cvat kayıtları
cvat üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %6,3
- Silahlaştırılmış
- 1 · %6,3
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %18,8
- Yayından KEV’e ortanca
- 503 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-862 Missing Authorization2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2021-45046Silahlaştırılmış | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Kritik9,0 | KEV | %100,0 | 14 Ara 2021 |
54Planlayın | CVE-2022-31188Kavram kanıtı | Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)cvat · computer vision annotation tool · CWE-918 | Kritik9,8 | — | %48,6 | 1 Ağu 2022 |
34İzleyin | CVE-2025-23045İstismar yok | CVAT allows remote code execution via tracker Nuclio functionscvat · computer vision annotation tool · CWE-502 | Yüksek8,7 | — | %0,5 | 28 Oca 2025 |
34İzleyin | CVE-2024-37164İstismar yok | CVAT SSRF via custom cloud storage endpointscvat · computer vision annotation tool · CWE-918 | Yüksek8,5 | — | %0,3 | 13 Haz 2024 |
34İzleyin | CVE-2026-23526İstismar yok | CVAT vulnerable to privilege escalation of users with staff statuscvat · computer vision annotation tool · CWE-267 | Yüksek8,5 | — | %0,3 | 21 Oca 2026 |
34İzleyin | CVE-2026-23516İstismar yok | CVAT vulnerable to XSS via skeleton SVG imagescvat · computer vision annotation tool · CWE-83 | Yüksek8,6 | — | %0,2 | 21 Oca 2026 |
28İzleyin | CVE-2024-37306İstismar yok | CVAT's export and backup-related API endpoints are susceptible to CSRFcvat · computer vision annotation tool · CWE-352 | Yüksek7,1 | — | %0,2 | 13 Haz 2024 |
26İzleyin | CVE-2025-54573İstismar yok | CVAT vulnerable to email verification bypass by use of basic authenticationcvat · computer vision annotation tool · CWE-287 | Orta6,5 | — | %0,3 | 30 Tem 2025 |
25İzleyin | CVE-2024-47064İstismar yok | Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpointscvat · computer vision annotation tool · CWE-79 | Orta6,3 | — | %0,3 | 30 Eyl 2024 |
25İzleyin | CVE-2024-45393İstismar yok | Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveriescvat · computer vision annotation tool · CWE-862 | Orta6,4 | — | %0,2 | 10 Eyl 2024 |
24İzleyin | CVE-2024-47063İstismar yok | Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpointcvat · computer vision annotation tool · CWE-79 | Orta6,2 | — | %0,3 | 30 Eyl 2024 |
21İzleyin | CVE-2026-58373İstismar yok | CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existencecvat · computer vision annotation tool · CWE-862 | Orta5,3 | — | %0,3 | 30 Haz 2026 |
21İzleyin | CVE-2025-49135İstismar yok | CVAT missing validation for in-progress backup upload namescvat · computer vision annotation tool · CWE-639 | Orta5,3 | — | %0,3 | 25 Haz 2025 |
21İzleyin | CVE-2025-68430İstismar yok | CVAT vulnerable to directory traversal via mounted share listingcvat · computer vision annotation tool · CWE-24 | Orta5,3 | — | %0,3 | 19 Ara 2025 |
21İzleyin | CVE-2025-48381İstismar yok | CVAT has information disclosure via browsable APIcvat · computer vision annotation tool · CWE-201 | Orta5,3 | — | %0,3 | 30 May 2025 |
21İzleyin | CVE-2024-47172İstismar yok | Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpointscvat · computer vision annotation tool · CWE-863 | Orta5,4 | — | %0,3 | 30 Eyl 2024 |
- CVE-2021-4504696Hemen
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100apache · log4j14 Ara 2021
- CVE-2022-3118854Planlayın
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
KritikCVSS 9,8Kavram kanıtıEPSS %49cvat · computer vision annotation tool1 Ağu 2022
- CVE-2025-2304534İzleyin
CVAT allows remote code execution via tracker Nuclio functions
YüksekCVSS 8,7İstismar yokEPSS %1cvat · computer vision annotation tool28 Oca 2025
- CVE-2024-3716434İzleyin
CVAT SSRF via custom cloud storage endpoints
YüksekCVSS 8,5İstismar yokEPSS %0cvat · computer vision annotation tool13 Haz 2024
- CVE-2026-2352634İzleyin
CVAT vulnerable to privilege escalation of users with staff status
YüksekCVSS 8,5İstismar yokEPSS %0cvat · computer vision annotation tool21 Oca 2026
- CVE-2026-2351634İzleyin
CVAT vulnerable to XSS via skeleton SVG images
YüksekCVSS 8,6İstismar yokEPSS %0cvat · computer vision annotation tool21 Oca 2026
- CVE-2024-3730628İzleyin
CVAT's export and backup-related API endpoints are susceptible to CSRF
YüksekCVSS 7,1İstismar yokEPSS %0cvat · computer vision annotation tool13 Haz 2024
- CVE-2025-5457326İzleyin
CVAT vulnerable to email verification bypass by use of basic authentication
OrtaCVSS 6,5İstismar yokEPSS %0cvat · computer vision annotation tool30 Tem 2025
- CVE-2024-4706425İzleyin
Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints
OrtaCVSS 6,3İstismar yokEPSS %0cvat · computer vision annotation tool30 Eyl 2024
- CVE-2024-4539325İzleyin
Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries
OrtaCVSS 6,4İstismar yokEPSS %0cvat · computer vision annotation tool10 Eyl 2024
- CVE-2024-4706324İzleyin
Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint
OrtaCVSS 6,2İstismar yokEPSS %0cvat · computer vision annotation tool30 Eyl 2024
- CVE-2026-5837321İzleyin
CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence
OrtaCVSS 5,3İstismar yokEPSS %0cvat · computer vision annotation tool30 Haz 2026
- CVE-2025-4913521İzleyin
CVAT missing validation for in-progress backup upload names
OrtaCVSS 5,3İstismar yokEPSS %0cvat · computer vision annotation tool25 Haz 2025
- CVE-2025-6843021İzleyin
CVAT vulnerable to directory traversal via mounted share listing
OrtaCVSS 5,3İstismar yokEPSS %0cvat · computer vision annotation tool19 Ara 2025
- CVE-2025-4838121İzleyin
CVAT has information disclosure via browsable API
OrtaCVSS 5,3İstismar yokEPSS %0cvat · computer vision annotation tool30 May 2025
- CVE-2024-4717221İzleyin
Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints
OrtaCVSS 5,4İstismar yokEPSS %0cvat · computer vision annotation tool30 Eyl 2024