AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

77

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 910 results — Active exploitation
UNKNOWN EXPLOIT AVAIL

lollms-webui: RCE via malicious GGUF model loading

CVE-2024-4897
--
EPSS 0.8%
Supply Chain Code Execution Framework Model Inference
6 ATLAS
CRITICAL EXPLOIT AVAIL

Gradio: code injection via component metadata (CVSS 9.8)

CVE-2024-39236
9.8
EPSS 1.9%
Code Execution Supply Chain Framework Inference
gradio 679 4 ATLAS
MEDIUM EXPLOIT AVAIL

Flowise: reflected XSS enables credential theft

CVE-2024-37146
6.1
EPSS 0.3%
Data Extraction Auth Bypass Social Engineering Agent Framework
flowise CWE-79 5 ATLAS
MEDIUM EXPLOIT AVAIL

Flowise: reflected XSS enables file read chain via chatflow

CVE-2024-37145
6.1
EPSS 0.4%
Code Execution Data Extraction Privacy Violation Agent Framework
flowise CWE-79 5 ATLAS
MEDIUM EXPLOIT AVAIL

Flowise: reflected XSS in chatflow API enables session hijack

CVE-2024-36423
6.1
EPSS 0.3%
Data Extraction Auth Bypass Code Execution Framework Agent
flowise CWE-79 5 ATLAS
MEDIUM EXPLOIT AVAIL

Flowise: reflected XSS enables session hijack and file read

CVE-2024-36422
6.1
EPSS 0.2%
Data Leakage Data Extraction Framework Agent
flowise CWE-79 4 ATLAS
HIGH EXPLOIT AVAIL

Flowise: CORS wildcard enables file read and data theft

CVE-2024-36421
7.5
EPSS 1.6%
Data Extraction Auth Bypass Data Leakage Agent Framework
flowise CWE-346 5 ATLAS
HIGH EXPLOIT AVAIL

Flowise: unauthenticated arbitrary file read via API

CVE-2024-36420
7.5
EPSS 0.3%
Data Extraction Auth Bypass Data Leakage Framework API Agent
flowise CWE-74 6 ATLAS
LOW EXPLOIT AVAIL

lollms-webui: CSRF allows unauthorized AI service install

CVE-2024-4839
3.3
EPSS 0.0%
Supply Chain Auth Bypass Inference Framework
lollms-webui 4 ATLAS
MEDIUM EXPLOIT AVAIL SCANNER

Gradio: open redirect enables phishing against ML users

CVE-2024-4940
6.1
EPSS 7.2%
Social Engineering Privacy Violation Framework Inference
gradio 679 5 ATLAS
HIGH EXPLOIT AVAIL

LangChain: Python REPL code execution without opt-in

CVE-2024-38459
7.8
EPSS 0.1%
Code Execution Prompt Injection Data Extraction Framework Agent
langchain-experimental 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

Langflow: unauthenticated RCE via custom component API

CVE-2024-37014
9.8
EPSS 6.5%
Code Execution Auth Bypass Supply Chain Framework Agent API
langflow CWE-94 5 ATLAS
HIGH EXPLOIT AVAIL

ONNX: path traversal in model download enables RCE

CVE-2024-5187
8.8
EPSS 1.4%
Supply Chain Code Execution Framework Model
onnx Patch: 1.16.2 CWE-22 1.2K 4 ATLAS
MEDIUM EXPLOIT AVAIL

langchain-community: DoS via recursive sitemap loop

CVE-2024-2965
4.2
EPSS 0.0%
DoS Supply Chain Framework RAG
langchain Patch: 0.2.5 CWE-400 2.6K 3 ATLAS
MEDIUM EXPLOIT AVAIL

scikit-learn: TfidfVectorizer leaks training data tokens

CVE-2024-5206
4.7
EPSS 0.0%
Data Leakage Data Extraction Privacy Violation Framework Training Data
scikit-learn CWE-922 28.2K 5 ATLAS
HIGH EXPLOIT AVAIL

litellm: arbitrary file deletion via audio endpoint

CVE-2024-4888
8.1
EPSS 0.1%
Auth Bypass DoS Framework API
litellm 4 3 ATLAS
CRITICAL EXPLOIT AVAIL SCANNER

ChuanhuChatGPT: path traversal exposes LLM API keys

CVE-2024-3234
9.8
EPSS 84.0%
Data Extraction Auth Bypass Data Leakage Framework API
chuanhuchatgpt 5 ATLAS
MEDIUM EXPLOIT AVAIL

MLflow: URL encoding bypass enables model poisoning

CVE-2024-3099
5.4
EPSS 0.1%
Model Poisoning DoS Framework Model
mlflow 624 5 ATLAS
HIGH EXPLOIT AVAIL

LangChain: SSRF in Web Retriever exposes cloud metadata

CVE-2024-3095
7.7
EPSS 0.2%
Data Extraction Auth Bypass Framework Agent RAG
langchain 2.6K 4 ATLAS
HIGH EXPLOIT AVAIL SCANNER

MLflow: URI fragment LFI exposes arbitrary files

CVE-2024-2928
7.5
EPSS 91.6%
Data Extraction Supply Chain Framework Model Training Data
mlflow CWE-22 624 6 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial