AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 910 results — Active exploitationFlowise: IDOR enables account takeover and SSO bypass
CVE-2026-30823 Flowise: mass assignment allows unauthenticated DB injection
CVE-2026-30822 flowise: Arbitrary File Upload enables RCE
CVE-2026-30821 Flowise: header spoof auth bypass exposes admin API & creds
CVE-2026-30820 bentoml: security flaw enables exploitation
CVE-2026-27905 gradio: SSRF allows internal network access
CVE-2026-28416 gradio: security flaw enables exploitation
CVE-2026-28414 gradio: Weak Credentials allow account compromise
CVE-2026-27167 langflow: Code Injection enables RCE
CVE-2026-27966 ray: Missing Auth allows unauthenticated access
CVE-2026-27482 sillytavern: SSRF allows internal network access
CVE-2026-26286 OpenClaw: indirect prompt injection via Slack metadata
CVE-2026-24764 smolagents: SSRF allows internal network access
CVE-2026-2654 pydantic-ai: SSRF allows internal network access
CVE-2026-25580 OpenClaw: path traversal enables arbitrary file read
CVE-2026-25475 langroid: Code Injection enables RCE
CVE-2026-25481 lollms: Access Control bypass enables privilege escalation
CVE-2026-1117 llama-index-core: DoS causes service disruption
CVE-2025-6208 text-generation: DoS causes service disruption
CVE-2026-0599 mlflow: security flaw enables exploitation
CVE-2025-10279 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert