Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2025-66423 Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. Trytond 6.0.70 / 7.0.40+ Fix from $1,9502025-11-30 MEDIUM 6.5 CVE-2025-66424 Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. Trytond 6.0.70 / 7.0.40+ Fix from $1,6002025-11-30 HIGH 7.5 CVE-2012-2238 trytond 2.4: ModelView.button fails to validate authorization Trytond 2.4.2+ Fix from $1,9502019-11-21 MEDIUM 5.9 CVE-2018-19443 The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py a… Tryton Mitigation only Fix from $1,6002018-11-22 HIGH 8.8 CVE-2014-6633 The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allow… Tryton 2.4.15 / 2.6.14+ Fix from $1,9502018-04-12 MEDIUM 5.3 CVE-2017-0360 file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root nam… Tryton Mitigation only Fix from $1,6002017-04-04 MEDIUM 5.3 CVE-2016-1241 Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated users to disc… Tryton Mitigation only Fix from $1,6002016-09-07 HIGH 7.8 CVE-2013-4510 Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write arbitrary… Tryton Patch available Fix from $1,9502013-11-18 MEDIUM 5.5 CVE-2012-0215 model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field … Trytond after 2.2.3 Fix from $1,6002012-07-12