aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Statistics

Threat intelligence overview across all tracked AI security items.

6,134

Total Items

17

Actively Exploited

0

Unpatched Critical/High

232

Last 7 Days

Top 10 CVEs by Exploit Probability (EPSS)

CVETitleEPSS Severity Exploit Patched
CVE-2024-37032CVE-2024-37032: Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,93.8%high—
CVE-2024-1561CVE-2024-1561: An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of93.6%high—
CVE-2023-1177CVE-2023-1177: Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. 93.3%critical—
CVE-2023-51409CVE-2023-51409: Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect92.8%critical—
CVE-2023-49785CVE-2023-49785: NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 92.6%critical—
CVE-2023-3765CVE-2023-3765: Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.92.1%critical—
CVE-2025-3248CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and 92.1%critical🔥 Actively Exploited—
CVE-2023-43654CVE-2023-43654: TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper91.6%critical—
CVE-2024-2928CVE-2024-2928: A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix91.6%high—
CVE-2023-6018CVE-2023-6018: An attacker can overwrite any file on the server hosting MLflow without any authentication.91.3%critical—
CVE-2024-3703293.8%

CVE-2024-37032: Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,

high
CVE-2024-156193.6%

CVE-2024-1561: An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of

high
CVE-2023-117793.3%

CVE-2023-1177: Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

critical
CVE-2023-5140992.8%

CVE-2023-51409: Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect

critical
CVE-2023-4978592.6%

CVE-2023-49785: NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2

critical
CVE-2023-376592.1%

CVE-2023-3765: Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

critical
CVE-2025-324892.1%

CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and

critical🔥 Actively Exploited
CVE-2023-4365491.6%

CVE-2023-43654: TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper

critical
CVE-2024-292891.6%

CVE-2024-2928: A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix

high
CVE-2023-601891.3%

CVE-2023-6018: An attacker can overwrite any file on the server hosting MLflow without any authentication.

critical

This Week vs Last Week

Total Items

111vs 199
-44%(day 3 of 7)

Critical + High

54vs 54
0%(day 3 of 7)

Vulnerabilities

42vs 25
+68%(day 3 of 7)

Research

1vs 5
-80%(day 3 of 7)
Attack Type This WeekLast WeekChange
Supply Chain3231+3%
Prompt Injection1720-15%
Data Extraction1015-33%
Model Theft711-36%
Jailbreak612-50%

Classification Analytics

LLM-classified attributes across all item types.

Attack Sophistication

Moderate4,349
Trivial1,267
Advanced517
Nation-State1

AI Component Targeted

Agent1,106
API1,073
Framework908
Model845
Inference515
Training Data211
RAG78
Plugin52

Exploit Maturity

2,184

No Known Exploit

17

Actively Exploited

LLM-Specific vs General AI

2,612

LLM-Specific

3,522

General AI/ML

Vendor Vulnerability Breakdown

Vulnerabilities and incidents only (excludes news and research).

VendorTotalCriticalHighMediumLow
LangChain48413821611713
HuggingFace23953125573
NVIDIA1001251325
OpenAI96339443
Anthropic851743212
Microsoft761738210
Google49824133
Amazon3042330
LlamaIndex153921
Apple82310
Meta60420
Stability AI60420
Mistral31011
xAI30000

Coverage Summary

By Type

Regulatory100Vulnerabilities2,422Incidents24Research566News3,022

By Severity

medium976info3,129none1high1,399critical445low184

Monthly Trend

All item types combined.

MonthTotal ItemsCritical + High
2025-096836
2025-107629
2025-116423
2025-1210827
2026-0110541
2026-0248693
2026-03796162
2026-04797211
2026-05765230
2026-06745170
2026-07828266
2026-0812156