AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 973 results — no patch CVE-2025-30370 jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
CVE-2025-3136 A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file...
CVE-2025-3121 A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is...
CVE-2025-31843 Missing Authorization vulnerability in Wilson OpenAI Tools for WordPress & WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OpenAI Tools for...
CVE-2025-3001 A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be...
CVE-2025-3000 A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on...
CVE-2025-2999 A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption....
CVE-2025-2998 A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory...
CVE-2025-2953 A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of...
CVE-2025-30358 Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and...
CVE-2024-12029 InvokeAI Deserialization of Untrusted Data vulnerability
CVE-2025-0330 LiteLLM Has a Leakage of Langfuse API Keys
GHSA-5ccf-884p-4jjq Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
CVE-2024-9052 vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
CVE-2024-7990 Open WebUI stored cross-site scripting (XSS) vulnerability
CVE-2024-8053 Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
CVE-2024-7983 Open WebUI denial of service through endpoint for converting markdown
CVE-2024-8020 PyTorch Lightning denial of service vulnerability
CVE-2024-7046 Open WebUI Allows Viewing of Admin Details
CVE-2024-7035 Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2024-7045 Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
CVE-2024-7053 Open WebUI Vulnerable to a Session Fixation Attack
CVE-2024-7034 Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
CVE-2024-7036 Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7039 Open WebUI Allows Admin Deletion via API Endpoint
CVE-2024-7043 Open WebUI Allows Arbitrary File Reading and Deletion
CVE-2024-7044 Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
CVE-2024-6825 LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-7033 Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
GHSA-w466-2wfc-8g58 Open WebUI has vulnerable dependency on starlette via fastapi
CVE-2024-12537 Open WebUI Uncontrolled Resource Consumption vulnerability
GHSA-564p-rx2q-4c8v BentoML Open Redirect vulnerability
CVE-2024-12534 Open WebUI Uncontrolled Resource Consumption vulnerability
GHSA-hh3j-9m59-p8vc BentoML vulnerable to Uncontrolled Resource Consumption
CVE-2024-11958 LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
CVE-2024-10572 H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2025-1474 In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be...
CVE-2025-1473 A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be...
CVE-2025-0453 In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given...
CVE-2025-0317 A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the...
CVE-2025-0315 A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate...
CVE-2025-0312 A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an...
CVE-2025-0187 A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename...
CVE-2024-9070 A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the...
CVE-2024-9056 BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an...
CVE-2024-9053 vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which...
CVE-2024-8966 A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the...
CVE-2024-8859 A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary...
CVE-2024-8063 A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a...
CVE-2024-8021 An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited...
Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial