AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,170

AI/ML CVEs Tracked

175

Critical

254

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 978 results — no patch
MEDIUM CVE-2024-52524

Giskard: ReDoS in text perturbation causes DoS

DoS Supply Chain Framework
EPSS 1.5% CWE-1333
View details
CRITICAL CVE-2024-52384

Sage AI Plugin: unrestricted upload → web shell RCE

Code Execution Data Extraction Auth Bypass Plugin API
CVSS 9.9
View details
HIGH CVE-2024-21799

Intel Extension for Transformers: path traversal privesc

Code Execution Supply Chain Framework
CVSS 7.1
View details
HIGH CVE-2024-49048

TorchGeo: RCE via code injection in geospatial ML lib

Code Execution Supply Chain Framework Training Data
CVSS 8.1 EPSS 0.5% CWE-94
View details
HIGH CVE-2024-43598

LightGBM: heap buffer overflow enables network RCE

Code Execution Supply Chain Framework Inference Training Data
CVSS 8.1 EPSS 1.6% lightgbm CWE-122
View details
MEDIUM CVE-2024-51751

Gradio: path traversal exposes arbitrary server files

Data Extraction Data Leakage Framework
CVSS 6.5 EPSS 0.3% gradio CWE-22
View details
CRITICAL CVE-2024-48061

Langflow: RCE via unsandboxed code component execution

Code Execution Auth Bypass Framework Agent
CVSS 9.8 EPSS 10.2% langflow CWE-94
View details
MEDIUM CVE-2024-48052

Gradio: SSRF in DownloadButton exposes internal resources

Data Extraction Privacy Violation Framework Inference
CVSS 6.5 EPSS 0.1% gradio CWE-918
View details
HIGH CVE-2024-39722

Ollama: path traversal exposes server filesystem

Data Extraction Data Leakage Inference API
CVSS 7.5 ollama
View details
HIGH CVE-2024-39721

Ollama: DoS via /dev/random causes goroutine exhaustion

DoS Inference API Framework
CVSS 7.5 ollama
View details
HIGH CVE-2024-39720

Ollama: OOB read in GGUF parser enables remote DoS

DoS Code Execution Inference Framework
CVSS 8.2 ollama
View details
HIGH CVE-2024-39719

Ollama: file existence oracle via api/create errors

Data Extraction Privacy Violation Inference API
CVSS 7.5 ollama
View details
CRITICAL CVE-2024-42835

Langflow: Unauthenticated RCE via PythonCodeTool

Code Execution Supply Chain Data Extraction Framework Agent Plugin
CVSS 9.8 EPSS 16.2% langflow
View details
CRITICAL CVE-2024-48063

PyTorch: RCE via RemoteModule deserialization

Code Execution Supply Chain Framework Training Data
CVSS 9.8 pytorch CWE-502
View details
MEDIUM CVE-2024-6581

Lollms: SVG upload XSS enables session hijack and RCE

Code Execution Data Leakage Social Engineering Framework API
CVSS 6.5 EPSS 1.6% lollms CWE-79
View details
CRITICAL CVE-2024-8309

LangChain GraphCypher: prompt injection enables DB wipe

Prompt Injection Data Extraction DoS Framework Agent RAG
CVSS 9.8 EPSS 3.0% langchain CWE-74
View details
CRITICAL CVE-2024-7774

LangChain.js: path traversal, arbitrary file read/write

Data Extraction Code Execution Data Leakage Framework Agent
CVSS 9.1 langchain.js CWE-22
View details
CRITICAL CVE-2024-7042

LangChainJS: prompt injection enables full graph DB takeover

Prompt Injection Data Extraction Code Execution Framework Agent API
CVSS 9.8 langchain
View details
UNKNOWN CVE-2024-48919

Cursor IDE: prompt injection triggers terminal RCE

Prompt Injection Code Execution Agent API
View details
CRITICAL CVE-2024-49326

Affiliator WP Plugin: Unauthenticated Web Shell Upload

Code Execution Auth Bypass Supply Chain Framework API
CVSS 9.8 affiliator
View details
MEDIUM CVE-2024-6985

lollms: path traversal allows arbitrary directory read

Data Extraction Auth Bypass Framework Agent
CVSS 4.4 EPSS 0.1% lollms CWE-23
View details
LOW CVE-2024-6971

lollms: path traversal in RAG database functions

Data Extraction Code Execution RAG Framework Agent
CVSS 3.4 EPSS 0.0% lollms CWE-22
View details
MEDIUM CVE-2024-47872

Gradio: stored XSS via malicious file upload

Data Extraction Privacy Violation Framework Inference
CVSS 5.4 EPSS 0.3% gradio CWE-79
View details
CRITICAL CVE-2024-47871

Gradio: cleartext MITM exposes ML demo data via share=True

Data Extraction Data Leakage Privacy Violation Framework Inference API
CVSS 9.1 EPSS 0.1% gradio CWE-311
View details
HIGH CVE-2024-47870

Gradio: race condition enables backend URL hijacking

Data Extraction Privacy Violation Auth Bypass Framework Inference
CVSS 8.1 EPSS 0.2% gradio CWE-362
View details
LOW CVE-2024-47869

