Cvat
Cvat Computer Vision Annotation Tool: vulnerabilidades y CVE
Cvat Computer Vision Annotation Tool tiene 16 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses4
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-45046 | Crítica (9) | 100% | ⚠ Explotación activa | 14 dic 2021 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58373 | Media (5.3) | 0.34% | — | 30 jun 2026 | CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by… |
| CVE-2026-23526 | Alta (8.5) | 0.29% | — | 21 ene 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their permissions, including giving themselves… |
| CVE-2026-23516 | Alta (8.6) | 0.17% | — | 21 ene 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided… |
| CVE-2025-68430 | Media (5.3) | 0.29% | — | 19 dic 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to retrieve the contents of any file… |
| CVE-2025-54573 | Media (6.5) | 0.27% | — | 30 jul 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users… |
| CVE-2025-49135 | Media (5.3) | 0.30% | — | 25 jun 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the import process of a project or task backup to check that the filename… |
| CVE-2025-48381 | Media (5.3) | 0.28% | — | 30 may 2025 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CVAT user may be able to retrieve the IDs… |
| CVE-2025-23045 | Alta (8.7) | 0.50% | — | 28 ene 2025 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the… |
| CVE-2024-47172 | Media (5.4) | 0.26% | — | 30 sept 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership… |
| CVE-2024-47064 | Media (6.3) | 0.31% | — | 30 sept 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate… |
| CVE-2024-47063 | Media (6.2) | 0.30% | — | 30 sept 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another… |
| CVE-2024-45393 | Media (6.4) | 0.24% | — | 10 sept 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the… |
| CVE-2024-37306 | Alta (7.1) | 0.21% | — | 13 jun 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into… |
| CVE-2024-37164 | Alta (8.5) | 0.35% | — | 13 jun 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages based on Amazon S3 and Azure Blob… |
| CVE-2022-31188 | Crítica (9.8) | 49% | — | 1 ago 2022 | CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to… |
| CVE-2021-45046 | Crítica (9) | 100% | ⚠ Explotación activa | 14 dic 2021 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.