aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Statistics

Threat intelligence overview across all tracked AI security items.

7,585

Total Items

29

Actively Exploited

0

Unpatched Critical/High

249

Last 7 Days

Top 10 CVEs by Exploit Probability (EPSS)

CVETitleEPSS Severity Exploit Patched
CVE-2024-37032CVE-2024-37032: Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,93.8%high—
CVE-2024-1561CVE-2024-1561: An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of93.6%high—
CVE-2023-1177CVE-2023-1177: Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. 93.3%critical—
CVE-2023-51409CVE-2023-51409: Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect92.8%critical—
CVE-2023-49785CVE-2023-49785: NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 92.6%critical—
CVE-2023-3765CVE-2023-3765: Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.92.1%critical—
CVE-2025-3248CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and 92.1%critical🔥 Actively Exploited—
CVE-2023-43654CVE-2023-43654: TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper91.6%critical—
CVE-2024-2928CVE-2024-2928: A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix91.6%high—
CVE-2023-6018CVE-2023-6018: An attacker can overwrite any file on the server hosting MLflow without any authentication.91.3%critical—
CVE-2024-3703293.8%

CVE-2024-37032: Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,

high
CVE-2024-156193.6%

CVE-2024-1561: An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of

high
CVE-2023-117793.3%

CVE-2023-1177: Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

critical
CVE-2023-5140992.8%

CVE-2023-51409: Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect

critical
CVE-2023-4978592.6%

CVE-2023-49785: NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2

critical
CVE-2023-376592.1%

CVE-2023-3765: Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

critical
CVE-2025-324892.1%

CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and

critical🔥 Actively Exploited
CVE-2023-4365491.6%

CVE-2023-43654: TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper

critical
CVE-2024-292891.6%

CVE-2024-2928: A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix

high
CVE-2023-601891.3%

CVE-2023-6018: An attacker can overwrite any file on the server hosting MLflow without any authentication.

critical

This Week vs Last Week

Total Items

240vs 223
+8%(day 7 of 7)

Critical + High

60vs 79
-24%(day 7 of 7)

Vulnerabilities

54vs 71
-24%(day 7 of 7)

Research

5vs 3
+67%(day 7 of 7)
Attack Type This WeekLast WeekChange
Supply Chain37370%
Prompt Injection1718-6%
Data Extraction1629-45%
Jailbreak1214-14%
DoS128+50%

Classification Analytics

LLM-classified attributes across all item types.

Attack Sophistication

Moderate5,386
Trivial1,479
Advanced719
Nation-State1

AI Component Targeted

Agent1,416
API1,328
Model1,077
Framework1,009
Inference637
Training Data281
RAG92
Plugin58

Exploit Maturity

2,564

No Known Exploit

29

Actively Exploited

LLM-Specific vs General AI

3,374

LLM-Specific

4,211

General AI/ML

Vendor Vulnerability Breakdown

Vulnerabilities and incidents only (excludes news and research).

VendorTotalCriticalHighMediumLow
LangChain62315828816413
HuggingFace27260146623
OpenAI120554493
NVIDIA1101357355
Anthropic1001853252
Microsoft942048250
Google591030144
Amazon4043330
LlamaIndex1731031
Mistral123711
Apple92410
Meta80620
Stability AI70520
Cohere41300
xAI40100

Coverage Summary

By Type

Regulatory120Vulnerabilities2,836Incidents31Research707News3,891

By Severity

medium1,134info3,973none1high1,769critical513low195

Monthly Trend

All item types combined.

MonthTotal ItemsCritical + High
2025-107629
2025-116423
2025-1210827
2026-0111341
2026-0249393
2026-03805162
2026-04807211
2026-05771230
2026-06750170
2026-07861266
2026-08830304
2026-09664190