Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aimstack

First CVE: Nov 23, 2021Active for: 5 yearsTotal CVEs: 23
52.4
VTI Score
TOP TARGET

Aimstack's vulnerability footprint concentrates in its AIM product, a narrowly scoped offering that nonetheless ranks among the more prominent vendors in the vulnerability landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the product's role in handling sensitive data and administrative functions where input validation and resource-management failures carry outsized consequences. The exposure recurs through weakness classes including path traversal, cross-site scripting, resource-exhaustion conditions, cross-site request forgery, and remote-resource access without timeout—a pattern characteristic of web-facing administrative tools where parser robustness, input sanitization, and rate-limiting are essential controls. Defenders should treat Aimstack advisories as high-priority, particularly those affecting internet-reachable instances; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
7.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Aimstack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2021
4 years ago
Most Recent CVE
Jul 22, 2025
367 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-6396CRITICAL
A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vul
Jul 12, 20249.868NOYES
CVE-2024-2195CRITICAL
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0
Apr 10, 20249.830NONO
CVE-2021-43775HIGH
Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables th
Nov 23, 20218.628NONO
CVE-2025-5321CRITICAL
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of th
May 29, 20259.927NONO
CVE-2024-7760CRITICAL
aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing
Mar 20, 20259.625NONO
CVE-2025-51464HIGH
Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/report
Jul 22, 20258.824NONO
CVE-2024-8769CRITICAL
A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` para
Mar 20, 20259.124NONO
CVE-2024-6829CRITICAL
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitra
Mar 20, 20259.124NONO
CVE-2024-8238HIGH
In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against th
Mar 20, 20258.122NONO
CVE-2024-2196HIGH
aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stealing data like log records and
Apr 10, 20248.822NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
22%
52%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None17 (73.9%)
Unknown0 (0.0%)
Required6 (26.1%)
Privileges Required
Low3 (13.0%)
High0 (0.0%)
None20 (87.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aimstack.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aimstack — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aimstack's Products

View all 4 CNAs →

Top CWEs