Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Clear

First CVE: Dec 30, 2010Active for: 16 yearsTotal CVEs: 10
38.7
VTI Score
Medium

Clear develops machine learning operations and data-management platforms, including ClearML workflow software and ClearSpot appliances, where vulnerability exposure concentrates around web-application and authentication-layer issues. The recurring weakness classes—cross-site scripting, CSRF, insufficiently protected credentials, untrusted deserialization, and forced-browsing flaws—reflect the web-facing and API-driven architecture of these management and integration tools, and vulnerabilities affecting the vendor reach moderate severity outcomes. Current exploitation activity, severity distribution, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Clear over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2010
15 years ago
Most Recent CVE
Feb 6, 2025
533 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4507HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9.4 allow remote attackers to hi
Dec 30, 20109.341NOYES
CVE-2024-24590HIGH
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitra
Feb 6, 20248.827NONO
CVE-2024-24592CRITICAL
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.
Feb 6, 20249.826NONO
CVE-2024-24593HIGH
A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate
Feb 6, 20248.824NONO
CVE-2024-24591HIGH
A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files
Feb 6, 20248.824NONO
CVE-2024-39272HIGH
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbi
Feb 6, 20258.223NONO
CVE-2024-43779MEDIUM
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults
Feb 6, 20256.520NONO
CVE-2024-24594MEDIUM
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload whe
Feb 6, 20245.420NONO
CVE-2024-24595HIGH
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
Feb 5, 20247.120NONO
CVE-2023-6778MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.
Dec 18, 20235.419NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
60%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network8 (80.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None3 (30.0%)
Unknown1 (10.0%)
Required6 (60.0%)
Privileges Required
Low4 (40.0%)
High0 (0.0%)
None5 (50.0%)
Unknown1 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Clear.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Clear — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Clear's Products

View all 4 CNAs →

Top CWEs