Gradio: timing attack exposes analytics dashboard auth

Auth Bypass Data Extraction Framework API
CVSS 3.7 EPSS 0.2% gradio CWE-203
View details
HIGH CVE-2024-47868

Gradio: path traversal leaks arbitrary server files

Data Extraction Data Leakage Framework Inference
CVSS 7.5 EPSS 0.2% gradio CWE-22
View details
HIGH CVE-2024-47867

Gradio: no integrity check on FRP binary, supply chain RCE

Supply Chain Code Execution Framework
CVSS 7.5 EPSS 0.2% gradio CWE-345
View details
MEDIUM CVE-2024-47168

Gradio: monitoring endpoint bypass leaks app analytics

Data Leakage Privacy Violation Auth Bypass Framework Inference
CVSS 4.3 EPSS 0.2% gradio CWE-670
View details
CRITICAL CVE-2024-47167

Gradio: unauthenticated SSRF in /queue/join, internal pivot

Data Extraction Auth Bypass Code Execution Framework Inference
CVSS 9.8 EPSS 0.2% gradio CWE-918
View details
MEDIUM CVE-2024-47166

Gradio: path traversal leaks custom component source

Data Extraction Data Leakage Framework
CVSS 5.3 EPSS 0.2% gradio CWE-22
View details
MEDIUM CVE-2024-47165

Gradio: CORS null origin bypass leaks auth tokens

Auth Bypass Data Extraction Framework API
CVSS 5.4 EPSS 0.2% gradio CWE-285
View details
MEDIUM CVE-2024-47164

Gradio: path traversal bypasses directory access controls

Data Extraction Auth Bypass Framework Inference
CVSS 6.5 EPSS 0.2% gradio CWE-22
View details
HIGH CVE-2024-47084

Gradio: CORS bypass exposes local instances to credential theft

Auth Bypass Data Extraction Data Leakage Framework Inference
CVSS 8.3 EPSS 0.1% gradio CWE-285
View details
MEDIUM CVE-2024-7041

open-webui: IDOR enables cross-user memory tampering

Auth Bypass Model Poisoning Privacy Violation API Agent Framework
CVSS 6.5 EPSS 0.1% open-webui CWE-250
View details
MEDIUM CVE-2024-7037

open-webui: path traversal → arbitrary file write/RCE

Code Execution Supply Chain Framework Plugin
CVSS 6.5 EPSS 2.3% open-webui CWE-22
View details
LOW CVE-2024-7038

open-webui: filesystem enumeration via admin error messages

Data Extraction Data Leakage Framework Inference RAG
CVSS 2.7 EPSS 0.2% open-webui CWE-200
View details
MEDIUM CVE-2024-9277

Langflow: ReDoS crashes LLM workflow backend via HTTP POST

DoS Framework
CVSS 6.5 EPSS 0.2% langflow CWE-1333
View details
HIGH CVE-2024-7714

AYS ChatGPT WP Plugin: auth bypass disables AI service

Auth Bypass Data Leakage DoS Plugin API
CVSS 7.5
View details
MEDIUM CVE-2024-6845

ChatGPT WP Plugin: OpenAI API key leak via unauth REST

Data Extraction Auth Bypass API Plugin
CVSS 5.3 CWE-862
View details
CRITICAL CVE-2024-46946

LangChain-Experimental: RCE via eval in math chain

Code Execution Supply Chain Framework Agent
CVSS 9.8 langchain-experimental
View details
MEDIUM CVE-2024-8939

ilab/vllm: best_of param causes inference API DoS

DoS Inference API
CVSS 6.2
View details
HIGH CVE-2024-8768

vLLM: unauthenticated DoS via empty completion prompt

DoS Inference API Framework
CVSS 7.5
View details
HIGH CVE-2024-5998

LangChain: RCE via FAISS pickle deserialization

Code Execution Supply Chain Framework RAG
CVSS 7.8 langchain
View details
HIGH CVE-2024-6587

LiteLLM: SSRF leaks OpenAI API key to attacker

Data Extraction Auth Bypass API Framework
CVSS 7.5 litellm
View details
HIGH CVE-2024-45848

MindsDB: RCE via eval() injection in ChromaDB INSERT

Code Execution Data Extraction Framework RAG Plugin
CVSS 8.8 CWE-94
View details
HIGH CVE-2024-45436

Ollama: ZIP path traversal exposes host filesystem

Supply Chain Data Extraction Framework Model Inference
CVSS 7.5 ollama CWE-22
View details
MEDIUM CVE-2024-42474

Streamlit: path traversal leaks Windows NTLM hash

Data Leakage Auth Bypass Framework API
CVSS 6.5 streamlit CWE-22
View details
HIGH CVE-2023-33976

TensorFlow: DoS via upper_bound rank validation crash

DoS Framework Inference
CVSS 7.5 tensorflow CWE-190
View details
HIGH CVE-2024-7297

Langflow: mass assignment grants super admin access

Auth Bypass Code Execution Framework Agent
CVSS 8.8 langflow
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial