AI Security Threat Feed

Latest CVEs affecting AI/ML systems — LLM frameworks, ML libraries, AI agents, vector databases, and inference servers. Vulnerabilities are tracked from NVD, GitHub Advisory, CISA KEV, MITRE ATLAS, and enriched with CVSS, EPSS, exploitation confidence, AI-component classification, and compliance mappings to ISO 42001, EU AI Act, NIST AI RMF, and OWASP LLM Top 10. Updated continuously as new CVEs are published.

Each CVE is enriched with
  • CVSS severity
  • EPSS exploit probability
  • Exploitation confidence
  • AI-component classification
  • Compliance mappings
2,390

AI/ML CVEs Tracked

342

Critical

360

New This Week

18

In CISA KEV

Latest AI Security Threats

Showing 20 of 1074 results — Active exploitation
Severity CVE ID Summary CVSS EPSS Package Date
HIGH E CVE-2024-12704 llama-index: DoS via infinite loop in LangChain LLM 7.5 0.8% llamaindex Mar 20 MEDI E CVE-2024-12217 Gradio: NTFS ADS bypass exposes blocked file paths 5.3 0.6% gradio Mar 20 UNKN E CVE-2024-12065 LLaVA: path traversal allows arbitrary file read 0.9% Mar 20 HIGH E CVE-2024-12055 Ollama: DoS via malicious gguf model file upload 7.5 0.8% ollama Mar 20 CRIT E CVE-2024-11041 vllm: RCE via unsafe pickle deserialization in MessageQueue 9.8 1.4% vllm Mar 20 UNKN E CVE-2024-11037 gpt_academic: path traversal exposes LLM API keys 1.0% gpt_academic Mar 20 HIGH E CVE-2024-11031 GPT Academic: SSRF in Markdown plugin leaks credentials 7.5 0.6% gpt_academic Mar 20 HIGH E CVE-2024-11030 GPT Academic: SSRF via unsanitized HotReload plugin 7.5 0.6% gpt_academic Mar 20 UNKN E CVE-2024-10950 gpt_academic: RCE via unsandboxed prompt injection 1.3% gpt_academic Mar 20 MEDI E CVE-2024-10940 langchain-core: file read via prompt template inputs 5.3 0.4% langchain-core Mar 20 UNKN E CVE-2024-10707 ChuanhuChatGPT: path traversal exposes server files unauthed 0.7% chuanhuchatgpt Mar 20 UNKN E CVE-2024-10650 ChuanhuChatGPT: DoS via multipart payload exhaustion 0.7% chuanhuchatgpt Mar 20 HIGH E CVE-2024-10648 Gradio: path traversal enables arbitrary file deletion DoS 8.2 0.7% gradio Mar 20 HIGH E CVE-2024-10624 Gradio: ReDoS in DateTime causes CPU exhaustion DoS 7.5 1.0% gradio Mar 20 HIGH E CVE-2024-10569 Gradio: zip bomb DoS via dataframe CSV upload 7.5 0.6% gradio Mar 20 CRIT E CVE-2025-29783 vLLM: RCE via unsafe deserialization in Mooncake KV 9.0 0.8% vllm Mar 19 MEDI E CVE-2025-29770 vLLM: DoS via unbounded grammar cache exhausts disk 6.5 0.4% vllm Mar 19 CRIT E CVE-2025-1550 Keras: safe_mode bypass enables RCE via model loading 9.8 2.8% keras Mar 11 LOW E CVE-2025-2149 PyTorch: improper init in quantized sigmoid skews model output 2.5 0.2% torch Mar 10 HIGH E CVE-2025-2148 PyTorch: memory corruption in JIT profiler callback handler 7.5 0.4% torch Mar 10

Frequently asked questions

What is an AI security threat feed?

An AI security threat feed is a continuously updated stream of vulnerabilities (CVEs) affecting AI and machine-learning systems — LLM frameworks, ML libraries, AI agents, vector databases, and inference servers — filtered out of the broader CVE firehose and enriched for relevance.

Which sources are the AI CVEs tracked from?

CVEs are tracked from NVD, GitHub Advisory, CISA KEV, and MITRE ATLAS, then enriched with CVSS, EPSS, exploitation confidence, AI-component classification, and compliance mappings.

What AI systems do these vulnerabilities affect?

Coverage spans LLM frameworks, ML libraries, AI agents, vector databases, and inference servers — the components most security teams now run in production.

How often is the AI threat feed updated?

The feed updates continuously as new CVEs are published and enriched, so the most recent AI/ML vulnerabilities appear at the top.

Is the AI security feed free?

Yes — the public feed is free to browse. A Pro subscription adds breaking alerts, MITRE ATLAS mappings, compliance reports (ISO 42001, EU AI Act), and full CISO analysis.

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial