AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 684 results — High severityMLflow: OS command injection enables local code execution
CVE-2023-4033 LangChain SQLDatabaseChain: SQL injection, DB exfil
CVE-2023-36189 MLflow: path traversal exposes arbitrary server files
CVE-2023-30172 n8n: unauthenticated info disclosure exposes credentials
CVE-2023-27564 n8n: privilege escalation exposes full workflow admin
CVE-2023-27563 MLflow: path traversal allows unauthenticated file read
CVE-2023-2356 TensorFlow Lite: FPE in tflite model crashes inference runtime
CVE-2023-27579 TensorFlow: double-free in pooling ops enables RCE
CVE-2023-25801 TensorFlow: NULL ptr deref DoS in ParallelConcat op
CVE-2023-25676 TensorFlow XLA: Bincount shape mismatch causes DoS
CVE-2023-25675 TensorFlow: null pointer DoS in RandomShuffle (XLA)
CVE-2023-25674 TensorFlow: FPE in TensorListSplit (XLA) remote DoS
CVE-2023-25673 TensorFlow: NPE in LookupTableImportV2 causes DoS
CVE-2023-25672 TensorFlow: OOB write DoS via integer type mismatch
CVE-2023-25671 TensorFlow: null ptr DoS in quantized MKL MatMul
CVE-2023-25670 TensorFlow: DoS via AvgPoolGrad invalid stride params
CVE-2023-25669 TensorFlow: integer overflow DoS in video frame decoding
CVE-2023-25667 TensorFlow: FPE in AudioSpectrogram causes DoS
CVE-2023-25666 TensorFlow: null ptr deref DoS via sparse tensors
CVE-2023-25665 TensorFlow: null ptr deref crashes inference serving
CVE-2023-25663 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert