Computer Vision Annotation Tool
Vendor:
First CVE: Dec 14, 2021 · Active for 4 years
16
Total CVEs
More Total CVEs than 92% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
6.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Computer Vision Annotation Tool over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 14, 2021
4 years ago
Most Recent CVE
Jun 30, 2026
24 days ago
CVE Severity & Scoring
Computer Vision Annotation Tool16 CVEs
63%
19%
19%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None12 (75.0%)
Unknown0 (0.0%)
Required4 (25.0%)
Privileges Required
Low10 (62.5%)
High0 (0.0%)
None6 (37.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45046CRITICAL It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Threa | Dec 14, 2021 | 9.0 | 98 | YES | YES |
CVE-2022-31188CRITICAL CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vuln | Aug 1, 2022 | 9.8 | 68 | NO | YES |
CVE-2026-23526HIGH CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their p | Jan 21, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-23045CRITICAL Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to ru | Jan 28, 2025 | 9.8 | 27 | NO | NO |
CVE-2026-58373MEDIUM CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers | Jun 30, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-23516MEDIUM CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a v | Jan 21, 2026 | 5.4 | 23 | NO | NO |
CVE-2024-37164HIGH Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages ba | Jun 13, 2024 | 8.5 | 23 | NO | NO |
CVE-2025-54573MEDIUM CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP | Jul 30, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-37306HIGH Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker | Jun 13, 2024 | 7.1 | 20 | NO | NO |
CVE-2025-49135MEDIUM CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the import process of a project or t | Jun 25, 2025 | 6.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
1 CVE
6.2% of CVEs· 97th percentile
Metasploit
1 CVE
6.2% of CVEs· 97th percentile
Nuclei
1 CVE
6.2% of CVEs· 97th percentile
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Computer Vision Annotation Tool
Top CWEs
Versions
No cataloged versions.