40 Total advisories
40 Vulnerabilities
0 Malware

Dependency scanning

Check whether aim is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.3
PyPI

CVE-2025-5321

Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution

CRITICAL 9.1
PyPI

CVE-2024-8769

Aim path traversal in LockManager.release_locks

UNKNOWN
PyPI

CVE-2025-51464

Aim vulnerable to Cross-site Scripting

LOW 3.5
PyPI

CVE-2024-8863

Aim Stored XSS through TEXT EXPLORER

CRITICAL 9.8
PyPI

CVE-2024-2195

Aim Web API vulnerable to Remote Code Execution

HIGH 8.6
PyPI

CVE-2021-43775

Arbitrary file reading vulnerability in Aim

MEDIUM 5.3
PyPI

CVE-2024-6483

Aim Relative Path Traversal vulnerability

HIGH 7.5
PyPI

CVE-2024-6851

Aim Path Traversal vulnerability

HIGH 7.5
PyPI

CVE-2025-0190

Aim Excessive Data Query Operations in a Large Data Table vulnerability

HIGH 7.5
PyPI

CVE-2024-12778

Aim Uncontrolled Resource Consumption vulnerability

MEDIUM 5.9
PyPI

CVE-2024-8238

Aim Improper Access Control

HIGH 7.4
PyPI

CVE-2024-7760

Aim vulnerable to Cross-Site Request Forgery

HIGH 7.5
PyPI

CVE-2024-10110

Aim Vulnerable to Denial of Service (DoS)

HIGH 7.5
PyPI

CVE-2025-0189

Aim Uncontrolled Resource Consumption vulnerability

MEDIUM 6.1
PyPI

CVE-2024-6578

Aim Stored Cross-site Scripting Vulnerability

HIGH 8.8
PyPI

CVE-2024-2196

Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations

HIGH 7.5
PyPI

CVE-2024-6227

Aim denial of service vulnerability

MEDIUM 5.9
PyPI

CVE-2024-12777

Aim vulnerable to Synchronous Access of Remote Resource without Timeout

HIGH 7.5
PyPI

CVE-2024-8061

Aim allows denial of service due to no timeouts for some tracking server endpoints

HIGH 7.5
PyPI

CVE-2025-0190

Aim Excessive Data Query Operations in a Large Data Table vulnerability

UNKNOWN
PyPI

CVE-2025-51464

Aim vulnerable to Cross-site Scripting

MEDIUM 6.3
PyPI

CVE-2025-5321

Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution

HIGH 7.5
PyPI

CVE-2024-10110

Aim Vulnerable to Denial of Service (DoS)

HIGH 8.8
PyPI

CVE-2024-2196

Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations

HIGH 7.5
PyPI

CVE-2024-8061

Aim allows denial of service due to no timeouts for some tracking server endpoints

HIGH 7.5
PyPI

CVE-2024-12778

Aim Uncontrolled Resource Consumption vulnerability

HIGH 7.5
PyPI

CVE-2024-6227

Aim denial of service vulnerability

HIGH 7.4
PyPI

CVE-2024-7760

Aim vulnerable to Cross-Site Request Forgery

MEDIUM 5.9
PyPI

CVE-2024-12777

Aim vulnerable to Synchronous Access of Remote Resource without Timeout

MEDIUM 5.9
PyPI

CVE-2024-8238

Aim Improper Access Control

HIGH 7.5
PyPI

CVE-2024-6851

Aim Path Traversal vulnerability

MEDIUM 5.3
PyPI

CVE-2024-6483

Aim Relative Path Traversal vulnerability

LOW 3.5
PyPI

CVE-2024-8863

Aim Stored XSS through TEXT EXPLORER

MEDIUM 6.1
PyPI

CVE-2024-6578

Aim Stored Cross-site Scripting Vulnerability

HIGH 7.5
PyPI

CVE-2025-0189

Aim Uncontrolled Resource Consumption vulnerability

CRITICAL 9.8
PyPI

CVE-2024-2195

Aim Web API vulnerable to Remote Code Execution

CRITICAL 9.1
PyPI

CVE-2024-6829

Aim External Control of File Name or Path vulnerability

CRITICAL 9.1
PyPI

CVE-2024-8769

Aim path traversal in LockManager.release_locks

CRITICAL 9.1
PyPI

CVE-2024-6829

Aim External Control of File Name or Path vulnerability

UNKNOWN
PyPI

CVE-2021-43775

CVE-2021-43775

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes