Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2025-51464MediumAim vulnerable to Cross-site Scripting
CVE-2025-5321Medium· 6.3Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
CVE-2024-8769Critical· 9.1Aim path traversal in LockManager.release_locks
CVE-2024-12777Medium· 5.9Aim vulnerable to Synchronous Access of Remote Resource without Timeout
CVE-2024-8238Medium· 5.9Aim Improper Access Control
CVE-2024-6483Medium· 5.3Aim Relative Path Traversal vulnerability
CVE-2024-6851High· 7.5Aim Path Traversal vulnerability
CVE-2025-0189High· 7.5Aim Uncontrolled Resource Consumption vulnerability
CVE-2024-10110High· 7.5Aim Vulnerable to Denial of Service (DoS)
CVE-2025-0190High· 7.5Aim Excessive Data Query Operations in a Large Data Table vulnerability
CVE-2024-8061High· 7.5Aim allows denial of service due to no timeouts for some tracking server endpoints
CVE-2024-7760High· 7.4Aim vulnerable to Cross-Site Request Forgery
CVE-2024-12778High· 7.5Aim Uncontrolled Resource Consumption vulnerability
CVE-2024-8863Low· 3.5Aim Stored XSS through TEXT EXPLORER
CVE-2024-6578Medium· 6.1Aim Stored Cross-site Scripting Vulnerability
CVE-2024-6227High· 7.5Aim denial of service vulnerability
CVE-2024-2195Critical· 9.8Aim Web API vulnerable to Remote Code Execution
CVE-2024-2196High· 8.8Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
CVE-2021-43775High· 8.6Arbitrary file reading vulnerability in Aim
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.