AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

76

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1092 results — no patch
Severity CVE ID Summary CVSS EPSS Package Date
UNKN E CVE-2024-1183 Gradio: SSRF enables internal network port scanning 55.0% gradio Apr 16 MEDI CVE-2024-31462 stable-diffusion-webui: path traversal file write 6.3 0.2% Apr 12 CRIT E CVE-2024-3568 HuggingFace Transformers: RCE via pickle deserialization 9.6 24.4% transformers Apr 10 HIGH E CVE-2024-1728 Gradio: path traversal leaks arbitrary files, potential RCE 7.5 86.5% gradio Apr 10 MEDI E CVE-2024-28224 Ollama: DNS rebinding exposes LLM API to remote access 6.6 0.2% ollama Apr 8 CRIT E CVE-2024-31224 gpt_academic: deserialization RCE, no auth required 9.8 3.3% gpt_academic Apr 8 UNKN E CVE-2024-1729 Gradio: timing attack enables auth bypass on ML UIs 0.1% gradio Mar 29 HIGH E CVE-2024-1540 Gradio: CI/CD command injection enables secrets exfil 8.2 0.5% gradio Mar 27 MEDI E CVE-2024-2206 Gradio: SSRF exposes internal HuggingFace endpoints 6.5 0.1% gradio Mar 27 MEDI E CVE-2024-1455 LangChain: Billion Laughs XML expansion causes DoS 5.9 0.1% langchain Mar 26 UNKN E CVE-2024-1727 Gradio: CSRF enables disk exhaustion via file upload DoS 0.2% gradio Mar 21 HIGH E CVE-2024-28088 LangChain: path traversal enables RCE and API key theft 8.1 13.4% langchain Mar 4 CRIT E CVE-2024-2057 LangChain TFIDFRetriever: SSRF/RCE via load_local 9.8 0.1% langchain Mar 1 CRIT E CVE-2024-27444 LangChain Experimental: RCE via Python sandbox escape 9.8 0.1% langchain-experimental Feb 26 CRIT E CVE-2024-27133 MLflow: XSS in recipe runner enables Jupyter RCE 9.6 0.2% mlflow Feb 23 CRIT E CVE-2024-27132 MLflow: XSS in recipes enables client-side RCE 9.6 0.2% mlflow Feb 23 MEDI CVE-2023-30767 Intel TF Opt: buffer overflow enables local privesc 6.7 0.1% optimization_for_tensorflow Feb 14 CRIT E CVE-2024-0964 Gradio: unauthenticated LFI exposes full server filesystem 9.4 0.1% gradio Feb 5 CRIT E CVE-2024-23751 LlamaIndex: SQL injection in Text-to-SQL feature 9.8 0.4% llamaindex Jan 22 HIGH E CVE-2023-51449 Gradio: path traversal grants arbitrary file read 7.5 81.5% gradio Dec 22

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial