AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
1,140
AI/ML CVEs Tracked
171
Critical
228
New This Week
2
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 450 results — High severity, no patch Severity CVE ID Summary CVSS EPSS Package Date
HIGH CVE-2026-33484 Langflow is a tool for building and deploying... 7.5 — langflow Mar 24 HIGH CVE-2026-33053 Langflow is a tool for building and deploying... 8.8 0.0% langflow Mar 20 HIGH CVE-2026-33236 NLTK has a Downloader Path Traversal... 8.1 0.0% — Mar 19 HIGH CVE-2026-33155 DeepDiff has Memory Exhaustion DoS through... — 0.0% — Mar 18 HIGH CVE-2026-25750 Langchain Helm Charts are Helm charts for... 8.1 — langsmith Mar 4 HIGH CVE-2026-27905 BentoML is a Python library for building online... 7.8 0.0% bentoml Mar 3 HIGH CVE-2026-28416 Gradio is an open-source Python package designed... 8.6 0.0% gradio Feb 27 HIGH CVE-2026-28414 Gradio is an open-source Python package designed... 7.5 0.0% gradio Feb 27 HIGH CVE-2026-27498 n8n is an open source workflow automation... 8.8 — n8n Feb 25 HIGH CVE-2026-27497 n8n is an open source workflow automation... 8.8 — n8n Feb 25 HIGH CVE-2026-2472 Google Cloud Vertex AI SDK affected by Stored... — 0.1% — Feb 20 HIGH CVE-2026-26286 SillyTavern is a locally installed user interface... 8.5 — — Feb 19 HIGH CVE-2026-1669 Arbitrary file read in the model loading... 7.5 0.0% keras Feb 11 HIGH CVE-2026-21893 n8n is an open source workflow automation... 7.2 — n8n Feb 4 HIGH CVE-2026-25056 n8n is an open source workflow automation... 8.8 — n8n Feb 4 HIGH CVE-2026-25055 n8n is an open source workflow automation... 8.1 — n8n Feb 4 HIGH CVE-2025-61917 n8n is an open source workflow automation... 7.7 — n8n Feb 4 HIGH CVE-2026-0599 A vulnerability in... 7.5 0.2% — Feb 2 HIGH CVE-2026-24780 AutoGPT is a platform that allows users to... 8.8 0.1% — Jan 29 HIGH CVE-2026-24779 vLLM is an inference and serving engine for large... 7.1 0.0% vllm Jan 27 HIGH CVE-2026-24747 PyTorch is a Python package that provides tensor... 8.8 0.0% pytorch Jan 27 HIGH CVE-2026-0770 Langflow exec_globals Inclusion of Functionality... — 11.4% langflow Jan 23 HIGH CVE-2025-65098 Typebot is an open-source chatbot builder. In... 7.4 — — Jan 22 HIGH CVE-2026-21852 Claude Code is an agentic coding tool. Prior to... 7.5 — claude_code Jan 21 HIGH CVE-2025-66960 An issue in ollama v.0.12.10 allows a remote... 7.5 — ollama Jan 21 HIGH CVE-2025-66959 An issue in ollama v.0.12.10 allows a remote... 7.5 — ollama Jan 21 HIGH CVE-2025-33233 NVIDIA Merlin Transformers4Rec for all platforms... 7.8 — — Jan 20 HIGH CVE-2025-15514 Ollama 0.11.5-rc0 through current version 0.13.5... 7.5 — ollama Jan 12 HIGH CVE-2024-58340 LangChain versions up to and including 0.3.1... 7.5 — langchain Jan 12 HIGH CVE-2024-58339 LlamaIndex (run-llama/llama_index) versions up to... 7.5 — llamaindex Jan 12 HIGH CVE-2024-14021 LlamaIndex (run-llama/llama_index) versions up to... 7.8 — llamaindex Jan 12 HIGH CVE-2026-22033 Label Studio is vulnerable to full account... — 0.0% label-studio Jan 12 HIGH CVE-2026-22773 vLLM is an inference and serving engine for large... 7.5 0.0% vllm Jan 10 HIGH CVE-2026-0621 Anthropic's MCP TypeScript SDK versions up to and... 7.5 — — Jan 5 HIGH CVE-2025-67729 lmdeploy vulnerable to Arbitrary Code Execution... 8.8 0.1% — Dec 26 HIGH CVE-2025-68664 LangChain is a framework for building agents and... 8.2 0.0% langchain_core Dec 23 HIGH CVE-2025-68613 n8n is an open source workflow automation... 8.8 — n8n Dec 19 HIGH CVE-2025-68478 Langflow is a tool for building and deploying... 7.1 0.1% langflow Dec 19 HIGH CVE-2025-53000 nbconvert has an uncontrolled search path that... — 0.0% — Dec 18 HIGH CVE-2025-67644 LangGraph's SQLite is vulnerable to SQL injection... 7.3 0.0% — Dec 10 HIGH CVE-2025-33213 NVIDIA Merlin Transformers4Rec for Linux contains... 8.8 — — Dec 9 HIGH CVE-2025-65964 n8n is an open source workflow automation... 8.8 — n8n Dec 9 HIGH CVE-2025-34291 Langflow versions up to and including 1.6.9... 8.8 13.1% langflow Dec 5 HIGH CVE-2025-66404 MCP Server Kubernetes is an MCP Server that can... 8.8 — — Dec 3 HIGH CVE-2025-66448 vLLM is an inference and serving engine for large... 8.8 0.2% vllm Dec 1 HIGH CVE-2025-62609 MLX is an array framework for machine learning on... 7.5 0.1% mlx Nov 21 HIGH CVE-2025-12973 The S2B AI Assistant – ChatBot, ChatGPT, OpenAI,... 7.2 — — Nov 21 HIGH CVE-2025-62164 vLLM is an inference and serving engine for large... 8.8 0.1% vllm Nov 21 HIGH CVE-2025-64439 LangGraph Checkpoint affected by RCE in "json"... — 0.8% — Nov 5 HIGH CVE-2025-62726 n8n is an open source workflow automation... 8.8 — n8n Oct 30 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial