AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 435 results — High severity, Active exploitation
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in quantize ops, DoS+leak

CVE-2021-41205
7.1
EPSS 0.0%
DoS Data Leakage Framework Training Data Inference
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: malformed checkpoint triggers overflow/crash

CVE-2021-41203
7.8
EPSS 0.0%
Supply Chain Code Execution DoS Framework Training Data
tensorflow CWE-190 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in SparseCountSparseOutput

CVE-2021-41210
7.1
EPSS 0.0%
Data Extraction Code Execution DoS Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: uninitialized var in Einsum allows local RCE

CVE-2021-41201
7.8
EPSS 0.0%
Code Execution Framework Inference
tensorflow CWE-824 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow/Keras: RCE via YAML model deserialization

CVE-2021-37678
8.8
EPSS 1.0%
Code Execution Supply Chain Framework Model
tensorflow CWE-502 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: null ptr deref in graph optimizer

CVE-2021-29616
7.8
EPSS 0.0%
Code Execution DoS Framework Inference
tensorflow CWE-476 3.7K 2 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: OOB write in decode_raw crashes interpreter

CVE-2021-29614
7.8
EPSS 0.0%
Code Execution DoS Framework Training Data
tensorflow CWE-787 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: CTCLoss heap OOB read, info leak + crash

CVE-2021-29613
7.1
EPSS 0.0%
DoS Data Extraction Framework Inference
tensorflow CWE-125 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap overflow in linalg op, RCE risk

CVE-2021-29612
7.8
EPSS 0.0%
Code Execution Framework Inference
tensorflow CWE-787 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap R/W via quantization axis underflow

CVE-2021-29610
7.8
EPSS 0.0%
Code Execution Data Extraction Framework Inference
tensorflow CWE-787 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: SparseAdd heap OOB write and null deref

CVE-2021-29609
7.8
EPSS 0.0%
Code Execution DoS Framework Inference
tensorflow CWE-476 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB in RaggedTensorToTensor op

CVE-2021-29608
7.8
EPSS 0.0%
Code Execution Supply Chain Framework Training Data
tensorflow 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB write in SparseAdd op

CVE-2021-29607
7.8
EPSS 0.0%
Code Execution DoS Framework Inference Training Data
tensorflow 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow Lite: OOB read via crafted TFLite model

CVE-2021-29606
7.8
EPSS 0.0%
Supply Chain Code Execution Data Extraction Framework Inference
tensorflow 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow TFLite: heap OOB write via malformed model

CVE-2021-29603
7.8
EPSS 0.0%
Code Execution Supply Chain Framework Inference
tensorflow 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow Lite: integer overflow in model concatenation

CVE-2021-29601
7.1
EPSS 0.0%
Supply Chain Code Execution Framework Model Inference
tensorflow 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow TFLite: div-by-zero via crafted OneHot model

CVE-2021-29600
7.8
EPSS 0.0%
DoS Code Execution Supply Chain Framework Inference Model
tensorflow CWE-369 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TFLite Split: malicious model triggers div-by-zero (DoS/RCE)

CVE-2021-29599
7.8
EPSS 0.0%
DoS Code Execution Supply Chain Framework Inference
tensorflow 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow TFLite: SVDF div-by-zero enables RCE

CVE-2021-29598
7.8
EPSS 0.0%
Code Execution DoS Supply Chain Framework Inference Model
tensorflow 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow TFLite: div-by-zero crash via crafted model

CVE-2021-29597
7.8
EPSS 0.0%
DoS Code Execution Supply Chain Framework Inference
tensorflow 3.7K 4 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial