AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 435 results — High severity, Active exploitation
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in ReverseSequence op

CVE-2022-21728
8.1
EPSS 1.1%
DoS Data Leakage Framework Inference
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: Dequantize integer overflow, RCE risk

CVE-2022-21727
8.8
EPSS 0.3%
Code Execution DoS Framework Inference
tensorflow CWE-190 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in Dequantize op allows RCE

CVE-2022-21726
8.8
EPSS 0.3%
Code Execution Data Extraction Framework Inference
tensorflow CWE-125 3.7K 2 ATLAS
HIGH EXPLOIT AVAIL

pytorch-lightning: deserialization RCE via malicious checkpoint

CVE-2021-4118
7.8
EPSS 0.3%
Code Execution Supply Chain Framework Training Data
pytorch_lightning 21.7K 4 ATLAS
HIGH EXPLOIT AVAIL SCANNER

Gradio: path traversal exposes host filesystem to users

CVE-2021-43831
7.7
EPSS 30.3%
Data Extraction Privacy Violation Framework Inference
gradio CWE-22 674 4 ATLAS
HIGH EXPLOIT AVAIL

Sockeye: unsafe YAML load RCE via model config file

CVE-2021-43811
7.8
EPSS 8.7%
Supply Chain Code Execution Framework Model
4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: eval() in saved_model_cli allows RCE

CVE-2021-41228
7.8
EPSS 0.0%
Code Execution Supply Chain Framework Training Data
tensorflow CWE-94 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow Grappler: uninitialized var, local priv-esc

CVE-2021-41225
7.8
EPSS 0.0%
Code Execution Supply Chain Framework Training Data
tensorflow 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: CuDNN heap overflow, local code execution

CVE-2021-41221
7.8
EPSS 0.0%
Code Execution Framework Training Data
tensorflow CWE-787 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: use-after-free in async collective ops

CVE-2021-41220
7.8
EPSS 0.0%
Code Execution Model Poisoning Framework Training Data
tensorflow 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap overflow in Transpose via negative perm

CVE-2021-41216
7.8
EPSS 0.0%
Code Execution Framework
tensorflow CWE-787 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap R/W + DoS in boosted trees APIs

CVE-2021-41208
7.8
EPSS 0.0%
DoS Code Execution Framework Training Data
tensorflow CWE-476 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: missing shape validation allows heap R/W

CVE-2021-41206
7.8
EPSS 0.0%
Code Execution Framework
tensorflow 3.7K 2 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB in SparseBinCount, crash/disclosure

CVE-2021-41226
7.1
EPSS 0.0%
Code Execution DoS Data Extraction Framework Training Data Inference
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in SparseFillEmptyRows op

CVE-2021-41224
7.1
EPSS 0.0%
Code Execution DoS Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: FusedBatchNorm heap OOB allows data leak/crash

CVE-2021-41223
7.1
EPSS 0.0%
Data Leakage DoS Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB in sparse matrix multiply

CVE-2021-41219
7.8
EPSS 0.0%
Code Execution DoS Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: null deref in ragged ops, local RCE

CVE-2021-41214
7.8
EPSS 0.0%
Code Execution Framework
tensorflow CWE-824 3.7K 2 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in ragged.cross shape inference

CVE-2021-41212
7.1
EPSS 0.0%
DoS Data Extraction Code Execution Framework Training Data Inference
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in QuantizeV2 shape inference

CVE-2021-41211
7.1
EPSS 0.0%
Data Extraction DoS Framework Training Data Inference
tensorflow CWE-125 3.7K 3 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial