Cvat-ai
4 CVEs tracked since 2024. Since Sep 2024, none of them reached CISA KEV.
Cvat-ai CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-09 | 4 | 0 |
Products
The products that kept showing up in Cvat-ai's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Cvat-ai.
- CVE-2026-73220CVAT: Stored XSS via annotation guides in audio tasks—
- CVE-2026-73221CVAT: Flawed authorization logic in endpoints related to lambda requests—
- CVE-2026-73219CVAT: Denial of service with regards to automatic annotation—
- CVE-2026-65986CVAT has stored XSS via annotation guide assets—
- CVE-2026-47682CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes—
- CVE-2026-58373CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence4.3
- CVE-2026-44369CVAT: Stored XSS via annotation guides—
- CVE-2026-23526CVAT vulnerable to privilege escalation of users with staff status8.8
- CVE-2026-23516CVAT vulnerable to XSS via skeleton SVG images5.4
- CVE-2025-68430CVAT vulnerable to directory traversal via mounted share listing4.3
- CVE-2025-64485CVAT: Mounted share file overwrite via crafted request—
- CVE-2025-54573CVAT vulnerable to email verification bypass by use of basic authentication4.3
- CVE-2025-49135CVAT missing validation for in-progress backup upload names6.5
- CVE-2025-48381CVAT has information disclosure via browsable API4.3
- CVE-2025-23045CVAT allows remote code execution via tracker Nuclio functions9.8
The record
- Peak rank
- #153 in Sep 2024
- Busiest month shown
- Sep 2024, 4 CVEs
- Months with a KEV entry
- 0 since Sep 2024
- Monthly snapshots
- 1 since 2024