trytond · CWE-862 | Orta6,5 | — | %1,3 | 4 Nis 2019 |
26İzleyin | CVE-2025-66424İstismar yok | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export.tryton · trytond · CWE-863 | Orta6,5 | — | %0,2 | 29 Kas 2025 |
23İzleyin | CVE-2012-0215İstismar yok | model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Matryton · trytond · CWE-264 | Orta5,5 | — | %2,0 | 12 Tem 2012 |
23İzleyin | CVE-2018-19443İstismar yok | The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances intryton · tryton · CWE-384 | Orta5,9 | — | %1,1 | 22 Kas 2018 |
21İzleyin | CVE-2016-1241İstismar yok | Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated usertryton · tryton · CWE-200 | Orta5,3 | — | %1,6 | 7 Eyl 2016 |
21İzleyin | CVE-2017-0360İstismar yok | file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "sametryton · tryton · CWE-269 | Orta5,3 | — | %1,6 | 4 Nis 2017 |
18İzleyin | CVE-2016-1242İstismar yok | file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authentitryton · tryton · CWE-200 | Orta4,4 | — | %1,8 | 7 Eyl 2016 |
17İzleyin | CVE-2015-0861İstismar yok | model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authentictryton · trytond · CWE-264 | Orta4,3 | — | %1,2 | 13 Nis 2016 |
17İzleyin | CVE-2025-66422İstismar yok | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.tryton · trytond · CWE-402 | Orta4,3 | — | %0,3 | 29 Kas 2025 |
- CVE-2014-663336İzleyin
The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.
YüksekCVSS 8,8İstismar yokEPSS %3tryton · tryton12 Nis 2018
- CVE-2013-451032İzleyin
Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write
YüksekCVSS 7,8İstismar yokEPSS %2tryton · tryton17 Kas 2013
- CVE-2022-2666231İzleyin
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x
YüksekCVSS 7,5İstismar yokEPSS %2tryton · proteus10 Mar 2022
- CVE-2012-223831İzleyin
trytond 2.4: ModelView.button fails to validate authorization
YüksekCVSS 7,5İstismar yokEPSS %2tryton · trytond21 Kas 2019
- CVE-2025-6642328İzleyin
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor.
YüksekCVSS 7,1İstismar yokEPSS %0tryton · trytond29 Kas 2025
- CVE-2022-2666126İzleyin
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.
OrtaCVSS 6,5İstismar yokEPSS %1tryton · proteus10 Mar 2022
- CVE-2019-1086826İzleyin
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6,
OrtaCVSS 6,5İstismar yokEPSS %1tryton · trytond4 Nis 2019
- CVE-2025-6642426İzleyin
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export.
OrtaCVSS 6,5İstismar yokEPSS %0tryton · trytond29 Kas 2025
- CVE-2012-021523İzleyin
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Ma
OrtaCVSS 5,5İstismar yokEPSS %2tryton · trytond12 Tem 2012
- CVE-2018-1944323İzleyin
The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in
OrtaCVSS 5,9İstismar yokEPSS %1tryton · tryton22 Kas 2018
- CVE-2016-124121İzleyin
Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated user
OrtaCVSS 5,3İstismar yokEPSS %2tryton · tryton7 Eyl 2016
- CVE-2017-036021İzleyin
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same
OrtaCVSS 5,3İstismar yokEPSS %2tryton · tryton4 Nis 2017
- CVE-2016-124218İzleyin
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenti
OrtaCVSS 4,4İstismar yokEPSS %2tryton · tryton7 Eyl 2016
- CVE-2015-086117İzleyin
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authentic
OrtaCVSS 4,3İstismar yokEPSS %1tryton · trytond13 Nis 2016
- CVE-2025-6642217İzleyin
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.
OrtaCVSS 4,3İstismar yokEPSS %0tryton · trytond29 Kas 2025