AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
911 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
CVE-2026-31239
Mamba: Insecure Deserialization in from_pretrained() via HuggingFace Hub
Mamba framework < 2.2.7
12 May 2026
9 views
Patched
CRITICAL
CVE-2026-31238
Ludwig Framework Insecure Deserialization via torch.load()
Previous
Page 17 of 76
Next
Ludwig framework < 0.10.5
12 May 2026
9 views
Patched
CRITICAL
CVE-2026-31228
ART Kubeflow component vulnerable to RCE via unsafe eval()
Adversarial Robustness Toolbox (ART) versions <= 1.20.1
12 May 2026
9 views
Patched
HIGH
CVE-2026-31221
PyTorch-Lightning Insecure Deserialization via Checkpoint Loading
PyTorch-Lightning versions 2.6.0 and earlier
12 May 2026
8 views
Patched
CRITICAL
CVE-2026-31214
Insecure Deserialization in ml-engineering torch-checkpoint-shrink.py
ml-engineering project, commit 0099885db36a8f06556efe1faf552518852cb1e0
12 May 2026
7 views
Unpatched
HIGH
CVE-2026-31250
CosyVoice Insecure Deserialization via PyTorch Model Averaging
CosyVoice (versions prior to commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e)
11 May 2026
8 views
Unpatched
HIGH
CVE-2026-31249
CosyVoice insecure deserialization via PyTorch .pt file loading
CosyVoice (prior to commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e)
11 May 2026
8 views
Patched
HIGH
CVE-2026-32207
Azure ML Cross-Site Scripting (XSS) Vulnerability
Azure Machine Learning (specific versions not detailed in CVE)
7 May 2026
8 views
Unpatched
CRITICAL
CVE-2026-42027
Apache OpenNLP Arbitrary Class Instantiation via Model Manifest
Apache OpenNLP (versions before 2.5.9)
Apache OpenNLP (versions before 3.0.0-M3)
4 May 2026
8 views
Patched
HIGH
CVE-2026-41269
Flowise: Unrestricted File Upload of JavaScript Allows RCE
Flowise < 3.1.0
23 Apr 2026
0 views
Patched
CRITICAL
CVE-2026-41268
Flowise Unauthenticated Remote Command Execution via Parameter Override
Flowise versions prior to 3.1.0
23 Apr 2026
0 views
Patched
HIGH
CVE-2026-41267
Flowise Cloud Improper Mass Assignment Vulnerability (CVE-2026-41267)
Flowise Cloud (versions prior to 3.1.0)
23 Apr 2026
0 views
Patched