Products: 1
Vulnerabilities: 9
Known Exploited: 0
2
Critical Level Threats
4
High Level Threats
2
Medium Level Threats
1
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-85663
Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch
Last Modified: Sep 04, 2026
Published: Sep 04, 2026
CVE-2025-51464
Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and executed by Pyodide when the report is viewed. No sanitisation or sandbox restrictions prevent JavaScript execution via pyodide.code.run_js().
Last Modified: Sep 11, 2025
Published: Jul 22, 2025
CVE-2025-5321
aimhubio aim run_view Object query.py RestrictedPythonQuery privilege escalation
Last Modified: Sep 19, 2025
Published: May 29, 2025
CVE-2024-8061
Denial of Service in aimhubio/aim
Last Modified: Oct 15, 2025
Published: Mar 20, 2025
CVE-2024-6851
Arbitrary File Deletion in aimhubio/aim
Last Modified: Jul 23, 2025
Published: Mar 20, 2025
Items Per Page
