AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1092 results — no patchlollms-webui: RCE via malicious GGUF model loading
CVE-2024-4897 Gradio: code injection via component metadata (CVSS 9.8)
CVE-2024-39236 Flowise: reflected XSS enables credential theft
CVE-2024-37146 Flowise: reflected XSS enables file read chain via chatflow
CVE-2024-37145 Flowise: reflected XSS in chatflow API enables session hijack
CVE-2024-36423 Flowise: reflected XSS enables session hijack and file read
CVE-2024-36422 Flowise: CORS wildcard enables file read and data theft
CVE-2024-36421 Flowise: unauthenticated arbitrary file read via API
CVE-2024-36420 lollms-webui: CSRF allows unauthorized AI service install
CVE-2024-4839 Gradio: open redirect enables phishing against ML users
CVE-2024-4940 LangChain: Python REPL code execution without opt-in
CVE-2024-38459 Langflow: unauthenticated RCE via custom component API
CVE-2024-37014 scikit-learn: TfidfVectorizer leaks training data tokens
CVE-2024-5206 litellm: arbitrary file deletion via audio endpoint
CVE-2024-4888 ChuanhuChatGPT: path traversal exposes LLM API keys
CVE-2024-3234 MLflow: URL encoding bypass enables model poisoning
CVE-2024-3099 LangChain: SSRF in Web Retriever exposes cloud metadata
CVE-2024-3095 MLflow: URI fragment LFI exposes arbitrary files
CVE-2024-2928 MLflow: path traversal enables RCE via dataset loading
CVE-2024-0520 pytorch-lightning: RCE via deepdiff Delta deserialization
CVE-2024-5452 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert