Solution sectors / ai-ml
AI & ML
The AI/ML stack — LLM serving and inference engines, ML frameworks, vector databases and agent tooling — is evolving fast and increasingly exposed to the internet. This hub tracks its emerging CVEs.
Cumulative CVEs
4,158
across 118 monthly snapshots
Latest month
323 · proj
+7.7% MoM · +634.1% YoY
Peak month
315
Mar 25
KEV this month
0
27 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- SaaS66%
- Mixed21%
- Library13%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to AI & ML.
- CVE-2026-73034DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header9.8
- CVE-2026-72922AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification8.2
- CVE-2026-72560HumanSignal Label Studio - Server-Side Request Forgery6.5
- CVE-2026-72917AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization5.9
- CVE-2026-69112Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map7.1
- CVE-2026-71962Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download7.5
- CVE-2026-72594lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar Upload7.6
- CVE-2026-12570Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/keras5.5
- CVE-2026-12372Server-Side Request Forgery (SSRF) in nltk/nltk3.7
- CVE-2026-10595Path Traversal Vulnerability in parisneo/lollms7.5
- CVE-2026-67620Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List7.7
- CVE-2026-52880Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run7.5
- CVE-2026-52879Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS7.5
- CVE-2026-52878Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain7.5
- CVE-2026-49343Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS5.9
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| flowiseai | 26 | 1 | · |
| langflow | 24 | · | · |
| open-webui | 17 | · | · |
| ggml-org | 11 | · | · |
| klever-io | 6 | · | · |
| livebook-dev | 5 | · | · |
| nousresearch | 5 | · | · |
| praison | 5 | 1 | · |
| foundationagents | 3 | · | · |
| nltk | 3 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| ai-agent-tooling | 86 | 2 | · | 11 | — | flowise (26) · langflow (24) · open-webui (17) |
| llm-serving-inference | 20 | · | · | 5 | — | llama.cpp (11) · klever-go (6) · dify (1) |
| notebook-mlops | 10 | · | · | 5 | — | livebook (5) · cvat (2) · jupyterhub (1) |
| ml-framework | 7 | · | · | 4 | — | nltk/nltk (3) · huggingface/transformers (1) · keras-team/keras (1) |
| — | 1 | · | · | 1 | — | litestar (1) |
| vector-db-rag | 1 | · | · | 1 | — | milvus (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification