AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 267 results — Medium severity, Active exploitationMLflow: broken access control allows artifact deletion
CVE-2024-4263 PyTorch: heap buffer overflow causes local DoS
CVE-2024-31580 Ollama: DNS rebinding exposes LLM API to remote access
CVE-2024-28224 Gradio: SSRF exposes internal HuggingFace endpoints
CVE-2024-2206 LangChain: Billion Laughs XML expansion causes DoS
CVE-2024-1455 MLflow: reflected XSS via Content-Type header injection
CVE-2023-6568 ChuanhuChatGPT: config exposure leaks API keys
CVE-2023-34094 Transformers: temp file race condition allows local DoS
CVE-2023-2800 n8n: path traversal allows arbitrary file read
CVE-2023-27562 AI ChatBot WP: auth bypass exposes OpenAI config + XSS
CVE-2023-1651 TensorFlow: DoS via malformed Convolution3D input
CVE-2023-25661 Label Studio: SSRF + file read, self-reg bypass
CVE-2022-36551 TensorFlow: input validation DoS in FFT signal ops
CVE-2022-29213 TensorFlow Lite: quantization assert crash (DoS)
CVE-2022-29212 TensorFlow: NaN input crashes histogram op (CPU DoS)
CVE-2022-29211 TensorFlow: CHECK macro type confusion causes DoS
CVE-2022-29209 TensorFlow: SparseTensorDenseAdd null ptr deref DoS
CVE-2022-29206 TensorFlow: NULL deref DoS via compat.v1 ops
CVE-2022-29205 TensorFlow: DoS via UnsortedSegmentJoin input validation
CVE-2022-29204 TensorFlow: DoS via SpaceToBatchND integer overflow
CVE-2022-29203 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert