AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 570 results — Medium severityGradio: SSRF exposes internal HuggingFace endpoints
CVE-2024-2206 LangChain: Billion Laughs XML expansion causes DoS
CVE-2024-1455 Intel TF Opt: buffer overflow enables local privesc
CVE-2023-30767 MLflow: reflected XSS via Content-Type header injection
CVE-2023-6568 TorchServe: ZipSlip arbitrary file write via model upload
CVE-2023-48299 Gradio: arbitrary file upload via /upload endpoint
CVE-2023-41626 ChuanhuChatGPT: config exposure leaks API keys
CVE-2023-34094 Transformers: temp file race condition allows local DoS
CVE-2023-2800 n8n: path traversal allows arbitrary file read
CVE-2023-27562 AI ChatBot WP: auth bypass exposes OpenAI config + XSS
CVE-2023-1651 TensorFlow: DoS via malformed Convolution3D input
CVE-2023-25661 Streamlit: reflected XSS enables session hijacking
CVE-2023-27494 Label Studio: SSRF + file read, self-reg bypass
CVE-2022-36551 Streamlit: path traversal leaks server filesystem
CVE-2022-35918 TensorFlow: input validation DoS in FFT signal ops
CVE-2022-29213 TensorFlow Lite: quantization assert crash (DoS)
CVE-2022-29212 TensorFlow: NaN input crashes histogram op (CPU DoS)
CVE-2022-29211 TensorFlow: heap OOB in TensorKey causes DoS
CVE-2022-29210 TensorFlow: CHECK macro type confusion causes DoS
CVE-2022-29209 TensorFlow: SparseTensorDenseAdd null ptr deref DoS
CVE-2022-29206 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert