AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1604 resultsLangChain-Experimental: RCE via eval in math chain
CVE-2024-46946 ilab/vllm: best_of param causes inference API DoS
CVE-2024-8939 vLLM: unauthenticated DoS via empty completion prompt
CVE-2024-8768 LangChain: RCE via FAISS pickle deserialization
CVE-2024-5998 LiteLLM: SSRF leaks OpenAI API key to attacker
CVE-2024-6587 MindsDB: RCE via eval() injection in ChromaDB INSERT
CVE-2024-45848 Ollama: ZIP path traversal exposes host filesystem
CVE-2024-45436 Streamlit: path traversal leaks Windows NTLM hash
CVE-2024-42474 TensorFlow: DoS via upper_bound rank validation crash
CVE-2023-33976 Langflow: mass assignment grants super admin access
CVE-2024-7297 streamlit-geospatial: blind SSRF via unvalidated URL input
CVE-2024-41120 streamlit-geospatial: RCE via eval() on vis_params input
CVE-2024-41119 streamlit-geospatial: blind SSRF via WMS URL input
CVE-2024-41118 streamlit-geospatial: eval() injection allows RCE
CVE-2024-41117 streamlit-geospatial: RCE via eval() injection
CVE-2024-41116 streamlit-geospatial: eval() injection enables RCE
CVE-2024-41115 streamlit-geospatial: RCE via eval() on palette input
CVE-2024-41114 streamlit-geospatial: RCE via eval() in Timelapse page
CVE-2024-41113 streamlit-geospatial: RCE via eval() on palette input
CVE-2024-41112 TorchServe: default gRPC exposure allows unauth inference
CVE-2024-35199 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert