AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

78

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1092 results — no patch
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in SparseFillEmptyRows op

CVE-2021-41224
7.1
EPSS 0.0%
Code Execution DoS Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: FusedBatchNorm heap OOB allows data leak/crash

CVE-2021-41223
7.1
EPSS 0.0%
Data Leakage DoS Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB in sparse matrix multiply

CVE-2021-41219
7.8
EPSS 0.0%
Code Execution DoS Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: null pointer crash in control flow graph

CVE-2021-41217
5.5
EPSS 0.0%
DoS Supply Chain Framework Model Inference
tensorflow CWE-476 3.7K 4 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DeserializeSparse null deref causes DoS

CVE-2021-41215
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow CWE-476 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: null deref in ragged ops, local RCE

CVE-2021-41214
7.8
EPSS 0.0%
Code Execution Framework
tensorflow CWE-824 3.7K 2 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in ragged.cross shape inference

CVE-2021-41212
7.1
EPSS 0.0%
DoS Data Extraction Code Execution Framework Training Data Inference
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in QuantizeV2 shape inference

CVE-2021-41211
7.1
EPSS 0.0%
Data Extraction DoS Framework Training Data Inference
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in quantize ops, DoS+leak

CVE-2021-41205
7.1
EPSS 0.0%
DoS Data Leakage Framework Training Data Inference
tensorflow CWE-125 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS via Grappler constant folding segfault

CVE-2021-41204
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow CWE-824 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: malformed checkpoint triggers overflow/crash

CVE-2021-41203
7.8
EPSS 0.0%
Supply Chain Code Execution DoS Framework Training Data
tensorflow CWE-190 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap OOB read in SparseCountSparseOutput

CVE-2021-41210
7.1
EPSS 0.0%
Data Extraction Code Execution DoS Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: uninitialized var in Einsum allows local RCE

CVE-2021-41201
7.8
EPSS 0.0%
Code Execution Framework Inference
tensorflow CWE-824 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS crash in tf.summary file writer

CVE-2021-41200
5.5
EPSS 0.0%
DoS Framework Training Data
tensorflow CWE-617 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: tf.image.resize integer overflow DoS

CVE-2021-41199
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow CWE-190 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: tf.tile integer overflow crashes ML process

CVE-2021-41198
5.5
EPSS 0.0%
DoS Framework Inference Training Data
tensorflow CWE-190 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: integer overflow in tensor dims causes DoS

CVE-2021-41197
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow CWE-190 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: integer underflow crashes Keras pooling layers

CVE-2021-41196
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow CWE-191 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: integer overflow in segment ops causes DoS

CVE-2021-41195
5.5
EPSS 0.0%
DoS Framework
tensorflow CWE-190 3.7K 3 ATLAS
HIGH

nbgitpuller: RCE via OS command injection in git URLs

CVE-2021-39160
8.8
EPSS 0.8%
Code Execution Supply Chain Framework Training Data
CWE-78 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial