15 Total CVEs
15 AI Analyzed
0 CISA KEV
2 Critical

Profile

0% ended up actively exploited 0 of 15 added to CISA KEV
13% rated critical (CVSS 9.0+) 2 critical, 13 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

14 CVEs in the last 12 months

Products

  • vLLM3
  • vLLM Inference Engine2

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-55574
Analyzed
8.7
vllm-project vLLM

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs

2026-07-07
CVE-2026-54234
Analyzed
7.5
vllm-project vLLM

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs

2026-07-07
CVE-2026-54232
Analyzed
8.8
vllm-project vLLM Inference Engine

vLLM is an inference and serving engine for large language models (LLMs)

2026-06-23
CVE-2026-4944
Analyzed
8.8
vllm-project Multiple Products

vllm-project/vllm version 0

2026-05-29
CVE-2026-48746
Analyzed
9.1
vllm-project vLLM

A vulnerability in the vLLM inference engine allows unauthenticated users to bypass OpenAI API key requirements, potentially exposing LLM services to...

2026-06-23
CVE-2026-41523
Analyzed
7.5
vllm-project vLLM Inference Engine

vLLM is an inference and serving engine for large language models (LLMs)

2026-06-23
CVE-2026-27893
Analyzed
8.8
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2026-03-27
CVE-2026-25960
Analyzed
7.1
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2026-03-10
CVE-2026-24779
Analyzed
7.1
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2026-01-28
CVE-2026-22807
Analyzed
8.8
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2026-01-22
CVE-2026-22778
Analyzed
9.8
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimo...

2026-02-03
CVE-2025-66448
Analyzed
7.1
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2025-12-02
CVE-2025-62164
Analyzed
8.8
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2025-11-22
CVE-2025-59425
Analyzed
7.5
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2025-10-07
CVE-2025-48956
Analyzed
7.5
vllm-project Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2025-08-21