AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 267 results — Medium severity, Active exploitationGradio: path traversal exposes arbitrary server files
CVE-2024-51751 Gradio: SSRF in DownloadButton exposes internal resources
CVE-2024-48052 Lollms: SVG upload XSS enables session hijack and RCE
CVE-2024-6581 lollms: path traversal allows arbitrary directory read
CVE-2024-6985 open-webui: path traversal → arbitrary file write/RCE
CVE-2024-7037 open-webui: IDOR enables cross-user memory tampering
CVE-2024-7041 Langflow: ReDoS crashes LLM workflow backend via HTTP POST
CVE-2024-9277 ChatGPT WP Plugin: OpenAI API key leak via unauth REST
CVE-2024-6845 ilab/vllm: best_of param causes inference API DoS
CVE-2024-8939 Streamlit: path traversal leaks Windows NTLM hash
CVE-2024-42474 Flowise: reflected XSS enables credential theft
CVE-2024-37146 Flowise: reflected XSS enables file read chain via chatflow
CVE-2024-37145 Flowise: reflected XSS in chatflow API enables session hijack
CVE-2024-36423 Flowise: reflected XSS enables session hijack and file read
CVE-2024-36422 Gradio: open redirect enables phishing against ML users
CVE-2024-4940 langchain-community: DoS via recursive sitemap loop
CVE-2024-2965 scikit-learn: TfidfVectorizer leaks training data tokens
CVE-2024-5206 MLflow: URL encoding bypass enables model poisoning
CVE-2024-3099 WP Testimonial Carousel: OpenAI API key hijack, no auth
CVE-2024-4858 wpbot: missing auth exposes OpenAI account files
CVE-2024-0451 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert