AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 766 results — Active exploitation, no patchOllama: path traversal exposes server filesystem
CVE-2024-39722 Ollama: DoS via /dev/random causes goroutine exhaustion
CVE-2024-39721 Ollama: OOB read in GGUF parser enables remote DoS
CVE-2024-39720 Ollama: file existence oracle via api/create errors
CVE-2024-39719 Langflow: Unauthenticated RCE via PythonCodeTool
CVE-2024-42835 PyTorch: RCE via RemoteModule deserialization
CVE-2024-48063 Lollms: SVG upload XSS enables session hijack and RCE
CVE-2024-6581 LangChain GraphCypher: prompt injection enables DB wipe
CVE-2024-8309 LangChain.js: path traversal, arbitrary file read/write
CVE-2024-7774 LangChainJS: prompt injection enables full graph DB takeover
CVE-2024-7042 Affiliator WP Plugin: Unauthenticated Web Shell Upload
CVE-2024-49326 lollms: path traversal allows arbitrary directory read
CVE-2024-6985 lollms: path traversal in RAG database functions
CVE-2024-6971 Gradio: path traversal leaks arbitrary server files
CVE-2024-47868 open-webui: filesystem enumeration via admin error messages
CVE-2024-7038 open-webui: path traversal → arbitrary file write/RCE
CVE-2024-7037 open-webui: IDOR enables cross-user memory tampering
CVE-2024-7041 Langflow: ReDoS crashes LLM workflow backend via HTTP POST
CVE-2024-9277 AYS ChatGPT WP Plugin: auth bypass disables AI service
CVE-2024-7714 ChatGPT WP Plugin: OpenAI API key leak via unauth REST
CVE-2024-6845 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert