Aim
Vendor:
First CVE: Nov 23, 2021 · Active for 4 years
23
Total CVEs
More Total CVEs than 95% of tracked products
7.7
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Aim over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2021
4 years ago
Most Recent CVE
Jul 22, 2025
367 days ago
CVE Severity & Scoring
Aim23 CVEs
22%
52%
26%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None17 (73.9%)
Unknown0 (0.0%)
Required6 (26.1%)
Privileges Required
Low3 (13.0%)
High0 (0.0%)
None20 (87.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6396CRITICAL A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vul | Jul 12, 2024 | 9.8 | 68 | NO | YES |
CVE-2024-2195CRITICAL A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0 | Apr 10, 2024 | 9.8 | 30 | NO | NO |
CVE-2021-43775HIGH Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables th | Nov 23, 2021 | 8.6 | 28 | NO | NO |
CVE-2025-5321CRITICAL A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of th | May 29, 2025 | 9.9 | 27 | NO | NO |
CVE-2024-7760CRITICAL aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing | Mar 20, 2025 | 9.6 | 25 | NO | NO |
CVE-2025-51464HIGH Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/report | Jul 22, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-8769CRITICAL A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` para | Mar 20, 2025 | 9.1 | 24 | NO | NO |
CVE-2024-6829CRITICAL A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitra | Mar 20, 2025 | 9.1 | 24 | NO | NO |
CVE-2024-8238HIGH In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against th | Mar 20, 2025 | 8.1 | 22 | NO | NO |
CVE-2024-2196HIGH aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stealing data like log records and | Apr 10, 2024 | 8.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Aim
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.28.0 | 2 | 7.9 | 0.5% | 0 | 0 |
| 3.25.0 | 4 | 7.1 | 0.6% | 0 | 0 |
| 3.23.0 | 3 | 7.0 | 0.5% | 0 | 0 |
| 3.22.0 | 3 | 8.4 | 0.7% | 0 | 0 |
| 3.19.3 | 5 | 7.4 | 11.1% | 0 | 1 |
| 3.17.5 | 1 | 8.8 | 0.6% | 0 | 0 |