CVE-2024-45393
- EPSS 0.32%
- Veröffentlicht 10.09.2024 15:15:18
- Zuletzt bearbeitet 21.01.2025 14:33:37
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of o...
CVE-2024-37306
- EPSS 0.27%
- Veröffentlicht 13.06.2024 15:15:53
- Zuletzt bearbeitet 21.01.2025 14:37:34
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into visiting a malicious URL, they ca...
CVE-2024-37164
- EPSS 0.28%
- Veröffentlicht 13.06.2024 15:15:52
- Zuletzt bearbeitet 21.01.2025 14:35:52
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages based on Amazon S3 and Azure Blob Storage. Starting in version 2.1.0 and...
CVE-2022-31188
- EPSS 35.73%
- Veröffentlicht 01.08.2022 20:15:08
- Zuletzt bearbeitet 20.02.2026 20:05:45
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code...
- EPSS 94.34%
- Veröffentlicht 14.12.2021 19:15:07
- Zuletzt bearbeitet 27.10.2025 17:35:56
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a n...