VendorsAimStackaimall versions
Vulnerabilities

AimStack Aim

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2025-5321
aimhubio aim run_view Object query.py RestrictedPythonQuery privilege escalation
Published 2025-05-29 · Analyzed
9.9EPSS 0.006
CVE-2024-6396
Arbitrary File Overwrite and Data Exfiltration in aimhubio/aim
Published 2024-07-12 · Analyzed
9.8EPSS 0.531
CVE-2024-2195
Remote Code Execution in aimhubio/aim
Published 2024-04-10 · Analyzed
9.8EPSS 0.018
CVE-2024-7760
CSRF in aimhubio/aim
Published 2025-03-20 · Analyzed
9.6EPSS 0.005
CVE-2024-8769
Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim
Published 2025-03-20 · Modified
9.1EPSS 0.009
CVE-2024-6829
Arbitrary File Overwrite through tarfile-extraction in aimhubio/aim
Published 2025-03-20 · Analyzed
9.1EPSS 0.009
CVE-2025-51464
Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and executed by Pyodide when the report is viewed. No sanitisation or sandbox restrictions prevent JavaScript execution via pyodide.code.run_js().
Published 2025-07-22 · Analyzed
8.8EPSS 0.006
CVE-2024-2196
CSRF Vulnerability in aimhubio/aim
Published 2024-04-10 · Analyzed
8.8EPSS 0.006
CVE-2021-43775
Arbitrary file reading vulnerability in Aim
Published 2021-11-23 · Modified
8.6EPSS 0.019
CVE-2024-8238
Unrestricted Code Execution in aimhubio/aim
Published 2025-03-20 · Modified
8.1EPSS 0.008
CVE-2024-6851
Arbitrary File Deletion in aimhubio/aim
Published 2025-03-20 · Analyzed
7.5EPSS 0.010
CVE-2024-12778
Denial of Service in aimhubio/aim
Published 2025-03-20 · Modified
7.5EPSS 0.008
CVE-2025-0189
Denial of Service in aimhubio/aim
Published 2025-03-20 · Modified
7.5EPSS 0.006
CVE-2024-10110
Denial of Service in aimhubio/aim
Published 2025-03-20 · Analyzed
7.5EPSS 0.006
CVE-2025-0190
Denial of Service in aimhubio/aim
Published 2025-03-20 · Analyzed
7.5EPSS 0.006
CVE-2024-6227
Infinite Loop in aimhubio/aim
Published 2024-07-08 · Modified
7.5EPSS 0.006
CVE-2024-8061
Denial of Service in aimhubio/aim
Published 2025-03-20 · Modified
7.5EPSS 0.005
CVE-2024-8101
Stored XSS in aimhubio/aim
Published 2025-03-20 · Analyzed
7.2EPSS 0.004
CVE-2024-6578
Stored XSS in aimhubio/aim
Published 2024-07-29 · Modified
7.2EPSS 0.003
CVE-2025-51463
Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted without path validation during restoration.
Published 2025-07-22 · Analyzed
7.0EPSS 0.005
CVE-2024-12777
Denial of Service in aimhubio/aim
Published 2025-03-20 · Analyzed
5.9EPSS 0.005
CVE-2024-8863
aimhubio aim Text Explorer textbox.tsx dangerouslySetInnerHTML cross site scripting
Published 2024-09-14 · Analyzed
5.4EPSS 0.005
CVE-2024-6483
Arbitrary File/Directory Deletion in aimhubio/aim
Published 2025-03-20 · Analyzed
5.3EPSS 0.009