AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1604 resultsTorchServe: URL bypass enables arbitrary model loading
CVE-2024-35198 langchain-experimental: RCE via eval() in VectorSQL chain
CVE-2024-21513 ChatGPT macOS: cleartext conversation storage exposed
CVE-2024-40594 lollms-webui: RCE via malicious GGUF model loading
CVE-2024-4897 Gradio: code injection via component metadata (CVSS 9.8)
CVE-2024-39236 Flowise: reflected XSS enables credential theft
CVE-2024-37146 Flowise: reflected XSS enables file read chain via chatflow
CVE-2024-37145 Flowise: reflected XSS in chatflow API enables session hijack
CVE-2024-36423 Flowise: reflected XSS enables session hijack and file read
CVE-2024-36422 Flowise: CORS wildcard enables file read and data theft
CVE-2024-36421 Flowise: unauthenticated arbitrary file read via API
CVE-2024-36420 lollms-webui: CSRF allows unauthorized AI service install
CVE-2024-4839 Gradio: open redirect enables phishing against ML users
CVE-2024-4940 LangChain: Python REPL code execution without opt-in
CVE-2024-38459 Langflow: unauthenticated RCE via custom component API
CVE-2024-37014 ONNX: path traversal in model download enables RCE
CVE-2024-5187 langchain-community: DoS via recursive sitemap loop
CVE-2024-2965 scikit-learn: TfidfVectorizer leaks training data tokens
CVE-2024-5206 litellm: arbitrary file deletion via audio endpoint
CVE-2024-4888 ChuanhuChatGPT: path traversal exposes LLM API keys
CVE-2024-3234 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert