İçeriğe atla
Noroxi

cvat kayıtları

cvat üreticisine ait 16 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %6,3
Silahlaştırılmış
1 · %6,3
Pre-auth RCE
2
Düzeltme kaydı olan
%18,8
Yayından KEV’e ortanca
503 gün

Tüm kayıtlar

16 kayıt
  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    apache · log4j14 Ara 2021

  • CVE-2022-31188
    54Planlayın

    Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)

    KritikCVSS 9,8Kavram kanıtıEPSS %49

    cvat · computer vision annotation tool1 Ağu 2022

  • CVE-2025-23045
    34İzleyin

    CVAT allows remote code execution via tracker Nuclio functions

    YüksekCVSS 8,7İstismar yokEPSS %1

    cvat · computer vision annotation tool28 Oca 2025

  • CVE-2024-37164
    34İzleyin

    CVAT SSRF via custom cloud storage endpoints

    YüksekCVSS 8,5İstismar yokEPSS %0

    cvat · computer vision annotation tool13 Haz 2024

  • CVE-2026-23526
    34İzleyin

    CVAT vulnerable to privilege escalation of users with staff status

    YüksekCVSS 8,5İstismar yokEPSS %0

    cvat · computer vision annotation tool21 Oca 2026

  • CVE-2026-23516
    34İzleyin

    CVAT vulnerable to XSS via skeleton SVG images

    YüksekCVSS 8,6İstismar yokEPSS %0

    cvat · computer vision annotation tool21 Oca 2026

  • CVE-2024-37306
    28İzleyin

    CVAT's export and backup-related API endpoints are susceptible to CSRF

    YüksekCVSS 7,1İstismar yokEPSS %0

    cvat · computer vision annotation tool13 Haz 2024

  • CVE-2025-54573
    26İzleyin

    CVAT vulnerable to email verification bypass by use of basic authentication

    OrtaCVSS 6,5İstismar yokEPSS %0

    cvat · computer vision annotation tool30 Tem 2025

  • CVE-2024-47064
    25İzleyin

    Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints

    OrtaCVSS 6,3İstismar yokEPSS %0

    cvat · computer vision annotation tool30 Eyl 2024

  • CVE-2024-45393
    25İzleyin

    Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries

    OrtaCVSS 6,4İstismar yokEPSS %0

    cvat · computer vision annotation tool10 Eyl 2024

  • CVE-2024-47063
    24İzleyin

    Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint

    OrtaCVSS 6,2İstismar yokEPSS %0

    cvat · computer vision annotation tool30 Eyl 2024

  • CVE-2026-58373
    21İzleyin

    CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence

    OrtaCVSS 5,3İstismar yokEPSS %0

    cvat · computer vision annotation tool30 Haz 2026

  • CVE-2025-49135
    21İzleyin

    CVAT missing validation for in-progress backup upload names

    OrtaCVSS 5,3İstismar yokEPSS %0

    cvat · computer vision annotation tool25 Haz 2025

  • CVE-2025-68430
    21İzleyin

    CVAT vulnerable to directory traversal via mounted share listing

    OrtaCVSS 5,3İstismar yokEPSS %0

    cvat · computer vision annotation tool19 Ara 2025

  • CVE-2025-48381
    21İzleyin

    CVAT has information disclosure via browsable API

    OrtaCVSS 5,3İstismar yokEPSS %0

    cvat · computer vision annotation tool30 May 2025

  • CVE-2024-47172
    21İzleyin

    Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints

    OrtaCVSS 5,4İstismar yokEPSS %0

    cvat · computer vision annotation tool30 Eyl 2024