AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
1,604
AI/ML CVEs Tracked
225
Critical
75
New This Week
16
In CISA KEV
Latest AI Security Threats
Showing 20 of 684 results — High severity Severity CVE ID Summary CVSS EPSS Package Date
HIGH E CVE-2024-8053 Open-WebUI: unauthenticated PDF endpoint enables DoS 7.5 0.7% open-webui Mar 20 HIGH E CVE-2024-7990 open-webui: Stored XSS enables admin session hijack 8.4 0.3% open-webui Mar 20 HIGH GHSA-6wj5-5pgr-jwq8 open-webui: DoS via malformed multipart boundary 7.5 — open-webui Mar 20 HIGH E CVE-2024-7053 open-webui: XSS enables admin session hijack via chat 7.6 0.2% open-webui Mar 20 HIGH E CVE-2024-7776 ONNX: path traversal in download_model enables RCE 8.1 5.3% onnx Mar 20 HIGH E CVE-2024-7806 Open-WebUI: CSRF enables RCE via pipeline code injection 8.0 1.8% open-webui Mar 20 HIGH E CVE-2024-6825 LiteLLM: RCE via post_call_rules callback injection 8.8 3.0% litellm Mar 20 HIGH E CVE-2024-6982 lollms: RCE via eval() sandbox bypass in Calculate 8.4 0.1% lollms Mar 20 HIGH E CVE-2024-7039 open-webui: Privilege bypass enables admin account deletion 8.3 0.2% open-webui Mar 20 HIGH E CVE-2024-7043 Open WebUI: auth bypass exposes all user files 8.1 0.2% open-webui Mar 20 HIGH E CVE-2024-7036 open-webui: unauthenticated DoS disables Admin panel 7.5 1.8% open-webui Mar 20 HIGH GHSA-w466-2wfc-8g58 open-webui: DoS via starlette memory exhaustion 7.5 — open-webui Mar 20 HIGH GHSA-hh3j-9m59-p8vc BentoML: DoS via multipart boundary in Gradio login 7.5 — bentoml Mar 20 HIGH E CVE-2024-12537 Open-WebUI: unauthenticated DoS via code formatter 7.5 2.7% open-webui Mar 20 HIGH E CVE-2024-12534 open-webui: unauthenticated DoS via login payload flood 7.5 0.6% open-webui Mar 20 HIGH E CVE-2024-10572 H2O-3: unauthenticated AST parser enables DoS + file write 7.5 0.4% — Mar 20 HIGH E CVE-2025-1473 MLflow: CSRF in signup allows rogue account creation 7.1 0.2% mlflow Mar 20 HIGH E CVE-2025-0453 MLflow: GraphQL DoS disables ML tracking server 7.5 0.3% mlflow Mar 20 HIGH E CVE-2025-0317 Ollama: DoS via malicious GGUF model file upload 7.5 2.9% ollama Mar 20 HIGH E CVE-2025-0315 Ollama: GGUF model upload causes memory exhaustion DoS 7.5 0.1% ollama Mar 20 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert