Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 428 respecto a la semana anterior
Críticas / altas1288▲ 1 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.4) | 0.54% | — | ClearmlAI | 1/7/2026 | 2/7/2026 | A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extracting `.zip` archives using the `ZipFile.extractall()` method in `StorageManager._extract_to_cache()`. This issue arises due to the lack of path traversal validation, enabling an attacker to write… | |
| Aplazada | Media (5.8) | 0.30% | — | ClearmlAI | 5/10/2025 | 17/6/2026 | A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten. | |
| Analizada | Media (6.5) | 0.82% | — | Clearml Enterprise Server | 6/2/2025 | 17/6/2026 | An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP requests to trigger this… | |
| Analizada | Alta (8.2) | 0.57% | — | Clearml Enterprise Server | 6/2/2025 | 17/6/2026 | A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code. An attacker can send a series of HTTP requests to trigger this vulnerability. | |
| Modificada | Media (5.4) | 0.59% | — | Clearml | 6/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI. | |
| Modificada | Alta (8.8) | 0.38% | — | Clearml | 6/2/2024 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise… | |
| Modificada | Crítica (9.8) | 0.98% | — | Clearml | 6/2/2024 | 17/6/2026 | Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files. | |
| Modificada | Alta (8.8) | 0.80% | — | Clearml | 6/2/2024 | 17/6/2026 | A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with. | |
| Modificada | Alta (8.8) | 2.5% | — | Clearml | 6/2/2024 | 17/6/2026 | Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with. | |
| Modificada | Alta (7.1) | 0.26% | — | Clearml | 5/2/2024 | 17/6/2026 | Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords. | |
| Modificada | Media (5.4) | 0.43% | — | Clearml Server | 18/12/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. |