VendorsCVATcomputer_vision_annotation_toolall versions
Vulnerabilities

CVAT Computer Vision Annotation Tool (CVAT)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2022-31188
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
Published 2022-08-01 · Analyzed
9.81 PoCEPSS 0.486
CVE-2025-23045
CVAT allows remote code execution via tracker Nuclio functions
Published 2025-01-28 · Analyzed
9.8EPSS 0.005
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Published 2021-12-14 · Analyzed
9.0KEVEPSS 1.000
CVE-2026-23526
CVAT vulnerable to privilege escalation of users with staff status
Published 2026-01-21 · Analyzed
8.8EPSS 0.003
CVE-2026-23516
CVAT vulnerable to XSS via skeleton SVG images
Published 2026-01-21 · Analyzed
8.6EPSS 0.002
CVE-2024-37164
CVAT SSRF via custom cloud storage endpoints
Published 2024-06-13 · Analyzed
8.5EPSS 0.003
CVE-2024-37306
CVAT's export and backup-related API endpoints are susceptible to CSRF
Published 2024-06-13 · Analyzed
7.1EPSS 0.002
CVE-2025-49135
CVAT missing validation for in-progress backup upload names
Published 2025-06-25 · Analyzed
6.5EPSS 0.003
CVE-2025-54573
CVAT vulnerable to email verification bypass by use of basic authentication
Published 2025-07-30 · Analyzed
6.5EPSS 0.003
CVE-2024-45393
Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries
Published 2024-09-10 · Analyzed
6.4EPSS 0.002
CVE-2024-47064
Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints
Published 2024-09-30 · Analyzed
6.3EPSS 0.003
CVE-2024-47063
Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint
Published 2024-09-30 · Analyzed
6.2EPSS 0.003
CVE-2024-47172
Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints
Published 2024-09-30 · Analyzed
5.4EPSS 0.003
CVE-2026-58373
CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence
Published 2026-06-30 · Analyzed
5.3EPSS 0.003
CVE-2025-68430
CVAT vulnerable to directory traversal via mounted share listing
Published 2025-12-19 · Analyzed
5.3EPSS 0.003
CVE-2025-48381
CVAT has information disclosure via browsable API
Published 2025-05-30 · Analyzed
5.3EPSS 0.003