Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
odoo odoo 10.0 vulnerabilities and exploits
(subscribe to this query)
490
VMScore
CVE-2018-14863
Incorrect access control in the RPC framework in Odoo Community 8.0 up to and including 11.0 and Odoo Enterprise 9.0 up to and including 11.0 allows authenticated users to call private functions via RPC.
Odoo Odoo 9.0
Odoo Odoo 10.0
Odoo Odoo 11.0
356
VMScore
CVE-2018-14866
Incorrect access control in the TransientModel framework in Odoo Community 11.0 and previous versions and Odoo Enterprise 11.0 and previous versions allows authenticated malicious users to access data in transient records that they do not own by making an RPC call before garbage ...
Odoo Odoo 9.0
Odoo Odoo 10.0
Odoo Odoo 11.0
516
VMScore
CVE-2018-14887
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and previous versions and Odoo Enterprise 11.0 and previous versions allows a remote malicious user to deny access to the service and to disclose database names via a crafted request.
Odoo Odoo 9.0
Odoo Odoo 10.0
Odoo Odoo 11.0
356
VMScore
CVE-2017-9416
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
Odoo Odoo 10.0
Odoo Odoo 9.0
Odoo Odoo 8.0
356
VMScore
CVE-2018-14861
Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of the secure hashed passwords of other users.
Odoo Odoo 10.0
Odoo Odoo 11.0
668
VMScore
CVE-2018-14885
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote malicious user to restore a database dump without knowing the super-admin password. An arbitrary password succeeds.
Odoo Odoo 10.0
Odoo Odoo 11.0
445
VMScore
CVE-2018-14867
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote malicious users to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.
Odoo Odoo 9.0
Odoo Odoo 10.0
802
VMScore
CVE-2018-15640
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 up to and including 12.0 allows remote authenticated malicious users to obtain elevated privileges via a crafted request.
Odoo Odoo
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2