Automated database of LLM/ML vulnerabilities and incidents
Last update: loading...
Loading vulnerabilities...
The 10 most critical security risks for LLM applications, per the OWASP Foundation.
User input or external content alters model behavior, directly or through indirect injection.
Personal, financial or business data leaked through model responses or memorization.
Risks from foundation models, hosted APIs, fine-tunes, RAG sources and third-party tools.
Training or fine-tuning data manipulated to implant bias or backdoors.
Model output passed downstream without validation or sanitization.
Too much functionality, permission or autonomy granted to an agent.
System instructions disclosed, exposing rules, secrets or architecture.
Flaws in how embeddings are generated, stored or retrieved in RAG systems.
Credible-looking false output, including hallucinated facts and code.
Unrestricted inference driving denial of service, cost blow-up or model extraction.