Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aim HIGH 8.8
CVE-2025-51464

Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python co…

Patch available
Fix from $1,950 2025-07-22
Aim HIGH 7.0
CVE-2025-51463

Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup…

Patch available
Fix from $1,950 2025-07-22
Aim CRITICAL 9.9
CVE-2025-5321

A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the f…

Fix: after 3.29.1
Fix from $2,300 2025-05-29
Aim HIGH 7.5
CVE-2025-0189

In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websock…

No fix yet
Fix from $1,950 2025-03-20
Aim HIGH 7.5
CVE-2025-0190

In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simu…

No fix yet
Fix from $1,950 2025-03-20
Aim CRITICAL 9.1
CVE-2024-8769

A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path…

Fix: 3.24.0+
Fix from $2,300 2025-03-20
Aim HIGH 8.1
CVE-2024-8238

In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This vers…

No fix yet
Fix from $1,950 2025-03-20
Aim MEDIUM 6.1
CVE-2024-8101

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due …

No fix yet
Fix from $1,600 2025-03-20
Aim HIGH 7.5
CVE-2024-8061

In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indef…

No fix yet
Fix from $1,950 2025-03-20
Aim CRITICAL 9.6
CVE-2024-7760

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly per…

No fix yet
Fix from $2,300 2025-03-20
Aim HIGH 7.5
CVE-2024-6851

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleti…

No fix yet
Fix from $1,950 2025-03-20
Aim CRITICAL 9.1
CVE-2024-6829

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a malicio…

No fix yet
Fix from $2,300 2025-03-20
Aim MEDIUM 5.3
CVE-2024-6483

A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path trave…

No fix yet
Fix from $1,600 2025-03-20
Aim HIGH 7.5
CVE-2024-12778

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics a…

No fix yet
Fix from $1,950 2025-03-20
Aim MEDIUM 5.9
CVE-2024-12777

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is s…

No fix yet
Fix from $1,600 2025-03-20
Aim HIGH 7.5
CVE-2024-10110

In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading t…

No fix yet
Fix from $1,950 2025-03-20
Aim MEDIUM 5.4
CVE-2024-8863

A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the f…

Fix: after 3.24.0
Fix from $1,600 2024-09-14
Aim MEDIUM 5.4
CVE-2024-6578

A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of…

No fix yet
Fix from $1,600 2024-07-29
Aim CRITICAL 9.8
CVE-2024-6396EPSS 53%

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exf…

No fix yet
Fix from $2,300 2024-07-12
Aim HIGH 7.5
CVE-2024-6227

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at its…

No fix yet
Fix from $1,950 2024-07-08
Aim CRITICAL 9.8
CVE-2024-2195

A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endp…

No fix yet
Fix from $2,300 2024-04-10
Aim HIGH 8.8
CVE-2024-2196

aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stea…

No fix yet
Fix from $1,950 2024-04-10
Aim HIGH 8.6
CVE-2021-43775

Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attac…

Fix: 3.1.0+
Fix from $1,950 2021-11-23