Aim是美国Aim开源的一个易于使用和高性能的开源实验跟踪器。 Aim 3.23.0版本存在安全漏洞,该漏洞源于Text Explorer组件使用dangerouslySetInnerHTML时未进行适当清理,允许在渲染跟踪文本时执行任意JavaScript。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aimhubio | aimhubio/aim | unspecified ~ latest | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-0189 | Denial of Service in aimhubio/aim | |
| CVE-2025-0190 | Denial of Service in aimhubio/aim | |
| CVE-2024-12777 | Denial of Service in aimhubio/aim | |
| CVE-2024-12778 | Denial of Service in aimhubio/aim | |
| CVE-2024-6851 | Arbitrary File Deletion in aimhubio/aim | |
| CVE-2024-6483 | Arbitrary File/Directory Deletion in aimhubio/aim | |
| CVE-2024-6829 | Arbitrary File Overwrite through tarfile-extraction in aimhubio/aim | |
| CVE-2024-7760 | CSRF in aimhubio/aim | |
| CVE-2024-8061 | Denial of Service in aimhubio/aim | |
| CVE-2024-8769 | Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim | |
| CVE-2024-8238 | Unrestricted Code Execution in aimhubio/aim | |
| CVE-2024-10110 | Denial of Service in aimhubio/aim |
No comments yet