AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

76

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1604 results
Severity CVE ID Summary CVSS EPSS Package Date
HIGH E CVE-2024-7983 open-webui: unauthenticated DoS via markdown parser 7.5 0.4% open-webui Mar 20 HIGH E CVE-2024-7990 open-webui: Stored XSS enables admin session hijack 8.4 0.3% open-webui Mar 20 HIGH E CVE-2024-8060 OpenWebUI: path traversal RCE via audio upload API 8.1 2.1% open-webui Mar 20 HIGH E CVE-2024-8020 pytorch-lightning: unauthenticated DoS crashes LightningApp 7.5 0.1% pytorch-lightning Mar 20 CRIT E CVE-2024-8019 pytorch-lightning: file upload RCE (Windows) 9.1 2.1% pytorch-lightning Mar 20 HIGH E CVE-2024-7806 Open-WebUI: CSRF enables RCE via pipeline code injection 8.0 1.8% open-webui Mar 20 HIGH GHSA-6wj5-5pgr-jwq8 open-webui: DoS via malformed multipart boundary 7.5 open-webui Mar 20 HIGH E CVE-2024-7776 ONNX: path traversal in download_model enables RCE 8.1 5.3% onnx Mar 20 HIGH E CVE-2024-7053 open-webui: XSS enables admin session hijack via chat 7.6 0.2% open-webui Mar 20 MEDI E CVE-2024-7046 Open WebUI: missing authz leaks admin credentials 4.3 0.2% open-webui Mar 20 MEDI E CVE-2024-7045 open-webui: missing authz exposes admin prompts 4.3 0.2% open-webui Mar 20 MEDI E CVE-2024-7035 Open WebUI: CSRF wipes RAG DB and AI memories via GET 6.9 0.1% open-webui Mar 20 MEDI E CVE-2024-7034 open-webui: path traversal allows arbitrary file write/RCE 6.5 6.7% open-webui Mar 20 HIGH E CVE-2024-7043 Open WebUI: auth bypass exposes all user files 8.1 0.2% open-webui Mar 20 MEDI E CVE-2024-7033 open-webui: path traversal allows file write and RCE 6.5 1.3% open-webui Mar 20 HIGH E CVE-2024-7036 open-webui: unauthenticated DoS disables Admin panel 7.5 1.8% open-webui Mar 20 HIGH E CVE-2024-6825 LiteLLM: RCE via post_call_rules callback injection 8.8 3.0% litellm Mar 20 HIGH E CVE-2024-7039 open-webui: Privilege bypass enables admin account deletion 8.3 0.2% open-webui Mar 20 MEDI E CVE-2024-7044 Open WebUI: Stored XSS via file upload, session hijack 6.8 0.2% open-webui Mar 20 HIGH E CVE-2024-6982 lollms: RCE via eval() sandbox bypass in Calculate 8.4 0.1% lollms Mar 20

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial