aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Statistics

Threat intelligence overview across all tracked AI security items.

6,526

Total Items

21

Actively Exploited

0

Unpatched Critical/High

154

Last 7 Days

Top 10 CVEs by Exploit Probability (EPSS)

CVETitleEPSS Severity Exploit Patched
CVE-2024-37032CVE-2024-37032: Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,93.8%high—
CVE-2024-1561CVE-2024-1561: An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of93.6%high—
CVE-2023-1177CVE-2023-1177: Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. 93.3%critical—
CVE-2023-51409CVE-2023-51409: Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect92.8%critical—
CVE-2023-49785CVE-2023-49785: NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 92.6%critical—
CVE-2023-3765CVE-2023-3765: Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.92.1%critical—
CVE-2025-3248CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and 92.1%critical🔥 Actively Exploited—
CVE-2023-43654CVE-2023-43654: TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper91.6%critical—
CVE-2024-2928CVE-2024-2928: A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix91.6%high—
CVE-2023-6018CVE-2023-6018: An attacker can overwrite any file on the server hosting MLflow without any authentication.91.3%critical—
CVE-2024-3703293.8%

CVE-2024-37032: Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,

high
CVE-2024-156193.6%

CVE-2024-1561: An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of

high
CVE-2023-117793.3%

CVE-2023-1177: Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

critical
CVE-2023-5140992.8%

CVE-2023-51409: Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect

critical
CVE-2023-4978592.6%

CVE-2023-49785: NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2

critical
CVE-2023-376592.1%

CVE-2023-3765: Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

critical
CVE-2025-324892.1%

CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and

critical🔥 Actively Exploited
CVE-2023-4365491.6%

CVE-2023-43654: TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper

critical
CVE-2024-292891.6%

CVE-2024-2928: A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix

high
CVE-2023-601891.3%

CVE-2023-6018: An attacker can overwrite any file on the server hosting MLflow without any authentication.

critical

This Week vs Last Week

Total Items

89vs 157
-43%(day 3 of 7)

Critical + High

31vs 44
-30%(day 3 of 7)

Vulnerabilities

33vs 46
-28%(day 3 of 7)

Research

0vs 4
-100%(day 3 of 7)
Attack Type This WeekLast WeekChange
Supply Chain1221-43%
Prompt Injection109+11%
Other1013-23%
Data Extraction711-36%
DoS56-17%

Classification Analytics

LLM-classified attributes across all item types.

Attack Sophistication

Moderate4,628
Trivial1,323
Advanced574
Nation-State1

AI Component Targeted

Agent1,199
API1,133
Framework947
Model889
Inference551
Training Data232
RAG81
Plugin52

Exploit Maturity

2,297

No Known Exploit

21

Actively Exploited

LLM-Specific vs General AI

2,823

LLM-Specific

3,703

General AI/ML

Vendor Vulnerability Breakdown

Vulnerabilities and incidents only (excludes news and research).

VendorTotalCriticalHighMediumLow
LangChain52114423712713
HuggingFace24954130613
NVIDIA1071354355
OpenAI103442473
Anthropic891845222
Microsoft801742210
Google50824134
Amazon3242530
LlamaIndex163931
Apple92410
Meta60420
Stability AI60420
Mistral41111
xAI30000

Coverage Summary

By Type

Regulatory103Vulnerabilities2,544Incidents24Research587News3,268

By Severity

medium1,024info3,340none1high1,505critical469low187

Monthly Trend

All item types combined.

MonthTotal ItemsCritical + High
2025-096836
2025-107629
2025-116423
2025-1210827
2026-0110641
2026-0248793
2026-03796162
2026-04800211
2026-05765230
2026-06745170
2026-07839266
2026-08497186