AI Component

Framework

AI/ML frameworks sit at the bottom of every AI stack — virtually every production AI system depends transitively on PyTorch or TensorFlow at the training layer, and on LangChain, LlamaIndex, or a similar orchestrator at the application layer. That concentration means a single vulnerability often affects tens of thousands of downstream services. The CVE patterns are recognisable: unsafe deserialization in model loading (the long tail of pickle), template injection in LangChain's prompt-construction utilities, SSRF in LlamaIndex's data-loader connectors, and path traversal in MLflow's experiment storage. PyTorch itself has shipped several high-severity CVEs around its distributed RPC layer. Because these libraries upgrade frequently and downstream applications pin loosely, patching is a real operational problem. AI Threat Alert tracks framework-level CVEs prominently because a single advisory often means urgent work for hundreds of teams.

1456
Total CVEs
73
Pages
Page 2 of 73
Current
Severity CVE CVSS
UNKNOWN CVE-2026-30822 -
UNKNOWN CVE-2026-30823 -
CRITICAL CVE-2026-30824 9.8
HIGH CVE-2026-31829 8.8
HIGH CVE-2026-27905 7.8
UNKNOWN CVE-2018-7576 -
HIGH CVE-2018-8825 8.8
UNKNOWN CVE-2018-10055 -
UNKNOWN CVE-2018-7577 -
UNKNOWN CVE-2019-9635 -
UNKNOWN CVE-2018-7575 -
CRITICAL CVE-2019-16778 9.8
HIGH CVE-2020-5215 7.5
MEDIUM CVE-2018-21233 6.5
MEDIUM CVE-2020-15190 5.3
MEDIUM CVE-2020-15191 5.3
MEDIUM CVE-2020-15192 4.3
HIGH CVE-2020-15193 7.1
MEDIUM CVE-2020-15194 5.3
HIGH CVE-2020-15195 8.8

Page 2 of 73