AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 167 results — Critical severity, no patchvllm: RCE via unsafe pickle deserialization in MessageQueue
CVE-2024-11041 vLLM: RCE via unsafe deserialization in Mooncake KV
CVE-2025-29783 Keras: safe_mode bypass enables RCE via model loading
CVE-2025-1550 picklescan: ZIP flag bypass enables RCE in PyTorch models
CVE-2025-1945 JupyterHub LTI13: JWT forgery enables full auth bypass
CVE-2023-25574 PandasAI: prompt injection enables unauthenticated RCE
CVE-2024-12366 Sage AI Plugin: unrestricted upload → web shell RCE
CVE-2024-52384 Langflow: RCE via unsandboxed code component execution
CVE-2024-48061 Langflow: Unauthenticated RCE via PythonCodeTool
CVE-2024-42835 PyTorch: RCE via RemoteModule deserialization
CVE-2024-48063 LangChain GraphCypher: prompt injection enables DB wipe
CVE-2024-8309 LangChain.js: path traversal, arbitrary file read/write
CVE-2024-7774 LangChainJS: prompt injection enables full graph DB takeover
CVE-2024-7042 Affiliator WP Plugin: Unauthenticated Web Shell Upload
CVE-2024-49326 Gradio: cleartext MITM exposes ML demo data via share=True
CVE-2024-47871 Gradio: unauthenticated SSRF in /queue/join, internal pivot
CVE-2024-47167 LangChain-Experimental: RCE via eval in math chain
CVE-2024-46946 streamlit-geospatial: blind SSRF via unvalidated URL input
CVE-2024-41120 streamlit-geospatial: RCE via eval() on vis_params input
CVE-2024-41119 streamlit-geospatial: blind SSRF via WMS URL input
CVE-2024-41118 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert