AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

77

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 910 results — Active exploitation
Severity CVE ID Summary CVSS EPSS Package Date
HIGH E CVE-2023-6753 MLflow: path traversal exposes arbitrary file read/write 8.8 2.4% mlflow Dec 13 HIGH E CVE-2023-6709 MLflow: SSTI enables RCE in ML experiment tracking 8.8 0.3% mlflow Dec 12 MEDI E CVE-2023-6568 MLflow: reflected XSS via Content-Type header injection 6.1 33.4% mlflow Dec 7 HIGH E CVE-2023-43472 MLflow: unauth REST API leaks sensitive ML data 7.5 74.4% mlflow Dec 5 CRIT CVE-2023-48022 Ray: unauthenticated RCE via job submission API 9.8 92.2% ray Nov 28 CRIT E CVE-2023-6020 Ray: unauthenticated LFI exposes entire filesystem 9.3 81.4% ray Nov 16 CRIT E CVE-2023-6014 MLflow: auth bypass allows arbitrary account creation 9.8 0.9% mlflow Nov 16 CRIT E CVE-2023-6021 Ray: LFI allows unauthenticated file read 9.3 87.3% ray Nov 16 CRIT E CVE-2023-6019 Ray: unauthenticated RCE via dashboard command injection 9.8 88.8% ray Nov 16 CRIT E CVE-2023-6018 MLflow: unauth file overwrite enables model poisoning 9.8 91.3% mlflow Nov 16 HIGH E CVE-2023-6015 MLflow: unauthenticated arbitrary file write via PUT 7.5 0.8% mlflow Nov 16 CRIT E CVE-2023-5245 MLeap: zip slip in model loading enables RCE 9.8 0.4% Nov 15 HIGH E CVE-2023-32786 LangChain: prompt injection triggers SSRF via URL fetch 7.5 0.2% langchain Oct 20 HIGH CVE-2023-46229 LangChain: SSRF in URL loader exposes internal network 8.8 1.8% langchain Oct 19 CRIT CVE-2023-44467 LangChain: RCE bypass via __import__ in PAL chain 9.8 0.1% langchain_experimental Oct 9 CRIT CVE-2023-43654 TorchServe: SSRF + RCE via unrestricted model URL loading 9.8 91.6% torchserve Sep 28 CRIT E CVE-2023-39631 LangChain: RCE via numexpr evaluate injection 9.8 1.6% langchain Sep 1 CRIT E CVE-2023-36281 LangChain: RCE via malicious JSON prompt template 9.8 62.2% langchain Aug 22 CRIT E CVE-2023-39659 LangChain: RCE via unsanitized PythonAstREPL input 9.8 1.2% langchain Aug 15 CRIT E CVE-2023-38896 LangChain: RCE via unsandboxed LLM code execution 9.8 0.8% langchain Aug 15

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial