CVE Tools

AI & ML

4,501 CVEs tracked since 2001. In the last 12 months, 2,052, +145% on the 12 before.

AI & ML by subsector, Sep 2026 so far

Sep 2026 so far: 190 CVEs across 5 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Agent tooling12465% · 16 vendors
  • LLM serving & inference4524% · 18 vendors
  • ML frameworks137% · 11 vendors

Also: Notebooks & MLOps 7, Vector DBs & RAG 1.

Month by month

Every monthly snapshot of AI & ML. A column is the CVEs published that month.

Aug 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
AI & ML CVEs per month
MonthCVEs
2021-0863
2021-098
2021-108
2021-1145
2021-1211
2022-019
2022-0238
2022-039
2022-040
2022-0526
2022-0614
2022-0713
2022-084
2022-0964
2022-109
2022-1139
2022-129
2023-016
2023-029
2023-030
2023-0414
2023-0520
2023-0631
2023-0723
2023-0827
2023-0940
2023-1014
2023-1121
2023-1231
2024-0150
2024-0243
2024-0334
2024-0496
2024-0551
2024-06171
2024-0743
2024-0826
2024-0951
2024-1072
2024-1144
2024-1230
2025-0150
2025-0221
2025-03315
2025-0443
2025-0553
2025-0641
2025-0772
2025-0844
2025-0979
2025-1057
2025-1149
2025-1280
2026-01113
2026-0299
2026-03202
2026-04249
2026-05274
2026-06272
2026-07300
2026-08278
2026-09190

Vendors

Who shipped the most AI & ML CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Langflow35#29
  2. Praison28#41
  3. Open-webui18#62
  4. Openwebui18#63
  5. Flowiseai15#74
  6. Vllm-project14#89
  7. Nousresearch7#166

Weaknesses

The weakness classes behind AI & ML CVEs in Sep 2026 so far.

  1. CWE-22 Path Traversal20
  2. CWE-863 Incorrect Authorization17
  3. CWE-862 Missing Authorization13
  4. CWE-639 Auth Bypass via User Key11
  5. CWE-79 XSS7
  6. CWE-200 Information Exposure5

Latest CVEs

The 15 most recently published vulnerabilities in AI & ML.

  1. CVE-2026-100846MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization7.6
  2. CVE-2026-100845MONAI before 1.6.0 Remote Code Execution via NumpyReader7.8
  3. CVE-2026-100844MONAI before 1.6.0 OS Command Injection via dataset_name_or_id8.4
  4. CVE-2026-100842MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains7.0
  5. CVE-2026-100843MONAI before 1.6.0 Remote Code Execution via algo_from_pickle7.8
  6. CVE-2026-100841MONAI 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache7.8
  7. CVE-2026-100840MONAI through 1.6.0 Remote Code Execution via bundle configuration7.8
  8. CVE-2026-100654vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids6.5
  9. CVE-2026-100653vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation6.5
  10. CVE-2026-100651vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass6.5
  11. CVE-2026-100652vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids5.9
  12. CVE-2026-100650vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization6.5
  13. CVE-2026-100649vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass3.7
  14. CVE-2026-100648vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding5.3
  15. CVE-2026-100647vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt5.3

The record

Busiest month
Mar 2025, 315 CVEs
Sep 2026 so far
190 CVEs from 53 vendors
Deployment
SaaS, 50%
Monthly snapshots
119 since 2001
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store