clear kayıtları
clear üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %20
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-502 Deserialization of Untrusted Data1
- CWE-522 Insufficiently Protected Credentials1
- CWE-425 Direct Request ('Forced Browsing')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-24592İstismar yok | Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily clear · clearml · CWE-425 | Kritik9,8 | — | %1,0 | 6 Şub 2024 |
38İzleyin | CVE-2010-4507Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmwclear · ispot firmware · CWE-352 | Kritik9,3 | — | %1,8 | 30 Ara 2010 |
36İzleyin | CVE-2024-24590Kavram kanıtı | Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliclear · clearml · CWE-502 | Yüksek8,8 | — | %2,5 | 6 Şub 2024 |
35İzleyin | CVE-2024-24591İstismar yok | A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploadedclear · clearml · CWE-22 | Yüksek8,8 | — | %0,8 | 6 Şub 2024 |
35İzleyin | CVE-2024-24593İstismar yok | A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform clear · clearml · CWE-352 | Yüksek8,8 | — | %0,4 | 6 Şub 2024 |
32İzleyin | CVE-2024-39272İstismar yok | A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533.clear · clearml enterprise server · CWE-79 | Yüksek8,2 | — | %0,6 | 6 Şub 2025 |
28İzleyin | CVE-2024-24595İstismar yok | Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaclear · clearml · CWE-522 | Yüksek7,1 | — | %0,3 | 5 Şub 2024 |
26İzleyin | CVE-2024-43779İstismar yok | An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533.clear · clearml enterprise server · CWE-200 | Orta6,5 | — | %0,8 | 6 Şub 2025 |
21İzleyin | CVE-2024-24594İstismar yok | A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attaclear · clearml · CWE-79 | Orta5,4 | — | %0,6 | 6 Şub 2024 |
21İzleyin | CVE-2023-6778İstismar yok | Cross-site Scripting (XSS) - Stored in allegroai/clearml-serverclear · clearml server · CWE-79 | Orta5,4 | — | %0,4 | 18 Ara 2023 |
- CVE-2024-2459239İzleyin
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily
KritikCVSS 9,8İstismar yokEPSS %1clear · clearml6 Şub 2024
- CVE-2010-450738İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmw
KritikCVSS 9,3Kavram kanıtıEPSS %2clear · ispot firmware30 Ara 2010
- CVE-2024-2459036İzleyin
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a mali
YüksekCVSS 8,8Kavram kanıtıEPSS %2clear · clearml6 Şub 2024
- CVE-2024-2459135İzleyin
A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded
YüksekCVSS 8,8İstismar yokEPSS %1clear · clearml6 Şub 2024
- CVE-2024-2459335İzleyin
A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform
YüksekCVSS 8,8İstismar yokEPSS %0clear · clearml6 Şub 2024
- CVE-2024-3927232İzleyin
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533.
YüksekCVSS 8,2İstismar yokEPSS %1clear · clearml enterprise server6 Şub 2025
- CVE-2024-2459528İzleyin
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server lea
YüksekCVSS 7,1İstismar yokEPSS %0clear · clearml5 Şub 2024
- CVE-2024-4377926İzleyin
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533.
OrtaCVSS 6,5İstismar yokEPSS %1clear · clearml enterprise server6 Şub 2025
- CVE-2024-2459421İzleyin
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote atta
OrtaCVSS 5,4İstismar yokEPSS %1clear · clearml6 Şub 2024
- CVE-2023-677821İzleyin
Cross-site Scripting (XSS) - Stored in allegroai/clearml-server
OrtaCVSS 5,4İstismar yokEPSS %0clear · clearml server18 Ara 2023