AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

77

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1604 results
CRITICAL EXPLOIT AVAIL

MLflow: XSS in recipes enables client-side RCE

CVE-2024-27132
9.6
EPSS 0.2%
Code Execution Supply Chain Data Extraction Framework Training Data
mlflow 624 5 ATLAS
MEDIUM

Intel TF Opt: buffer overflow enables local privesc

CVE-2023-30767
6.7
EPSS 0.1%
Code Execution Supply Chain Framework Training Data
optimization_for_tensorflow CWE-119 3.7K 3 ATLAS
CRITICAL EXPLOIT AVAIL

Gradio: unauthenticated LFI exposes full server filesystem

CVE-2024-0964
9.4
EPSS 0.1%
Data Extraction Data Leakage Auth Bypass Framework Inference API
gradio CWE-22 679 5 ATLAS
CRITICAL EXPLOIT AVAIL

LlamaIndex: SQL injection in Text-to-SQL feature

CVE-2024-23751
9.8
EPSS 0.4%
Code Execution Data Extraction Prompt Injection Framework Agent
llamaindex CWE-89 5 ATLAS
HIGH EXPLOIT AVAIL SCANNER

Gradio: path traversal grants arbitrary file read

CVE-2023-51449
7.5
EPSS 81.5%
Data Extraction Privacy Violation Framework Inference
gradio 679 5 ATLAS
HIGH EXPLOIT AVAIL

Transformers: unsafe deserialization enables RCE on load

CVE-2023-7018
7.8
EPSS 0.2%
Supply Chain Code Execution Framework Model
transformers 7.9K 5 ATLAS
HIGH EXPLOIT AVAIL

HuggingFace Transformers: RCE via unsafe deserialization

CVE-2023-6730
8.8
EPSS 0.2%
Supply Chain Code Execution Framework Model
transformers CWE-502 7.9K 5 ATLAS
HIGH EXPLOIT AVAIL SCANNER

MLflow: path traversal exposes arbitrary files (no auth)

CVE-2023-6909
7.5
EPSS 85.7%
Data Extraction Framework
mlflow 624 4 ATLAS
HIGH EXPLOIT AVAIL SCANNER

MLflow: path traversal allows arbitrary file write

CVE-2023-6831
8.1
EPSS 74.0%
Supply Chain Code Execution Framework Training Data
mlflow CWE-22 624 4 ATLAS
HIGH EXPLOIT AVAIL

Gradio: command injection enables RCE on ML servers

CVE-2023-6572
8.1
EPSS 2.5%
Code Execution Data Extraction Supply Chain Framework Inference API
gradio 679 5 ATLAS
HIGH EXPLOIT AVAIL

MLflow: path traversal exposes arbitrary file read/write

CVE-2023-6753
8.8
EPSS 2.4%
Data Extraction Code Execution Supply Chain Framework Training Data Model
mlflow 624 5 ATLAS
HIGH EXPLOIT AVAIL

MLflow: SSTI enables RCE in ML experiment tracking

CVE-2023-6709
8.8
EPSS 0.3%
Code Execution Supply Chain Data Extraction Framework Training Data
mlflow 624 5 ATLAS
MEDIUM EXPLOIT AVAIL SCANNER

MLflow: reflected XSS via Content-Type header injection

CVE-2023-6568
6.1
EPSS 33.4%
Auth Bypass Data Extraction Framework
mlflow CWE-79 624 4 ATLAS
HIGH EXPLOIT AVAIL SCANNER

MLflow: unauth REST API leaks sensitive ML data

CVE-2023-43472
7.5
EPSS 74.4%
Data Extraction Data Leakage Auth Bypass Framework API Training Data
mlflow 624 5 ATLAS
CRITICAL KEV SCANNER

Ray: unauthenticated RCE via job submission API

CVE-2023-48022
9.8
EPSS 92.2%
Code Execution Auth Bypass Framework Training Data Inference
ray CWE-829 847 6 ATLAS
MEDIUM

TorchServe: ZipSlip arbitrary file write via model upload

CVE-2023-48299
5.3
EPSS 0.4%
Supply Chain Code Execution Framework Inference
torchserve 21.9K 4 ATLAS
CRITICAL EXPLOIT AVAIL SCANNER

Ray: unauthenticated LFI exposes entire filesystem

CVE-2023-6020
9.3
EPSS 81.4%
Data Extraction Auth Bypass Framework Training Data Model
ray Patch: 2.8.1 CWE-598 847 5 ATLAS
CRITICAL EXPLOIT AVAIL

MLflow: auth bypass allows arbitrary account creation

CVE-2023-6014
9.8
EPSS 0.9%
Auth Bypass Data Extraction Supply Chain Framework Training Data Model
mlflow 624 6 ATLAS
CRITICAL EXPLOIT AVAIL

Ray: unauthenticated RCE via dashboard command injection

CVE-2023-6019
9.8
EPSS 88.8%
Code Execution Auth Bypass Supply Chain Framework Inference Training Data
ray Patch: 2.8.1 CWE-78 847 6 ATLAS
CRITICAL EXPLOIT AVAIL SCANNER

Ray: LFI allows unauthenticated file read

CVE-2023-6021
9.3
EPSS 87.3%
Data Extraction Auth Bypass Framework Inference
ray Patch: 2.8.1 CWE-22 847 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial