Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-0189 In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websock… Aim No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2025-0190 In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simu… Aim No fix yet Fix from $1,9502025-03-20 HIGH 8.1 CVE-2024-8238 In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This vers… Aim No fix yet Fix from $1,9502025-03-20 MEDIUM 6.1 CVE-2024-8101 A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due … Aim No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-8061 In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indef… Aim No fix yet Fix from $1,9502025-03-20 CRITICAL 9.6 CVE-2024-7760 aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly per… Aim No fix yet Fix from $2,3002025-03-20 HIGH 7.5 CVE-2024-6851 In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleti… Aim No fix yet Fix from $1,9502025-03-20 CRITICAL 9.1 CVE-2024-6829 A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a malicio… Aim No fix yet Fix from $2,3002025-03-20 MEDIUM 5.3 CVE-2024-6483 A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path trave… Aim No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-12778 A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics a… Aim No fix yet Fix from $1,9502025-03-20 MEDIUM 5.9 CVE-2024-12777 A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is s… Aim No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-10110 In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading t… Aim No fix yet Fix from $1,9502025-03-20 MEDIUM 5.4 CVE-2024-6578 A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of… Aim No fix yet Fix from $1,6002024-07-29 CRITICAL 9.8 CVE-2024-6396EPSS 53% A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exf… Aim No fix yet Fix from $2,3002024-07-12 HIGH 7.5 CVE-2024-6227 A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at its… Aim No fix yet Fix from $1,9502024-07-08 CRITICAL 9.8 CVE-2024-2195 A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endp… Aim No fix yet Fix from $2,3002024-04-10 HIGH 8.8 CVE-2024-2196 aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stea… Aim No fix yet Fix from $1,9502024-04-10