AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 766 results — Active exploitation, no patchwpbot: missing auth exposes OpenAI account files
CVE-2024-0451 MLflow: broken access control allows artifact deletion
CVE-2024-4263 llama_index: RCE via eval() in RunGptLLM connector
CVE-2024-4181 MLflow: URL fragment bypass leaks SSH and cloud keys
CVE-2024-3848 llama-cpp-python: SSTI in .gguf loader enables RCE
CVE-2024-34359 Gradio: credential leakage via Windows path encoding bug
CVE-2024-34510 PyTorch: heap buffer overflow causes local DoS
CVE-2024-31580 Keras: RCE via malicious model deserialization
CVE-2024-3660 MLflow: LFI via URI parsing allows arbitrary file read
CVE-2024-3573 LangChain: path traversal allows arbitrary file R/W
CVE-2024-3571 BentoML: RCE via insecure deserialization (CVSS 10)
CVE-2024-2912 MLflow: path traversal via URI fragment reads arbitrary files
CVE-2024-1594 MLflow: path traversal via ';' smuggling exposes files
CVE-2024-1593 Gradio: path traversal enables arbitrary file read
CVE-2024-1561 MLflow: path traversal allows arbitrary directory deletion
CVE-2024-1560 MLflow: path traversal enables arbitrary file read
CVE-2024-1558 MLflow: path traversal exposes arbitrary server files
CVE-2024-1483 Gradio: SSRF enables internal network port scanning
CVE-2024-1183 HuggingFace Transformers: RCE via pickle deserialization
CVE-2024-3568 Gradio: path traversal leaks arbitrary files, potential RCE
CVE-2024-1728 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert