aim has 19 CVEs on record between 2021 and 2025. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- aim 19
Worst active — by depth score
CVE-2024-2195Critical· 9.8Aim Web API vulnerable to Remote Code Execution54CVE-2024-8769Critical· 9.1Aim path traversal in LockManager.release_locks50CVE-2024-2196High· 8.8Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations49CVE-2021-43775High· 8.6Arbitrary file reading vulnerability in Aim48CVE-2025-0190High· 7.5Aim Excessive Data Query Operations in a Large Data Table vulnerability41
aim vulnerabilities
CVEs affecting aim, newest first. Open any entry for full detail, references, and exploit status.
19 CVEsRSS
CVE-2025-51464MediumAim vulnerable to Cross-site Scripting
Aim vulnerable to Cross-site Scripting
CVE-2025-5321Medium· 6.3Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
CVE-2024-8769Critical· 9.1Aim path traversal in LockManager.release_locks
Aim path traversal in LockManager.release_locks
CVE-2024-12777Medium· 5.9Aim vulnerable to Synchronous Access of Remote Resource without Timeout
Aim vulnerable to Synchronous Access of Remote Resource without Timeout
CVE-2024-8238Medium· 5.9Aim Improper Access Control
Aim Improper Access Control
CVE-2024-6483Medium· 5.3Aim Relative Path Traversal vulnerability
Aim Relative Path Traversal vulnerability
CVE-2024-6851High· 7.5Aim Path Traversal vulnerability
Aim Path Traversal vulnerability
CVE-2025-0189High· 7.5Aim Uncontrolled Resource Consumption vulnerability
Aim Uncontrolled Resource Consumption vulnerability
CVE-2024-10110High· 7.5Aim Vulnerable to Denial of Service (DoS)
Aim Vulnerable to Denial of Service (DoS)
CVE-2025-0190High· 7.5Aim Excessive Data Query Operations in a Large Data Table vulnerability
Aim Excessive Data Query Operations in a Large Data Table vulnerability
CVE-2024-8061High· 7.5Aim allows denial of service due to no timeouts for some tracking server endpoints
Aim allows denial of service due to no timeouts for some tracking server endpoints
CVE-2024-7760High· 7.4Aim vulnerable to Cross-Site Request Forgery
Aim vulnerable to Cross-Site Request Forgery
CVE-2024-12778High· 7.5Aim Uncontrolled Resource Consumption vulnerability
Aim Uncontrolled Resource Consumption vulnerability
CVE-2024-8863Low· 3.5Aim Stored XSS through TEXT EXPLORER
Aim Stored XSS through TEXT EXPLORER
CVE-2024-6578Medium· 6.1Aim Stored Cross-site Scripting Vulnerability
Aim Stored Cross-site Scripting Vulnerability
CVE-2024-6227High· 7.5Aim denial of service vulnerability
Aim denial of service vulnerability
CVE-2024-2195Critical· 9.8Aim Web API vulnerable to Remote Code Execution
Aim Web API vulnerable to Remote Code Execution
CVE-2024-2196High· 8.8Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
CVE-2021-43775High· 8.6Arbitrary file reading vulnerability in Aim
Arbitrary file reading vulnerability in Aim