Записи cvat
16 опубликованных записей вендора cvat.
Профиль для исследователя
- Попали в KEV
- 1 · 6,3 %
- С эксплойтом
- 1 · 6,3 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 18,8 %
- Медиана: публикация → KEV
- 503 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-862 Missing Authorization2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
96Срочно | CVE-2021-45046Готовый эксплойт | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Критическая9,0 | KEV | 100,0 % | 14 дек. 2021 г. |
54В плане | CVE-2022-31188Proof of concept | Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)cvat · computer vision annotation tool · CWE-918 | Критическая9,8 | — | 48,6 % | 1 авг. 2022 г. |
34Наблюдать | CVE-2025-23045Эксплойта нет | CVAT allows remote code execution via tracker Nuclio functionscvat · computer vision annotation tool · CWE-502 | Высокая8,7 | — | 0,5 % | 28 янв. 2025 г. |
34Наблюдать | CVE-2024-37164Эксплойта нет | CVAT SSRF via custom cloud storage endpointscvat · computer vision annotation tool · CWE-918 | Высокая8,5 | — | 0,3 % | 13 июн. 2024 г. |
34Наблюдать | CVE-2026-23526Эксплойта нет | CVAT vulnerable to privilege escalation of users with staff statuscvat · computer vision annotation tool · CWE-267 | Высокая8,5 | — | 0,3 % | 21 янв. 2026 г. |
34Наблюдать | CVE-2026-23516Эксплойта нет | CVAT vulnerable to XSS via skeleton SVG imagescvat · computer vision annotation tool · CWE-83 | Высокая8,6 | — | 0,2 % | 21 янв. 2026 г. |
28Наблюдать | CVE-2024-37306Эксплойта нет | CVAT's export and backup-related API endpoints are susceptible to CSRFcvat · computer vision annotation tool · CWE-352 | Высокая7,1 | — | 0,2 % | 13 июн. 2024 г. |
26Наблюдать | CVE-2025-54573Эксплойта нет | CVAT vulnerable to email verification bypass by use of basic authenticationcvat · computer vision annotation tool · CWE-287 | Средняя6,5 | — | 0,3 % | 30 июл. 2025 г. |
25Наблюдать | CVE-2024-47064Эксплойта нет | Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpointscvat · computer vision annotation tool · CWE-79 | Средняя6,3 | — | 0,3 % | 30 сент. 2024 г. |
25Наблюдать | CVE-2024-45393Эксплойта нет | Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveriescvat · computer vision annotation tool · CWE-862 | Средняя6,4 | — | 0,2 % | 10 сент. 2024 г. |
24Наблюдать | CVE-2024-47063Эксплойта нет | Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpointcvat · computer vision annotation tool · CWE-79 | Средняя6,2 | — | 0,3 % | 30 сент. 2024 г. |
21Наблюдать | CVE-2026-58373Эксплойта нет | CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existencecvat · computer vision annotation tool · CWE-862 | Средняя5,3 | — | 0,3 % | 30 июн. 2026 г. |
21Наблюдать | CVE-2025-49135Эксплойта нет | CVAT missing validation for in-progress backup upload namescvat · computer vision annotation tool · CWE-639 | Средняя5,3 | — | 0,3 % | 25 июн. 2025 г. |
21Наблюдать | CVE-2025-68430Эксплойта нет | CVAT vulnerable to directory traversal via mounted share listingcvat · computer vision annotation tool · CWE-24 | Средняя5,3 | — | 0,3 % | 19 дек. 2025 г. |
21Наблюдать | CVE-2025-48381Эксплойта нет | CVAT has information disclosure via browsable APIcvat · computer vision annotation tool · CWE-201 | Средняя5,3 | — | 0,3 % | 30 мая 2025 г. |
21Наблюдать | CVE-2024-47172Эксплойта нет | Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpointscvat · computer vision annotation tool · CWE-863 | Средняя5,4 | — | 0,3 % | 30 сент. 2024 г. |
- CVE-2021-4504696Срочно
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %apache · log4j14 дек. 2021 г.
- CVE-2022-3118854В плане
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
КритическаяCVSS 9,8Proof of conceptEPSS 49 %cvat · computer vision annotation tool1 авг. 2022 г.
- CVE-2025-2304534Наблюдать
CVAT allows remote code execution via tracker Nuclio functions
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %cvat · computer vision annotation tool28 янв. 2025 г.
- CVE-2024-3716434Наблюдать
CVAT SSRF via custom cloud storage endpoints
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %cvat · computer vision annotation tool13 июн. 2024 г.
- CVE-2026-2352634Наблюдать
CVAT vulnerable to privilege escalation of users with staff status
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %cvat · computer vision annotation tool21 янв. 2026 г.
- CVE-2026-2351634Наблюдать
CVAT vulnerable to XSS via skeleton SVG images
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %cvat · computer vision annotation tool21 янв. 2026 г.
- CVE-2024-3730628Наблюдать
CVAT's export and backup-related API endpoints are susceptible to CSRF
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %cvat · computer vision annotation tool13 июн. 2024 г.
- CVE-2025-5457326Наблюдать
CVAT vulnerable to email verification bypass by use of basic authentication
СредняяCVSS 6,5Эксплойта нетEPSS 0 %cvat · computer vision annotation tool30 июл. 2025 г.
- CVE-2024-4706425Наблюдать
Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints
СредняяCVSS 6,3Эксплойта нетEPSS 0 %cvat · computer vision annotation tool30 сент. 2024 г.
- CVE-2024-4539325Наблюдать
Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries
СредняяCVSS 6,4Эксплойта нетEPSS 0 %cvat · computer vision annotation tool10 сент. 2024 г.
- CVE-2024-4706324Наблюдать
Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint
СредняяCVSS 6,2Эксплойта нетEPSS 0 %cvat · computer vision annotation tool30 сент. 2024 г.
- CVE-2026-5837321Наблюдать
CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence
СредняяCVSS 5,3Эксплойта нетEPSS 0 %cvat · computer vision annotation tool30 июн. 2026 г.
- CVE-2025-4913521Наблюдать
CVAT missing validation for in-progress backup upload names
СредняяCVSS 5,3Эксплойта нетEPSS 0 %cvat · computer vision annotation tool25 июн. 2025 г.
- CVE-2025-6843021Наблюдать
CVAT vulnerable to directory traversal via mounted share listing
СредняяCVSS 5,3Эксплойта нетEPSS 0 %cvat · computer vision annotation tool19 дек. 2025 г.
- CVE-2025-4838121Наблюдать
CVAT has information disclosure via browsable API
СредняяCVSS 5,3Эксплойта нетEPSS 0 %cvat · computer vision annotation tool30 мая 2025 г.
- CVE-2024-4717221Наблюдать
Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints
СредняяCVSS 5,4Эксплойта нетEPSS 0 %cvat · computer vision annotation tool30 сент. 2024 г.