Solution sectors / ai-ml
AI & ML
The AI/ML stack — LLM serving and inference engines, ML frameworks, vector databases and agent tooling — is evolving fast and increasingly exposed to the internet. This hub tracks its emerging CVEs.
ai-agent-tooling · 122llm-serving-inference · 27ml-framework · 16vector-db-rag · 16notebook-mlops · 12
Cumulative CVEs
3,937
across 117 monthly snapshots
Latest month
234 · proj
-14.0% MoM · +225.0% YoY
Peak month
315
Mar 25
KEV this month
0
65 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Mixed51%
- SaaS33%
- On-prem15%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to AI & ML.
- CVE-2026-17432NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control5.0
- CVE-2026-66027Suna < 0.9.102 Broken Access Control via Message Queue API8.3
- CVE-2026-66007Datasets Path Traversal via Unsanitized file_name Metadata6.5
- CVE-2026-66004BlenderMCP Path Traversal via download_polyhaven_asset API5.3
- CVE-2026-11922Rate-limit Bypass in zenml-io/zenml6.5
- CVE-2026-56167Azure AI Search Elevation of Privilege Vulnerability8.5
- CVE-2026-65010Datasets Symlink-following Arbitrary File Write via Extractor.extract()6.6
- CVE-2026-65920Diffusers Path Traversal via weight_map Arbitrary File Read4.3
- CVE-2026-65918PyTorch torchvision GIF Decoder Out-of-bounds Heap Read7.1
- CVE-2026-65702Vanna 2.0.2 Path Traversal via FileSystemConversationStore8.6
- CVE-2026-65700h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API9.8
- CVE-2026-65013Onlook tRPC Insecure Direct Object Reference via multiple procedures8.8
- CVE-2026-65012InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder5.3
- CVE-2026-65318Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader8.6
- CVE-2026-65317Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass8.6
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| praison | 29 | 4 | · |
| linuxfoundation | 22 | 2 | · |
| open-webui | 19 | · | · |
| openwebui | 19 | · | · |
| labring | 9 | · | · |
| nousresearch | 7 | · | · |
| zhayujie | 7 | · | · |
| langroid | 6 | 1 | · |
| lobehub | 5 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| ai-agent-tooling | 122 | 16 | · | 26 | — | praisonai (29) · open webui (19) · open-webui (19) |
| llm-serving-inference | 27 | 3 | · | 14 | — | fastgpt (9) · litellm (8) · vllm (8) |
| vector-db-rag | 16 | 2 | · | 4 | — | nats-server (12) · mem0 (2) · ragflow (1) |
| ml-framework | 16 | 2 | · | 12 | — | keras-team/keras (4) · docling-core (2) · new-api (2) |
| notebook-mlops | 12 | 2 | · | 6 | — | enterprise_gateway (3) · gradio (3) · mcp python sdk (3) |
| — | 11 | 2 | · | 3 | — | containerd (6) · artificial intelligence (3) · mysti (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification