AI Vulnerabilities by Vendor

Browse AI/ML vulnerabilities by the vendor that ships them. AI Threat Alert tracks 1,538 CVEs across 165 vendors — foundation-model providers, framework maintainers, and AI tooling companies including OpenAI, Anthropic, Google, Meta, Microsoft, and Hugging Face — with 220 critical issues, so you can see which vendors carry the most AI security exposure.

Vendor CVEs Critical
google 432 17
OpenClaw 225 11
n8n 72 16
lfprojects 49 10
gradio_project 47 7
n/a 39 7
Red Hat 37 2
langchain 35 20
flowiseai 33 9
n8n-io 31 0
vllm 31 7
linuxfoundation 31 4
huggingface 31 3
openclaw 27 3
Flowise 23 9
ollama 20 1
open-webui 20 0
langflow 19 7
FlowiseAI 17 5
opensuse 16 4
picklescan 14 7
IBM 12 4
MervinPraison 11 0
opengeos 9 9
keras 7 2
oracle 7 7
BerriAI 6 0
llamaindex 6 1
binary-husky 6 1
quantumcloud 6 0
siyuan-note 6 2
filamentphp 6 0
bentoml 5 3
litellm 5 1
Eliz Software 5 5
PraisonAI 5 0
Edimax 5 0
hiyouga 4 2
pytorch 4 2
chatchat-space 3 1
openairinterface 3 0
lightningai 3 2
craftcms 3 0
anthropics 3 0
pydantic 3 0
scikit-learn 3 1
snowflake 3 0
gaizhenbiao 3 1
Unknown 3 0
mmaitre314 3 1
marimo-team 2 0
intel 2 0
jupyterlab 2 0
QR Menu Pro Smart Menu Systems 2 0
Headroom Labs 2 1
snorkel 2 0
h2o 2 0
Microsoft 2 0
Splunk 2 0
taxopress 2 0
Apache Software Foundation 2 0
tugcantopaloglu 2 1
microsoft 2 1
LXware 2 0
langchain-ai 2 0
ml-explore 2 1
kvcache-ai 2 2
Insyde Software 2 0
mlflow 2 1
lollms 2 0
leejet 2 0
parisneo 2 0
Chainlit 2 0
keras-team 2 0
pinpoint-apm 2 0
Feast 2 1
typebot 1 0
uapp 1 0
vasiliskerasiotis 1 1
vercel 1 0
vllm-project 1 1
webdigit 1 0
wolfSSL 1 0
x-d_lab 1 1
yashbhalgat 1 0
yushine 1 0
zanllp 1 0
zephyrproject 1 0
A-J-Evolution 1 0
zephyrproject-rtos 1 0
Anthropic 1 0
BSS Software 1 1
Budibase 1 0
DataDog 1 0
Elastic 1 0
FFmpeg 1 0
Flux159 1 1
ForceInjection 1 0
FreeBSD 1 0
GST Electronics 1 1
Google 1 0
Google Cloud 1 1
Grafana 1 0
HKUDS 1 0
Merkulove 1 0
Merkur Software 1 1
NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. 1 1
NVIDIA 1 0
Notepad++ 1 0
NousResearch 1 0
Ollama AI 1 0
OpenSignLabs 1 0
Oracle Corporation 1 1
PickleScan 1 0
QQBot 1 0
QuantumCloud 1 0
Siemens 1 0
Siemens AG 1 0
Snowflake 1 0
Sony 1 0
Teknolojik Center Telecommunication Industry Trade Co. Ltd. 1 0
Thecus 1 0
Vesta 1 1
WebPros 1 0
aeon 1 0
agpt 1 0
aliasrobotics 1 1
allegroai 1 0
amazon 1 0
anthropic 1 0
astoundify 1 0
ays-pro 1 0
bylancer 1 1
chetans9 1 0
chuanhuchatgpt_project 1 0
combust 1 1
crewai 1 0
davila7 1 0
dtwang 1 0
exo-explore 1 0
ffmpeg 1 0
getgrav 1 1
ggml-org 1 0
gradio 1 0
h2oai 1 1
hestiacp 1 0
hliu 1 0
humansignal 1 0
increments 1 0
langflow-ai 1 0
langgenius 1 0
lobehub 1 0
matrixaddons 1 0
mcp-tool-shop-org 1 1
mindsdb 1 0
mintplexlabs 1 0
mistralai 1 0
nltk 1 0
openai 1 0
openwebui 1 0
pgadmin.org 1 1
sillytavern 1 0
sourcentis 1 0
suyogs 1 0
themegrill 1 0

Frequently asked questions

Which AI vendors does AI Threat Alert track?

AI Threat Alert tracks 165 vendors that publish AI/ML models, frameworks, or tooling — including OpenAI, Anthropic, Google, Meta, Microsoft, and Hugging Face — ranked by the number of CVEs affecting their products.

How many AI vendor vulnerabilities are tracked?

1,538 AI/ML CVEs across 165 vendors, of which 220 are rated critical.

How are vendors ranked?

Vendors are ranked by total CVE count, with critical-severity issues highlighted, so the vendors with the largest AI security exposure surface first.

What counts as an AI vendor here?

Any organization whose AI/ML models, frameworks, libraries, or tools have tracked vulnerabilities — from foundation-model providers to open-source framework maintainers.

Where does the vendor CVE data come from?

Vendor vulnerability data is sourced from NVD and GitHub Advisory, then mapped to the specific AI/ML packages each vendor maintains.