AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
1,604
AI/ML CVEs Tracked
225
Critical
76
New This Week
16
In CISA KEV
Latest AI Security Threats
Showing 20 of 1604 results Severity CVE ID Summary CVSS EPSS Package Date
HIGH E CVE-2024-8859 MLflow: path traversal allows arbitrary file read via DBFS 7.5 25.7% mlflow Mar 20 HIGH E CVE-2024-8063 ollama: divide-by-zero DoS via crafted GGUF model import 7.5 0.1% ollama Mar 20 MEDI E CVE-2024-8021 Gradio: open redirect exposes AI demo users to phishing 6.1 2.4% gradio Mar 20 HIGH E CVE-2024-7959 Open-WebUI: SSRF via unchecked OpenAI URL leaks internal secrets 7.7 0.5% open-webui Mar 20 MEDI E CVE-2024-6838 MLflow: unconstrained input causes UI denial of service 5.3 0.6% mlflow Mar 20 MEDI E CVE-2024-6577 TorchServe: unverified S3 bucket exposes benchmark data 6.3 0.2% — Mar 20 HIGH E CVE-2024-12911 llama-index: SQLi+DoS via prompt injection in query engine 7.1 0.3% llamaindex Mar 20 UNKN E CVE-2024-12775 Dify: SSRF via custom tool URL enables credential theft — 0.3% — Mar 20 HIGH E CVE-2024-12720 Transformers: ReDoS in Nougat tokenizer causes DoS 7.5 0.2% transformers Mar 20 HIGH E CVE-2024-12704 llama-index: DoS via infinite loop in LangChain LLM 7.5 0.4% llamaindex Mar 20 MEDI E CVE-2024-12217 Gradio: NTFS ADS bypass exposes blocked file paths 5.3 0.3% gradio Mar 20 UNKN E CVE-2024-12065 LLaVA: path traversal allows arbitrary file read — 0.6% — Mar 20 HIGH E CVE-2024-12055 Ollama: DoS via malicious gguf model file upload 7.5 0.1% ollama Mar 20 CRIT E CVE-2024-11041 vllm: RCE via unsafe pickle deserialization in MessageQueue 9.8 5.6% vllm Mar 20 UNKN E CVE-2024-11037 gpt_academic: path traversal exposes LLM API keys — 0.2% gpt_academic Mar 20 HIGH E CVE-2024-11031 GPT Academic: SSRF in Markdown plugin leaks credentials 7.5 0.2% gpt_academic Mar 20 HIGH E CVE-2024-11030 GPT Academic: SSRF via unsanitized HotReload plugin 7.5 0.3% gpt_academic Mar 20 UNKN E CVE-2024-10950 gpt_academic: RCE via unsandboxed prompt injection — 2.8% gpt_academic Mar 20 MEDI E CVE-2024-10940 langchain-core: file read via prompt template inputs 5.3 0.3% langchain-core Mar 20 UNKN E CVE-2024-10707 ChuanhuChatGPT: path traversal exposes server files unauthed — 0.2% chuanhuchatgpt Mar 20 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert