AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1092 results — no patchGradio: cleartext MITM exposes ML demo data via share=True
CVE-2024-47871 Gradio: race condition enables backend URL hijacking
CVE-2024-47870 Gradio: timing attack exposes analytics dashboard auth
CVE-2024-47869 Gradio: path traversal leaks arbitrary server files
CVE-2024-47868 Gradio: no integrity check on FRP binary, supply chain RCE
CVE-2024-47867 Gradio: monitoring endpoint bypass leaks app analytics
CVE-2024-47168 Gradio: unauthenticated SSRF in /queue/join, internal pivot
CVE-2024-47167 Gradio: path traversal leaks custom component source
CVE-2024-47166 Gradio: CORS null origin bypass leaks auth tokens
CVE-2024-47165 Gradio: path traversal bypasses directory access controls
CVE-2024-47164 Gradio: CORS bypass exposes local instances to credential theft
CVE-2024-47084 open-webui: IDOR enables cross-user memory tampering
CVE-2024-7041 open-webui: path traversal → arbitrary file write/RCE
CVE-2024-7037 open-webui: filesystem enumeration via admin error messages
CVE-2024-7038 Langflow: ReDoS crashes LLM workflow backend via HTTP POST
CVE-2024-9277 AYS ChatGPT WP Plugin: auth bypass disables AI service
CVE-2024-7714 ChatGPT WP Plugin: OpenAI API key leak via unauth REST
CVE-2024-6845 LangChain-Experimental: RCE via eval in math chain
CVE-2024-46946 ilab/vllm: best_of param causes inference API DoS
CVE-2024-8939 vLLM: unauthenticated DoS via empty completion prompt
CVE-2024-8768 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert