AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
1,604
AI/ML CVEs Tracked
225
Critical
77
New This Week
16
In CISA KEV
Latest AI Security Threats
Showing 20 of 1604 results Severity CVE ID Summary CVSS EPSS Package Date
CRIT E CVE-2023-6018 MLflow: unauth file overwrite enables model poisoning 9.8 91.3% mlflow Nov 16 HIGH E CVE-2023-6015 MLflow: unauthenticated arbitrary file write via PUT 7.5 0.8% mlflow Nov 16 CRIT E CVE-2023-5245 MLeap: zip slip in model loading enables RCE 9.8 0.4% — Nov 15 HIGH CVE-2023-46315 Infinite Image Browsing: path traversal leaks credentials 7.5 0.2% — Oct 22 CRIT CVE-2023-32785 LangChain: prompt injection → SQL RCE (CVSS 9.8) 9.8 — langchain Oct 21 HIGH E CVE-2023-32786 LangChain: prompt injection triggers SSRF via URL fetch 7.5 0.2% langchain Oct 20 HIGH CVE-2023-46229 LangChain: SSRF in URL loader exposes internal network 8.8 1.8% langchain Oct 19 CRIT CVE-2023-44467 LangChain: RCE bypass via __import__ in PAL chain 9.8 0.1% langchain_experimental Oct 9 CRIT CVE-2023-43654 TorchServe: SSRF + RCE via unrestricted model URL loading 9.8 91.6% torchserve Sep 28 MEDI CVE-2023-41626 Gradio: arbitrary file upload via /upload endpoint 4.8 0.1% gradio Sep 15 CRIT E CVE-2023-39631 LangChain: RCE via numexpr evaluate injection 9.8 1.6% langchain Sep 1 CRIT E CVE-2023-36281 LangChain: RCE via malicious JSON prompt template 9.8 62.2% langchain Aug 22 CRIT E CVE-2023-39659 LangChain: RCE via unsanitized PythonAstREPL input 9.8 1.2% langchain Aug 15 CRIT E CVE-2023-38896 LangChain: RCE via unsandboxed LLM code execution 9.8 0.8% langchain Aug 15 CRIT E CVE-2023-38860 LangChain: RCE via unsanitized prompt parameter 9.8 1.4% langchain Aug 15 HIGH CVE-2023-27506 Intel TF Opt: buffer overflow enables local priv-esc 7.8 0.1% optimization_for_tensorflow Aug 11 CRIT E CVE-2023-36095 LangChain PALChain: RCE via unsanitized exec() calls 9.8 3.1% langchain Aug 5 HIGH E CVE-2023-4033 MLflow: OS command injection enables local code execution 7.8 0.2% mlflow Aug 1 CRIT E CVE-2023-3765 MLflow: path traversal allows arbitrary file read 10.0 91.5% mlflow Jul 19 CRIT E CVE-2023-3686 QuickAI: unauthenticated SQLi exposes OpenAI API keys 9.8 0.1% quickai_openai Jul 16 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert