AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
1,140
AI/ML CVEs Tracked
171
Critical
228
New This Week
2
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 973 results — no patch Severity CVE ID Summary CVSS EPSS Package Date
CRIT CVE-2026-22778 vLLM is an inference and serving engine for large... 9.8 0.1% vllm Feb 2 CRIT CVE-2026-25481 Langroid has WAF Bypass Leading to RCE in... — 0.0% — Feb 2 HIGH CVE-2026-0599 A vulnerability in... 7.5 0.2% — Feb 2 CRIT CVE-2026-25130 CAI find_file Agent Tool has Command Injection... 9.7 0.0% — Jan 30 LOW CVE-2026-25211 Llama Stack exposes secret in initialization log 3.2 0.0% — Jan 30 HIGH CVE-2026-24780 AutoGPT is a platform that allows users to... 8.8 0.1% — Jan 29 MEDI GHSA-gpx9-96j6-pp87 TaskWeaver has Protection Mechanism Failure and... 6.5 — — Jan 28 HIGH CVE-2026-24779 vLLM is an inference and serving engine for large... 7.1 0.0% vllm Jan 27 HIGH CVE-2026-24747 PyTorch is a Python package that provides tensor... 8.8 0.0% pytorch Jan 27 CRIT CVE-2026-1470 n8n contains a critical Remote Code Execution... 9.9 — n8n Jan 27 MEDI CVE-2026-24123 BentoML is a Python library for building online... 6.5 0.0% bentoml Jan 26 CRIT CVE-2025-13374 The Kalrav AI Agent plugin for WordPress is... 9.8 — — Jan 24 UNKN CVE-2026-0772 Langflow Disk Cache Deserialization of Untrusted... — — langflow Jan 23 UNKN CVE-2026-0771 Langflow PythonFunction Code Injection Remote... — — langflow Jan 23 HIGH CVE-2026-0770 Langflow exec_globals Inclusion of Functionality... — 11.4% langflow Jan 23 UNKN CVE-2026-0769 Langflow eval_custom_component_code Eval... — — langflow Jan 23 UNKN CVE-2026-0768 Langflow code Code Injection Remote Code... — — langflow Jan 23 UNKN CVE-2025-15063 Ollama MCP Server execAsync Command Injection... — — — Jan 23 HIGH CVE-2025-65098 Typebot is an open-source chatbot builder. In... 7.4 — — Jan 22 CRIT CVE-2026-22807 vLLM is an inference and serving engine for large... 9.8 0.0% vllm Jan 21 HIGH CVE-2026-21852 Claude Code is an agentic coding tool. Prior to... 7.5 — claude_code Jan 21 HIGH CVE-2025-66960 An issue in ollama v.0.12.10 allows a remote... 7.5 — ollama Jan 21 HIGH CVE-2025-66959 An issue in ollama v.0.12.10 allows a remote... 7.5 — ollama Jan 21 HIGH CVE-2025-33233 NVIDIA Merlin Transformers4Rec for all platforms... 7.8 — — Jan 20 CRIT CVE-2026-0863 Using string formatting and exception handling,... 9.9 — n8n Jan 18 MEDI CVE-2025-68949 n8n is an open source workflow automation... 5.3 — n8n Jan 13 HIGH CVE-2025-15514 Ollama 0.11.5-rc0 through current version 0.13.5... 7.5 — ollama Jan 12 HIGH CVE-2024-58340 LangChain versions up to and including 0.3.1... 7.5 — langchain Jan 12 HIGH CVE-2024-58339 LlamaIndex (run-llama/llama_index) versions up to... 7.5 — llamaindex Jan 12 HIGH CVE-2024-14021 LlamaIndex (run-llama/llama_index) versions up to... 7.8 — llamaindex Jan 12 HIGH CVE-2026-22033 Label Studio is vulnerable to full account... — 0.0% label-studio Jan 12 HIGH CVE-2026-22773 vLLM is an inference and serving engine for large... 7.5 0.0% vllm Jan 10 MEDI CVE-2025-14980 The BetterDocs plugin for WordPress is vulnerable... 6.5 — — Jan 9 MEDI CVE-2026-21894 n8n is an open source workflow automation... 6.5 — n8n Jan 8 CRIT CVE-2026-21877 n8n is an open source workflow automation... 9.9 — n8n Jan 8 CRIT CVE-2026-21858 n8n is an open source workflow automation... 10.0 — n8n Jan 8 MEDI CVE-2025-14371 The Tag, Category, and Taxonomy Manager – AI... 4.3 — — Jan 6 HIGH CVE-2026-0621 Anthropic's MCP TypeScript SDK versions up to and... 7.5 — — Jan 5 CRIT CVE-2026-21445 Langflow is a tool for building and deploying... 9.1 0.1% langflow Jan 2 MEDI CVE-2025-68697 n8n is an open source workflow automation... 5.4 — n8n Dec 26 CRIT CVE-2025-68668 n8n is an open source workflow automation... 9.9 — n8n Dec 26 MEDI CVE-2025-61914 n8n is an open source workflow automation... 5.4 — n8n Dec 26 HIGH CVE-2025-67729 lmdeploy vulnerable to Arbitrary Code Execution... 8.8 0.1% — Dec 26 CRIT CVE-2025-68665 LangChain is a framework for building LLM-powered... 9.1 — langchain.js Dec 23 HIGH CVE-2025-68664 LangChain is a framework for building agents and... 8.2 0.0% langchain_core Dec 23 UNKN CVE-2025-14930 Hugging Face Transformers GLM4 Deserialization of... — — transformers Dec 23 UNKN CVE-2025-14929 Hugging Face Transformers X-CLIP Checkpoint... — — transformers Dec 23 UNKN CVE-2025-14928 Hugging Face Transformers HuBERT convert_config... — — transformers Dec 23 UNKN CVE-2025-14927 Hugging Face Transformers SEW-D convert_config... — — transformers Dec 23 UNKN CVE-2025-14926 Hugging Face Transformers SEW convert_config Code... — — transformers Dec 23 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial