AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 973 results — no patch
HIGH CVE-2025-30370

jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"

CVSS 7.4 EPSS 0.1% CWE-78
View details
LOW CVE-2025-3136

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file...

CVSS 3.3 pytorch CWE-787
View details
MEDIUM CVE-2025-3121

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is...

CVSS 5.5 pytorch
View details
MEDIUM CVE-2025-31843

Missing Authorization vulnerability in Wilson OpenAI Tools for WordPress & WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OpenAI Tools for...

CVSS 4.3
View details
MEDIUM CVE-2025-3001

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-3000

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2999

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption....

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2998

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2953

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of...

CVSS 5.5 EPSS 0.2% pytorch CWE-404
View details
HIGH CVE-2025-30358

Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and...

CVSS 8.1 EPSS 3.1% CWE-915
View details
CRITICAL CVE-2024-12029

InvokeAI Deserialization of Untrusted Data vulnerability

CVSS 9.8 EPSS 49.1% CWE-502
View details
HIGH CVE-2025-0330

LiteLLM Has a Leakage of Langfuse API Keys

CVSS 7.5 EPSS 0.1% litellm CWE-1230
View details
HIGH GHSA-5ccf-884p-4jjq

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability

CVSS 7.5 open-webui CWE-400
View details
CRITICAL CVE-2024-9052

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

CVSS 9.8 EPSS 0.3% vllm CWE-502
View details
HIGH CVE-2024-7990

Open WebUI stored cross-site scripting (XSS) vulnerability

CVSS 8.4 EPSS 0.2% open-webui CWE-79
View details
HIGH CVE-2024-8053

Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint

CVSS 7.5 EPSS 0.8% open-webui CWE-287
View details
HIGH CVE-2024-7983

Open WebUI denial of service through endpoint for converting markdown

CVSS 7.5 EPSS 0.2% open-webui CWE-400
View details
HIGH CVE-2024-8020

PyTorch Lightning denial of service vulnerability

CVSS 7.5 EPSS 0.1% pytorch-lightning CWE-248
View details
MEDIUM CVE-2024-7046

Open WebUI Allows Viewing of Admin Details

CVSS 4.3 EPSS 0.1% open-webui CWE-475
View details
MEDIUM CVE-2024-7035

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)

CVSS 6.9 EPSS 0.0% open-webui CWE-352
View details
MEDIUM CVE-2024-7045

Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read

CVSS 4.3 EPSS 0.1% open-webui CWE-862
View details
HIGH CVE-2024-7053

Open WebUI Vulnerable to a Session Fixation Attack

CVSS 7.6 EPSS 0.2% open-webui CWE-79
View details
MEDIUM CVE-2024-7034

Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint

CVSS 6.5 EPSS 3.0% open-webui CWE-22
View details
HIGH CVE-2024-7036

Open WebUI Uncontrolled Resource Consumption vulnerability

CVSS 7.5 EPSS 0.5% open-webui CWE-400
View details
HIGH CVE-2024-7039

Open WebUI Allows Admin Deletion via API Endpoint

CVSS 8.3 EPSS 0.1% open-webui CWE-863
View details
HIGH CVE-2024-7043

Open WebUI Allows Arbitrary File Reading and Deletion

CVSS 8.1 EPSS 0.1% open-webui CWE-821
View details
MEDIUM CVE-2024-7044

Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload

CVSS 6.8 EPSS 0.3% open-webui CWE-79
View details
HIGH CVE-2024-6825

LiteLLM Vulnerable to Remote Code Execution (RCE)

CVSS 8.8 EPSS 1.3% litellm CWE-77
View details
MEDIUM CVE-2024-7033

Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

CVSS 6.5 EPSS 1.2% open-webui CWE-29
View details
HIGH GHSA-w466-2wfc-8g58

Open WebUI has vulnerable dependency on starlette via fastapi

CVSS 7.5 open-webui CWE-400
View details
HIGH CVE-2024-12537

Open WebUI Uncontrolled Resource Consumption vulnerability

CVSS 7.5 EPSS 0.8% open-webui CWE-400
View details
MEDIUM GHSA-564p-rx2q-4c8v

BentoML Open Redirect vulnerability

CVSS 6.1 bentoml CWE-601
View details
HIGH CVE-2024-12534

Open WebUI Uncontrolled Resource Consumption vulnerability

CVSS 7.5 EPSS 0.2% open-webui CWE-400
View details
HIGH GHSA-hh3j-9m59-p8vc

BentoML vulnerable to Uncontrolled Resource Consumption

CVSS 7.5 bentoml CWE-400
View details
CRITICAL CVE-2024-11958

LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection

CVSS 9.8 EPSS 1.2% CWE-89
View details
HIGH CVE-2024-10572

H2O Vulnerable to Denial of Service (DoS) and File Write

CVSS 7.5 EPSS 0.1% CWE-94
View details
MEDIUM CVE-2025-1474

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be...

CVSS 5.5 EPSS 0.1% mlflow CWE-521
View details
HIGH CVE-2025-1473

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be...

CVSS 7.1 EPSS 0.1% mlflow CWE-352
View details
HIGH CVE-2025-0453

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given...

CVSS 7.5 EPSS 0.1% mlflow CWE-400
View details
HIGH CVE-2025-0317

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the...

CVSS 7.5 ollama CWE-369
View details
HIGH CVE-2025-0315

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate...

CVSS 7.5 ollama CWE-770
View details
HIGH CVE-2025-0312

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an...

CVSS 7.5 ollama CWE-476
View details
UNKNOWN CVE-2025-0187

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename...

gradio
View details
CRITICAL CVE-2024-9070

A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the...

CVSS 9.8 EPSS 0.3% bentoml CWE-502
View details
HIGH CVE-2024-9056

BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an...

CVSS 7.5 EPSS 0.2% bentoml CWE-400
View details
CRITICAL CVE-2024-9053

vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which...

CVSS 9.8 EPSS 2.2% vllm CWE-78
View details
HIGH CVE-2024-8966

A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the...

CVSS 7.5 EPSS 0.2% video CWE-400
View details
HIGH CVE-2024-8859

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary...

CVSS 7.5 EPSS 26.9% mlflow CWE-22
View details
HIGH CVE-2024-8063

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a...

CVSS 7.5 ollama
View details
MEDIUM CVE-2024-8021

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited...

CVSS 6.1 EPSS 2.7% gradio CWE-601
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial