clear records
10 published records for vendor clear.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-502 Deserialization of Untrusted Data1
- CWE-522 Insufficiently Protected Credentials1
- CWE-425 Direct Request ('Forced Browsing')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-24592No exploit | Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily clear · clearml · CWE-425 | Critical9.8 | — | 1.0% | Feb 6, 2024 |
38Monitor | CVE-2010-4507Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmwclear · ispot firmware · CWE-352 | Critical9.3 | — | 1.8% | Dec 30, 2010 |
36Monitor | CVE-2024-24590Proof of concept | Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliclear · clearml · CWE-502 | High8.8 | — | 2.5% | Feb 6, 2024 |
35Monitor | CVE-2024-24591No exploit | A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploadedclear · clearml · CWE-22 | High8.8 | — | 0.8% | Feb 6, 2024 |
35Monitor | CVE-2024-24593No exploit | A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform clear · clearml · CWE-352 | High8.8 | — | 0.4% | Feb 6, 2024 |
32Monitor | CVE-2024-39272No exploit | A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533.clear · clearml enterprise server · CWE-79 | High8.2 | — | 0.6% | Feb 6, 2025 |
28Monitor | CVE-2024-24595No exploit | Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaclear · clearml · CWE-522 | High7.1 | — | 0.3% | Feb 5, 2024 |
26Monitor | CVE-2024-43779No exploit | An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533.clear · clearml enterprise server · CWE-200 | Medium6.5 | — | 0.8% | Feb 6, 2025 |
21Monitor | CVE-2024-24594No exploit | A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attaclear · clearml · CWE-79 | Medium5.4 | — | 0.6% | Feb 6, 2024 |
21Monitor | CVE-2023-6778No exploit | Cross-site Scripting (XSS) - Stored in allegroai/clearml-serverclear · clearml server · CWE-79 | Medium5.4 | — | 0.4% | Dec 18, 2023 |
- CVE-2024-2459239Monitor
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily
CriticalCVSS 9.8No exploitEPSS 1%clear · clearmlFeb 6, 2024
- CVE-2010-450738Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmw
CriticalCVSS 9.3Proof of conceptEPSS 2%clear · ispot firmwareDec 30, 2010
- CVE-2024-2459036Monitor
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a mali
HighCVSS 8.8Proof of conceptEPSS 2%clear · clearmlFeb 6, 2024
- CVE-2024-2459135Monitor
A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded
HighCVSS 8.8No exploitEPSS 1%clear · clearmlFeb 6, 2024
- CVE-2024-2459335Monitor
A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform
HighCVSS 8.8No exploitEPSS 0%clear · clearmlFeb 6, 2024
- CVE-2024-3927232Monitor
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533.
HighCVSS 8.2No exploitEPSS 1%clear · clearml enterprise serverFeb 6, 2025
- CVE-2024-2459528Monitor
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server lea
HighCVSS 7.1No exploitEPSS 0%clear · clearmlFeb 5, 2024
- CVE-2024-4377926Monitor
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533.
MediumCVSS 6.5No exploitEPSS 1%clear · clearml enterprise serverFeb 6, 2025
- CVE-2024-2459421Monitor
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote atta
MediumCVSS 5.4No exploitEPSS 1%clear · clearmlFeb 6, 2024
- CVE-2023-677821Monitor
Cross-site Scripting (XSS) - Stored in allegroai/clearml-server
MediumCVSS 5.4No exploitEPSS 0%clear · clearml serverDec 18, 2023