İçeriğe atla
Noroxi

clear kayıtları

clear üreticisine ait 10 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%20
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

10 kayıt
  • CVE-2024-24592
    39İzleyin

    Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily

    KritikCVSS 9,8İstismar yokEPSS %1

    clear · clearml6 Şub 2024

  • CVE-2010-4507
    38İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmw

    KritikCVSS 9,3Kavram kanıtıEPSS %2

    clear · ispot firmware30 Ara 2010

  • CVE-2024-24590
    36İzleyin

    Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a mali

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    clear · clearml6 Şub 2024

  • CVE-2024-24591
    35İzleyin

    A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded

    YüksekCVSS 8,8İstismar yokEPSS %1

    clear · clearml6 Şub 2024

  • CVE-2024-24593
    35İzleyin

    A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform

    YüksekCVSS 8,8İstismar yokEPSS %0

    clear · clearml6 Şub 2024

  • CVE-2024-39272
    32İzleyin

    A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533.

    YüksekCVSS 8,2İstismar yokEPSS %1

    clear · clearml enterprise server6 Şub 2025

  • CVE-2024-24595
    28İzleyin

    Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server lea

    YüksekCVSS 7,1İstismar yokEPSS %0

    clear · clearml5 Şub 2024

  • CVE-2024-43779
    26İzleyin

    An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533.

    OrtaCVSS 6,5İstismar yokEPSS %1

    clear · clearml enterprise server6 Şub 2025

  • CVE-2024-24594
    21İzleyin

    A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote atta

    OrtaCVSS 5,4İstismar yokEPSS %1

    clear · clearml6 Şub 2024

  • CVE-2023-6778
    21İzleyin

    Cross-site Scripting (XSS) - Stored in allegroai/clearml-server

    OrtaCVSS 5,4İstismar yokEPSS %0

    clear · clearml server18 Ara 2023