AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 12 of 1092 results — no patch
MEDIUM EXPLOIT AVAIL

TensorFlow: null ptr deref in dlpack causes remote DoS

CVE-2020-15191
5.3
EPSS 0.2%
DoS Code Execution Framework Inference
tensorflow CWE-252 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: null ptr deref DoS via Switch op eager runtime

CVE-2020-15190
5.3
EPSS 0.2%
DoS Framework Inference
tensorflow CWE-476 3.7K 3 ATLAS
CRITICAL EXPLOIT AVAIL

scikit-learn: RCE via malicious joblib model deserialization

CVE-2020-13092
9.8
EPSS 0.9%
Code Execution Supply Chain Framework Model
scikit-learn CWE-502 27.9K 5 ATLAS
MEDIUM

TensorFlow: integer overflow leaks process memory via BMP

CVE-2018-21233
6.5
EPSS 0.1%
Data Extraction Privacy Violation Supply Chain Framework Inference
tensorflow CWE-125 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: type confusion DoS crashes eager mode inference

CVE-2020-5215
7.5
EPSS 0.2%
DoS Supply Chain Framework Inference
tensorflow CWE-20 3.7K 5 ATLAS
CRITICAL

TensorFlow: heap overflow in UnsortedSegmentSum op

CVE-2019-16778
9.8
EPSS 0.3%
Code Execution Supply Chain Framework Inference
tensorflow CWE-681 3.7K 3 ATLAS
UNKNOWN

TensorFlow: buffer overflow, potential RCE in 1.7.x

CVE-2018-7575
--
EPSS 0.2%
Code Execution Supply Chain Framework Model
tensorflow CWE-190 3.7K 4 ATLAS
UNKNOWN EXPLOIT AVAIL

TensorFlow: NULL ptr deref DoS via malformed GIF input

CVE-2019-9635
--
EPSS 0.1%
DoS Framework Inference
tensorflow CWE-476 3.7K 3 ATLAS
UNKNOWN

TensorFlow: Snappy memcpy overlap crash/mem disclosure

CVE-2018-7577
--
EPSS 0.2%
DoS Data Extraction Supply Chain Framework Training Data Inference
tensorflow CWE-20 3.7K 3 ATLAS
UNKNOWN EXPLOIT AVAIL

TensorFlow XLA: heap overflow via crafted config file

CVE-2018-10055
--
EPSS 0.2%
Code Execution DoS Framework Training Data
tensorflow CWE-119 3.7K 3 ATLAS
HIGH

TensorFlow 1.7: Buffer overflow enables arbitrary code exec

CVE-2018-8825
8.8
EPSS 0.2%
Code Execution Supply Chain Framework Inference Model
tensorflow CWE-119 3.7K 5 ATLAS
UNKNOWN

TensorFlow: NPD in 1.6.x crashes ML runtime

CVE-2018-7576
--
EPSS 0.1%
DoS Code Execution Framework Inference
tensorflow CWE-476 3.7K 3 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial