AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1092 results — no patchExecuTorch: integer overflow enables RCE via model loading
CVE-2025-54952 Azure OpenAI: SSRF EoP, no auth required (CVSS 10)
CVE-2025-53767 Ollama: arbitrary file deletion via /api/pull
CVE-2025-44779 Transformers: ReDoS in TF-to-PyTorch weight converter
CVE-2025-5197 ChatGLM-Webui: arbitrary file read, no auth required
CVE-2025-45150 WP Contest Gallery: Stored XSS exposes OpenAI API creds
CVE-2025-7725 ms-swift: RCE via pickle deserialization in adapter models
GHSA-r54c-2xmf-2cf3 BentoML: unauthenticated SSRF via file upload URLs
CVE-2025-54381 LangChain GmailToolkit: indirect prompt injection to RCE
CVE-2025-46059 smolagents: sandbox escape enables unauthenticated RCE
CVE-2025-5120 OpenAI Codex CLI: sandbox bypass via ripgrep flag abuse
CVE-2025-54558 WordPress AI Engine: SSRF leaks files via OpenAI API
CVE-2025-7780 Ollama: auth token hijack via crafted WWW-Authenticate
CVE-2025-51471 Dagster: path traversal exposes arbitrary file read via gRPC
CVE-2025-51481 DSpace: XXE injection enables server file disclosure
CVE-2025-53621 Transformers: ReDoS in DonutProcessor causes DoS
CVE-2025-3933 Contest Gallery WP Plugin: Stored XSS in OpenAI integration
CVE-2025-6716 OpenAI Operator: fullscreen spoofing captures credentials
CVE-2025-7021 lollms: timing attack enables credential enumeration
CVE-2025-6386 Transformers: URL validation bypass exposes image pipeline
CVE-2025-3777 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert