Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Clearml Enterprise Server MEDIUM 6.5
CVE-2024-43779

An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP requ…

No fix yet
Fix from $1,600 2025-02-06
Clearml Enterprise Server HIGH 8.2
CVE-2024-39272

A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted H…

Mitigation only
Fix from $1,950 2025-02-06
Clearml MEDIUM 5.4
CVE-2024-24594

A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to e…

No fix yet
Fix from $1,600 2024-02-06
Clearml CRITICAL 9.8
CVE-2024-24592

Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, c…

No fix yet
Fix from $2,300 2024-02-06
Clearml HIGH 8.8
CVE-2024-24590

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously u…

Fix: after 1.14.2
Fix from $1,950 2024-02-06
Clearml HIGH 8.8
CVE-2024-24591

A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset …

Fix: after 1.14.1
Fix from $1,950 2024-02-06
Clearml HIGH 8.8
CVE-2024-24593

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a …

Fix: after 1.14.1
Fix from $1,950 2024-02-06
Clearml HIGH 7.1
CVE-2024-24595

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all …

Mitigation only
Fix from $1,950 2024-02-05
Clearml Server MEDIUM 5.4
CVE-2023-6778

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.

Fix: 1.13.0+
Fix from $1,600 2023-12-18
Ispot Firmware HIGH 9.3
CVE-2010-4507

Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9…

No fix yet
Fix from $1,950 2010-12-30