AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 450 results — High severity, no patch
HIGH CVE-2024-7039

Open WebUI Allows Admin Deletion via API Endpoint

CVSS 8.3 EPSS 0.1% open-webui CWE-863
View details
HIGH CVE-2024-6825

LiteLLM Vulnerable to Remote Code Execution (RCE)

CVSS 8.8 EPSS 1.3% litellm CWE-77
View details
HIGH CVE-2024-7036

Open WebUI Uncontrolled Resource Consumption vulnerability

CVSS 7.5 EPSS 0.5% open-webui CWE-400
View details
HIGH GHSA-w466-2wfc-8g58

Open WebUI has vulnerable dependency on starlette via fastapi

CVSS 7.5 open-webui CWE-400
View details
HIGH CVE-2024-12534

Open WebUI Uncontrolled Resource Consumption vulnerability

CVSS 7.5 EPSS 0.2% open-webui CWE-400
View details
HIGH GHSA-hh3j-9m59-p8vc

BentoML vulnerable to Uncontrolled Resource Consumption

CVSS 7.5 bentoml CWE-400
View details
HIGH CVE-2024-12537

Open WebUI Uncontrolled Resource Consumption vulnerability

CVSS 7.5 EPSS 0.8% open-webui CWE-400
View details
HIGH CVE-2024-10572

H2O Vulnerable to Denial of Service (DoS) and File Write

CVSS 7.5 EPSS 0.1% CWE-94
View details
HIGH CVE-2025-1473

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be...

CVSS 7.1 EPSS 0.1% mlflow CWE-352
View details
HIGH CVE-2025-0453

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given...

CVSS 7.5 EPSS 0.1% mlflow CWE-400
View details
HIGH CVE-2025-0317

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the...

CVSS 7.5 ollama CWE-369
View details
HIGH CVE-2025-0315

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate...

CVSS 7.5 ollama CWE-770
View details
HIGH CVE-2025-0312

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an...

CVSS 7.5 ollama CWE-476
View details
HIGH CVE-2024-9056

BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an...

CVSS 7.5 EPSS 0.2% bentoml CWE-400
View details
HIGH CVE-2024-8966

A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the...

CVSS 7.5 EPSS 0.2% video CWE-400
View details
HIGH CVE-2024-8859

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary...

CVSS 7.5 EPSS 26.9% mlflow CWE-22
View details
HIGH CVE-2024-8063

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a...

CVSS 7.5 ollama
View details
HIGH CVE-2024-7959

The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the...

CVSS 7.7 EPSS 0.4% open-webui CWE-918
View details
HIGH CVE-2024-12911

A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary...

CVSS 7.1 EPSS 0.2% llamaindex CWE-89
View details
HIGH CVE-2024-12720

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
HIGH CVE-2024-12704

A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The stream_complete method executes the llm using a...

CVSS 7.5 EPSS 0.3% llamaindex CWE-755
View details
HIGH CVE-2024-12055

A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious...

CVSS 7.5 ollama
View details
HIGH CVE-2024-11031

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited...

CVSS 7.5
View details
HIGH CVE-2024-11030

GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API...

CVSS 7.5
View details
HIGH CVE-2024-10648

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file,...

CVSS 8.2 EPSS 0.2% gradio CWE-29
View details
HIGH CVE-2024-10624

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The affected version is git commit 98cbcae. The...

CVSS 7.5 EPSS 0.8% gradio CWE-400
View details
HIGH CVE-2024-10569

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed...

CVSS 7.5 EPSS 0.2% gradio CWE-475
View details
HIGH CVE-2025-2148

A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component...

CVSS 7.5 pytorch
View details
HIGH CVE-2025-25295

Label Studio has a Path Traversal Vulnerability via image Field

EPSS 0.1% CWE-26
View details
HIGH CVE-2025-24357

vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses...

CVSS 8.8 EPSS 1.0% vllm CWE-502
View details
HIGH CVE-2025-23205

nbgrader's `frame-ancestors: self` grants all users access to formgrader

EPSS 0.3% CWE-668
View details
HIGH CVE-2025-23042

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL)...

CVSS 7.5 EPSS 0.1% gradio CWE-178
View details
HIGH CVE-2024-32965

Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without...

CVSS 8.6
View details
HIGH CVE-2024-27134

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU...

CVSS 7.0 EPSS 0.0% mlflow CWE-276
View details
HIGH CVE-2024-11394

Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

CVSS 8.8 EPSS 59.4% transformers CWE-502
View details
HIGH CVE-2024-11393

Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

CVSS 8.8 EPSS 76.1% transformers CWE-502
View details
HIGH CVE-2024-11392

Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

CVSS 8.8 EPSS 54.9% transformers CWE-502
View details
HIGH CVE-2024-21799

Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 7.1
View details
HIGH CVE-2024-49048

TorchGeo Remote Code Execution Vulnerability

CVSS 8.1 EPSS 0.5% CWE-94
View details
HIGH CVE-2024-43598

LightGBM Remote Code Execution Vulnerability

CVSS 8.1 EPSS 1.6% lightgbm CWE-122
View details
HIGH CVE-2024-39722

An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route.

CVSS 7.5 ollama
View details
HIGH CVE-2024-39721

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random,...

CVSS 7.5 ollama
View details
HIGH CVE-2024-39720

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By...

CVSS 8.2 ollama
View details
HIGH CVE-2024-39719

An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the...

CVSS 7.5 ollama
View details
HIGH CVE-2024-47870

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the...

CVSS 8.1 EPSS 0.2% gradio CWE-362
View details
HIGH CVE-2024-47868

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks through the...

CVSS 7.5 EPSS 0.2% gradio CWE-22
View details
HIGH CVE-2024-47867

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to...

CVSS 7.5 EPSS 0.2% gradio CWE-345
View details
HIGH CVE-2024-47084

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate the request origin when...

CVSS 8.3 EPSS 0.1% gradio CWE-285
View details
HIGH CVE-2024-7714

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and...

CVSS 7.5
View details
HIGH CVE-2024-8768

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

CVSS 7.5
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial