Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sim

First CVE: Jul 7, 2025Active for: 1 yearTotal CVEs: 10
47.2
VTI Score
High

Sim's vulnerability profile centers on a single, focused product line that ranks more prominently in the landscape than its modestly sized CVE footprint might suggest, indicating concentrated deployment or high operational criticality. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through a pattern of authentication, authorization, and access-control weaknesses—including improper authentication, path traversal, missing authorization, server-side request forgery, and unrestricted file uploads—that collectively expose the product to authentication bypass and arbitrary code execution. Defenders should prioritize patches for this vendor given the severity profile and the access-control-oriented nature of the recurring flaws; live exploitation activity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sim over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2025
12 months ago
Most Recent CVE
Mar 2, 2026
144 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-3431CRITICAL
On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can
Mar 2, 20269.834NONO
CVE-2026-3432CRITICAL
On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId`
Mar 2, 20269.131NONO
CVE-2025-15099CRITICAL
A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps/sim/lib/auth/internal.ts of the component CRON Secret Handl
Dec 26, 20259.831NONO
CVE-2025-10097CRITICAL
A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app/api/function/execute/route.ts. The manipulation of the argu
Sep 8, 20259.830NONO
CVE-2025-9800MEDIUM
A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of the file apps/sim/app/api/files/u
Sep 1, 20256.125NONO
CVE-2025-9805HIGH
A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unknown processing of the file apps/sim/app/api/proxy/image/rou
Sep 2, 20257.524NONO
CVE-2025-9801HIGH
A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manipulation of the argument filePat
Sep 1, 20258.124NONO
CVE-2025-10096MEDIUM
A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Executing manipulation of the arg
Sep 8, 20256.522NONO
CVE-2025-7114HIGH
A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulnerability is the function POST o
Jul 7, 20257.521NONO
CVE-2025-7107HIGH
A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. T
Jul 7, 20257.521NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
20%
40%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sim.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sim — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sim's Products

View all 2 CNAs →

Top CWEs