AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 1140 results CVE-2025-0628 LiteLLM Has an Improper Authorization Vulnerability
GHSA-5ccf-884p-4jjq Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
CVE-2024-9606 LiteLLM Reveals Portion of API Key via a Logging File
CVE-2024-9052 vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
CVE-2024-8984 LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-7983 Open WebUI denial of service through endpoint for converting markdown
CVE-2024-7990 Open WebUI stored cross-site scripting (XSS) vulnerability
CVE-2024-8053 Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
CVE-2024-8060 Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
CVE-2024-8020 PyTorch Lightning denial of service vulnerability
CVE-2024-7035 Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2024-7776 Open Neural Network Exchange (ONNX) Path Traversal Vulnerability
CVE-2024-7053 Open WebUI Vulnerable to a Session Fixation Attack
CVE-2024-7045 Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
CVE-2024-7806 Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2024-7046 Open WebUI Allows Viewing of Admin Details
CVE-2024-8019 PyTorch Lightning path traversal vulnerability
GHSA-6wj5-5pgr-jwq8 Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file
CVE-2024-7039 Open WebUI Allows Admin Deletion via API Endpoint
CVE-2024-7034 Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
CVE-2024-7043 Open WebUI Allows Arbitrary File Reading and Deletion
CVE-2024-7044 Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
CVE-2024-6982 LoLLMS Code Injection vulnerability
CVE-2024-7036 Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-6825 LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-7033 Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
CVE-2024-12910 LlamaIndex Uncontrolled Resource Consumption vulnerability
GHSA-w466-2wfc-8g58 Open WebUI has vulnerable dependency on starlette via fastapi
GHSA-hh3j-9m59-p8vc BentoML vulnerable to Uncontrolled Resource Consumption
CVE-2024-12537 Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-12534 Open WebUI Uncontrolled Resource Consumption vulnerability
GHSA-564p-rx2q-4c8v BentoML Open Redirect vulnerability
CVE-2024-11958 LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
CVE-2024-10572 H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2025-1474 In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be...
CVE-2025-1473 A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be...
CVE-2025-0453 In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given...
CVE-2025-0317 A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the...
CVE-2025-0315 A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate...
CVE-2025-0312 A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an...
CVE-2025-0187 A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename...
CVE-2024-9070 A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the...
CVE-2024-9056 BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an...
CVE-2024-9053 vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which...
CVE-2024-8966 A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the...
CVE-2024-8859 A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary...
CVE-2024-8063 A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a...
CVE-2024-8021 An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited...
CVE-2024-7959 The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the...
CVE-2024-6838 In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment...
Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial