AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1604 resultsHugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
CVE-2025-14931 transformers: Deserialization enables RCE
CVE-2025-14930 transformers: Deserialization enables RCE
CVE-2025-14929 transformers: Code Injection enables RCE
CVE-2025-14928 transformers: Code Injection enables RCE
CVE-2025-14927 transformers: Code Injection enables RCE
CVE-2025-14926 transformers: Deserialization enables RCE
CVE-2025-14924 transformers: Deserialization enables RCE
CVE-2025-14921 transformers: Deserialization enables RCE
CVE-2025-14920 local-deep-research: SSRF allows internal network access
CVE-2025-67743 n8n: security flaw enables exploitation
CVE-2025-68613 langflow: File Control enables path manipulation
CVE-2025-68478 langflow: SSRF allows internal network access
CVE-2025-68477 nbconvert: security flaw enables exploitation
CVE-2025-53000 anythingllm: Missing Auth allows unauthenticated access
CVE-2025-63390 ollama: Missing Auth allows unauthenticated access
CVE-2025-63389 fickling: Code Injection enables RCE
CVE-2025-67748 fickling: Allowlist Bypass evades input filtering
CVE-2025-67747 cai-framework: Command Injection enables RCE
CVE-2025-67511 langgraph-checkpoint-sqlite: SQL Injection exposes database
CVE-2025-67644 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert