AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 267 results — Medium severity, Active exploitation
MEDIUM EXPLOIT AVAIL

Gradio: path traversal exposes arbitrary server files

CVE-2024-51751
6.5
EPSS 0.3%
Data Extraction Data Leakage Framework
gradio CWE-22 674 3 ATLAS
MEDIUM EXPLOIT AVAIL

Gradio: SSRF in DownloadButton exposes internal resources

CVE-2024-48052
6.5
EPSS 0.1%
Data Extraction Privacy Violation Framework Inference
gradio CWE-918 674 4 ATLAS
MEDIUM EXPLOIT AVAIL

Lollms: SVG upload XSS enables session hijack and RCE

CVE-2024-6581
6.5
EPSS 1.6%
Code Execution Data Leakage Social Engineering Framework API
lollms CWE-79 4 ATLAS
MEDIUM EXPLOIT AVAIL

lollms: path traversal allows arbitrary directory read

CVE-2024-6985
4.4
EPSS 0.1%
Data Extraction Auth Bypass Framework Agent
lollms CWE-23 4 ATLAS
MEDIUM EXPLOIT AVAIL

open-webui: path traversal → arbitrary file write/RCE

CVE-2024-7037
6.5
EPSS 2.3%
Code Execution Supply Chain Framework Plugin
open-webui CWE-22 4 ATLAS
MEDIUM EXPLOIT AVAIL

open-webui: IDOR enables cross-user memory tampering

CVE-2024-7041
6.5
EPSS 0.1%
Auth Bypass Model Poisoning Privacy Violation API Agent Framework
open-webui CWE-250 4 ATLAS
MEDIUM EXPLOIT AVAIL

Langflow: ReDoS crashes LLM workflow backend via HTTP POST

CVE-2024-9277
6.5
EPSS 0.2%
DoS Framework
langflow CWE-1333 3 ATLAS
MEDIUM EXPLOIT AVAIL SCANNER

ChatGPT WP Plugin: OpenAI API key leak via unauth REST

CVE-2024-6845
5.3
EPSS 21.6%
Data Extraction Auth Bypass API Plugin
CWE-862 5 ATLAS 1 incident
MEDIUM EXPLOIT AVAIL

ilab/vllm: best_of param causes inference API DoS

CVE-2024-8939
6.2
EPSS 0.0%
DoS Inference API
3 ATLAS
MEDIUM EXPLOIT AVAIL

Streamlit: path traversal leaks Windows NTLM hash

CVE-2024-42474
6.5
EPSS 1.7%
Data Leakage Auth Bypass Framework API
streamlit CWE-22 2.8K 4 ATLAS
MEDIUM EXPLOIT AVAIL

Flowise: reflected XSS enables credential theft

CVE-2024-37146
6.1
EPSS 0.3%
Data Extraction Auth Bypass Social Engineering Agent Framework
flowise CWE-79 5 ATLAS
MEDIUM EXPLOIT AVAIL

Flowise: reflected XSS enables file read chain via chatflow

CVE-2024-37145
6.1
EPSS 0.4%
Code Execution Data Extraction Privacy Violation Agent Framework
flowise CWE-79 5 ATLAS
MEDIUM EXPLOIT AVAIL

Flowise: reflected XSS in chatflow API enables session hijack

CVE-2024-36423
6.1
EPSS 0.3%
Data Extraction Auth Bypass Code Execution Framework Agent
flowise CWE-79 5 ATLAS
MEDIUM EXPLOIT AVAIL

Flowise: reflected XSS enables session hijack and file read

CVE-2024-36422
6.1
EPSS 0.2%
Data Leakage Data Extraction Framework Agent
flowise CWE-79 4 ATLAS
MEDIUM EXPLOIT AVAIL SCANNER

Gradio: open redirect enables phishing against ML users

CVE-2024-4940
6.1
EPSS 7.2%
Social Engineering Privacy Violation Framework Inference
gradio 674 5 ATLAS
MEDIUM EXPLOIT AVAIL

langchain-community: DoS via recursive sitemap loop

CVE-2024-2965
4.2
EPSS 0.0%
DoS Supply Chain Framework RAG
langchain Patch: 0.2.5 CWE-400 2.6K 3 ATLAS
MEDIUM EXPLOIT AVAIL

scikit-learn: TfidfVectorizer leaks training data tokens

CVE-2024-5206
4.7
EPSS 0.0%
Data Leakage Data Extraction Privacy Violation Framework Training Data
scikit-learn CWE-922 27.9K 5 ATLAS
MEDIUM EXPLOIT AVAIL

MLflow: URL encoding bypass enables model poisoning

CVE-2024-3099
5.4
EPSS 0.1%
Model Poisoning DoS Framework Model
mlflow 624 5 ATLAS
MEDIUM EXPLOIT AVAIL

WP Testimonial Carousel: OpenAI API key hijack, no auth

CVE-2024-4858
5.3
EPSS 0.2%
Auth Bypass DoS API Plugin
CWE-862 4 ATLAS
MEDIUM EXPLOIT AVAIL

wpbot: missing auth exposes OpenAI account files

CVE-2024-0451
5.0
EPSS 0.4%
Data Extraction Auth Bypass API Plugin
wpbot CWE-862 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial