Перейти к содержимому
Noroxi

Записи cvat

16 опубликованных записей вендора cvat.

Профиль для исследователя

Попали в KEV
1 · 6,3 %
С эксплойтом
1 · 6,3 %
Pre-auth RCE
2
С записью об исправлении
18,8 %
Медиана: публикация → KEV
503 дн.

Записи по годам

  1. 21
  2. 22
  3. 24
  4. 25
  5. 26

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

16 записей
  • CVE-2021-45046
    96Срочно

    Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j14 дек. 2021 г.

  • CVE-2022-31188
    54В плане

    Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)

    КритическаяCVSS 9,8Proof of conceptEPSS 49 %

    cvat · computer vision annotation tool1 авг. 2022 г.

  • CVE-2025-23045
    34Наблюдать

    CVAT allows remote code execution via tracker Nuclio functions

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    cvat · computer vision annotation tool28 янв. 2025 г.

  • CVE-2024-37164
    34Наблюдать

    CVAT SSRF via custom cloud storage endpoints

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool13 июн. 2024 г.

  • CVE-2026-23526
    34Наблюдать

    CVAT vulnerable to privilege escalation of users with staff status

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool21 янв. 2026 г.

  • CVE-2026-23516
    34Наблюдать

    CVAT vulnerable to XSS via skeleton SVG images

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool21 янв. 2026 г.

  • CVE-2024-37306
    28Наблюдать

    CVAT's export and backup-related API endpoints are susceptible to CSRF

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool13 июн. 2024 г.

  • CVE-2025-54573
    26Наблюдать

    CVAT vulnerable to email verification bypass by use of basic authentication

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool30 июл. 2025 г.

  • CVE-2024-47064
    25Наблюдать

    Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool30 сент. 2024 г.

  • CVE-2024-45393
    25Наблюдать

    Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries

    СредняяCVSS 6,4Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool10 сент. 2024 г.

  • CVE-2024-47063
    24Наблюдать

    Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint

    СредняяCVSS 6,2Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool30 сент. 2024 г.

  • CVE-2026-58373
    21Наблюдать

    CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool30 июн. 2026 г.

  • CVE-2025-49135
    21Наблюдать

    CVAT missing validation for in-progress backup upload names

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool25 июн. 2025 г.

  • CVE-2025-68430
    21Наблюдать

    CVAT vulnerable to directory traversal via mounted share listing

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool19 дек. 2025 г.

  • CVE-2025-48381
    21Наблюдать

    CVAT has information disclosure via browsable API

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool30 мая 2025 г.

  • CVE-2024-47172
    21Наблюдать

    Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool30 сент. 2024 г.