AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
1,140
AI/ML CVEs Tracked
171
Critical
228
New This Week
2
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 973 results — no patch Severity CVE ID Summary CVSS EPSS Package Date
MEDI CVE-2025-3933 A Regular Expression Denial of Service (ReDoS)... 5.3 0.0% transformers Jul 11 MEDI CVE-2025-6716 The Photos, Files, YouTube, Twitter, Instagram,... 6.4 — — Jul 11 MEDI CVE-2025-7021 Fullscreen API Spoofing and UI Redressing in the... 6.5 — operator Jul 10 MEDI CVE-2025-6210 LlamaIndex vulnerability in its ObsidianReader... 6.2 0.0% — Jul 7 HIGH CVE-2025-6386 Lord of Large Language Models vulnerable to... 7.5 0.1% lollms Jul 7 MEDI CVE-2025-3044 LlamaIndex vulnerability in ArxivReader class can... 5.3 0.1% — Jul 7 HIGH CVE-2025-3225 LlamaIndex has an XML Entity Expansion... 7.5 0.1% — Jul 7 HIGH CVE-2025-3046 LlamaIndex is vulnerable to Path Traversal attack... 7.5 0.1% — Jul 7 LOW CVE-2025-3777 Hugging Face Transformers versions up to 4.49.0... 3.5 0.0% transformers Jul 7 MEDI CVE-2025-3264 A Regular Expression Denial of Service (ReDoS)... 5.3 0.0% transformers Jul 7 MEDI CVE-2025-3263 A Regular Expression Denial of Service (ReDoS)... 5.3 0.0% transformers Jul 7 HIGH CVE-2025-3262 A Regular Expression Denial of Service (ReDoS)... 7.5 0.1% transformers Jul 7 MEDI CVE-2025-52554 n8n is a workflow automation platform. Prior to... 4.3 — n8n Jul 3 MEDI CVE-2025-45809 SQL Injection vulnerability in BerriAI LiteLLM... 5.4 — litellm Jul 3 MEDI CVE-2025-49595 n8n is a workflow automation platform. Prior to... 4.9 — n8n Jul 3 UNKN CVE-2025-34072 A data exfiltration vulnerability exists in... — — — Jul 2 HIGH CVE-2025-6855 A vulnerability, which was classified as... 8.8 0.2% langchain-chatchat Jun 29 MEDI CVE-2025-6854 A vulnerability classified as problematic was... 4.3 0.1% langchain-chatchat Jun 29 CRIT CVE-2025-6853 A vulnerability classified as critical has been... 9.8 0.2% langchain-chatchat Jun 29 MEDI CVE-2025-49592 n8n is a workflow automation platform. Versions... 5.4 — n8n Jun 26 CRIT CVE-2025-53002 LLaMA-Factory is a tuning library for large... 9.8 1.6% llamafactory Jun 26 CRIT CVE-2025-2828 A Server-Side Request Forgery (SSRF)... 10.0 0.1% langchain Jun 23 HIGH CVE-2025-5018 The Hive Support plugin for WordPress is... 7.1 — — Jun 6 HIGH CVE-2025-30167 Jupyter Core on Windows Has Uncontrolled Search... 7.3 0.0% — Jun 4 MEDI CVE-2025-48944 vLLM is an inference and serving engine for large... 6.5 0.1% vllm May 30 MEDI CVE-2025-48943 vLLM is an inference and serving engine for large... 6.5 0.1% vllm May 30 MEDI CVE-2025-48942 vLLM is an inference and serving engine for large... 6.5 0.1% vllm May 30 MEDI CVE-2025-48887 vLLM, an inference and serving engine for large... 6.5 0.1% vllm May 30 HIGH CVE-2025-48889 Gradio is an open-source Python package that... 7.5 0.9% gradio May 30 HIGH CVE-2025-46722 vLLM is an inference and serving engine for large... 7.3 0.1% vllm May 29 LOW CVE-2025-46570 vLLM is an inference and serving engine for large... 2.6 0.1% vllm May 29 LOW CVE-2025-5320 A vulnerability classified as problematic has... 3.7 0.0% gradio May 29 HIGH CVE-2025-5173 A vulnerability has been found in HumanSignal... 7.8 0.1% — May 26 CRIT CVE-2025-47277 vLLM, an inference and serving engine for large... 9.8 0.9% vllm May 20 HIGH CVE-2025-2099 A vulnerability in the `preprocess_string()`... 7.5 0.1% transformers May 19 UNKN CVE-2025-1975 A vulnerability in the Ollama server version... — — ollama May 16 HIGH CVE-2025-0649 Incorrect JSON input stringification in Google's... 7.5 — tensorflow_serving May 6 HIGH CVE-2025-30165 vLLM is an inference and serving engine for large... 8.0 1.3% vllm May 6 LOW CVE-2025-4287 A vulnerability was found in PyTorch 2.6.0+cu124.... 3.3 — — May 5 HIGH CVE-2025-46560 vLLM is a high-throughput and memory-efficient... 7.5 0.6% vllm Apr 30 CRIT CVE-2025-32444 vLLM is a high-throughput and memory-efficient... 9.8 2.5% vllm Apr 30 HIGH CVE-2025-30202 vLLM is a high-throughput and memory-efficient... 7.5 0.4% vllm Apr 30 MEDI CVE-2025-1194 A Regular Expression Denial of Service (ReDoS)... 6.5 0.1% transformers Apr 29 MEDI CVE-2025-46343 n8n is a workflow automation platform. Prior to... 5.4 — n8n Apr 29 CRIT CVE-2025-32434 PyTorch is a Python package that provides tensor... 9.8 1.2% pytorch Apr 18 MEDI CVE-2025-3730 A vulnerability, which was classified as... 5.5 0.1% pytorch Apr 16 CRIT CVE-2025-32428 TigerVNC accessible via the network and not just... — 0.2% — Apr 12 CRIT CVE-2025-32375 BentoML is a Python library for building online... 9.8 67.3% bentoml Apr 9 CRIT CVE-2025-3248 Langflow versions prior to 1.3.0 are susceptible... 9.8 92.5% langflow Apr 7 CRIT CVE-2025-27520 BentoML is a Python library for building online... 9.8 87.3% bentoml Apr 4 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial