Aimstack / Aim
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-51464 | Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitt… | MEDIUM | 5.3 | Jul 22, 2025 |
| CVE-2025-51463 | Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file… | HIGH | 7.0 | Jul 22, 2025 |
| CVE-2025-5321 | aimhubio aim run_view Object query.py RestrictedPythonQuery privilege escalation | MEDIUM | 5.3 | May 29, 2025 |
| CVE-2024-8101 | Stored XSS in aimhubio/aim | MEDIUM | 6.1 | Mar 20, 2025 |
| CVE-2024-8769 | Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim | CRITICAL | 9.1 | Mar 20, 2025 |
| CVE-2024-12777 | Denial of Service in aimhubio/aim | MEDIUM | 5.9 | Mar 20, 2025 |
| CVE-2024-8238 | Unrestricted Code Execution in aimhubio/aim | HIGH | 8.1 | Mar 20, 2025 |
| CVE-2025-0189 | Denial of Service in aimhubio/aim | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2024-6829 | Arbitrary File Overwrite through tarfile-extraction in aimhubio/aim | CRITICAL | 9.1 | Mar 20, 2025 |
| CVE-2024-12778 | Denial of Service in aimhubio/aim | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2024-8061 | Denial of Service in aimhubio/aim | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2024-6851 | Arbitrary File Deletion in aimhubio/aim | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2024-6483 | Arbitrary File/Directory Deletion in aimhubio/aim | MEDIUM | 5.3 | Mar 20, 2025 |
| CVE-2024-10110 | Denial of Service in aimhubio/aim | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2024-7760 | CSRF in aimhubio/aim | CRITICAL | 9.6 | Mar 20, 2025 |
| CVE-2025-0190 | Denial of Service in aimhubio/aim | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2024-8863 | aimhubio aim Text Explorer textbox.tsx dangerouslySetInnerHTML cross site scripting | MEDIUM | 5.3 | Sep 14, 2024 |
| CVE-2024-6578 | Stored XSS in aimhubio/aim | MEDIUM | 5.3 | Jul 29, 2024 |
| CVE-2024-6396 | Arbitrary File Overwrite and Data Exfiltration in aimhubio/aim | CRITICAL | 9.8 | Jul 12, 2024 |
| CVE-2024-6227 | Infinite Loop in aimhubio/aim | HIGH | 8.7 | Jul 8, 2024 |
| CVE-2024-2195 | Remote Code Execution in aimhubio/aim | CRITICAL | 9.8 | Apr 10, 2024 |
| CVE-2024-2196 | CSRF Vulnerability in aimhubio/aim | HIGH | 8.8 | Apr 10, 2024 |
| CVE-2021-43775 | Arbitrary file reading vulnerability in Aim | CRITICAL | 9.2 | Nov 23, 2021 |
Showing 1 to 23 of 23 CVEs