AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 377 results — Medium severity
MEDIUM CVE-2022-23569

Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fails (i.e., assertion failures). This is similar to...

CVSS 6.5 tensorflow CWE-617
View details
MEDIUM CVE-2022-21735

Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalMaxPool` can be made to crash a TensorFlow process via a division by 0. The fix will be included in...

CVSS 6.5 tensorflow CWE-369
View details
MEDIUM CVE-2022-21734

Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a scalar. The fix will be included in TensorFlow 2.8.0....

CVSS 6.5 tensorflow CWE-843
View details
MEDIUM CVE-2022-21729

Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an integer overflow bug. The fix will be included in...

CVSS 6.5 tensorflow CWE-190
View details
MEDIUM CVE-2022-21725

Tensorflow is an Open Source Machine Learning Framework. The estimator for the cost of some convolution operations can be made to execute a division by 0. The function fails to check that the stride...

CVSS 6.5 tensorflow CWE-369
View details
MEDIUM CVE-2022-23568

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable to an integer overflow which results in a `CHECK`-fail when building new...

CVSS 6.5 tensorflow CWE-190
View details
MEDIUM CVE-2022-23567

Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to integer overflows. These can be used to trigger large allocations (so, OOM based...

CVSS 6.5 tensorflow CWE-190
View details
MEDIUM CVE-2022-21736

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefined behavior: under certain condition it can be made to dereference a `nullptr`...

CVSS 6.5 tensorflow CWE-476
View details
MEDIUM CVE-2022-21733

Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by causing an out of memory condition after an integer...

CVSS 6.5 tensorflow CWE-190
View details
MEDIUM CVE-2022-21732

Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack by allocating too much memory. This is because the...

CVSS 6.5 tensorflow CWE-770
View details
MEDIUM CVE-2022-21731

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of service attack via a segfault caused by a type...

CVSS 6.5 tensorflow CWE-843
View details
MEDIUM CVE-2021-41227

TensorFlow is an open source platform for machine learning. In affected versions the `ImmutableConst` operation in TensorFlow can be tricked into reading arbitrary memory contents. This is because...

CVSS 5.5 tensorflow CWE-125
View details
MEDIUM CVE-2021-41222

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trigger a segfault is an attacker supplies negative arguments. This occurs whenever...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-41213

TensorFlow is an open source platform for machine learning. In affected versions the code behind `tf.function` API can be made to deadlock when two `tf.function` decorated Python functions are...

CVSS 5.5 tensorflow CWE-662
View details
MEDIUM CVE-2021-41218

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `AllToAll` can be made to execute a division by 0. This occurs whenever the `split_count`...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-41209

TensorFlow is an open source platform for machine learning. In affected versions the implementations for convolution operators trigger a division by 0 if passed empty filter tensor arguments. The fix...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-41207

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `ParallelConcat` misses some input validation and can produce a division by 0. The fix will be...

CVSS 5.5 EPSS 0.0% tensorflow CWE-369
View details
MEDIUM CVE-2021-41202

TensorFlow is an open source platform for machine learning. In affected versions while calculating the size of the output within the `tf.range` kernel, there is a conditional statement of type `int64...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-41217

TensorFlow is an open source platform for machine learning. In affected versions the process of building the control flow graph for a TensorFlow model is vulnerable to a null pointer exception when...

CVSS 5.5 tensorflow CWE-476
View details
MEDIUM CVE-2021-41215

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `DeserializeSparse` can trigger a null pointer dereference. This is because the shape...

CVSS 5.5 tensorflow CWE-476
View details
MEDIUM CVE-2021-41204

TensorFlow is an open source platform for machine learning. In affected versions during TensorFlow's Grappler optimizer phase, constant folding might attempt to deep copy a resource tensor. This...

CVSS 5.5 tensorflow CWE-824
View details
MEDIUM CVE-2021-41200

TensorFlow is an open source platform for machine learning. In affected versions if `tf.summary.create_file_writer` is called with non-scalar arguments code crashes due to a `CHECK`-fail. The fix...

CVSS 5.5 tensorflow CWE-617
View details
MEDIUM CVE-2021-41199

TensorFlow is an open source platform for machine learning. In affected versions if `tf.image.resize` is called with a large input argument then the TensorFlow process will crash due to a...

CVSS 5.5 tensorflow CWE-190
View details
MEDIUM CVE-2021-41198

TensorFlow is an open source platform for machine learning. In affected versions if `tf.tile` is called with a large input argument then the TensorFlow process will crash due to a `CHECK`-failure...

CVSS 5.5 tensorflow CWE-190
View details
MEDIUM CVE-2021-41197

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow allows tensor to have a large number of dimensions and each dimension can be as large as desired. However,...

CVSS 5.5 tensorflow CWE-190
View details
MEDIUM CVE-2021-41196

TensorFlow is an open source platform for machine learning. In affected versions the Keras pooling layers can trigger a segfault if the size of the pool is 0 or if a dimension is negative. This is...

CVSS 5.5 tensorflow CWE-191
View details
MEDIUM CVE-2021-41195

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `tf.math.segment_*` operations results in a `CHECK`-fail related abort (and denial of service)...

CVSS 5.5 tensorflow CWE-190
View details
MEDIUM CVE-2021-37690

TensorFlow is an end-to-end open source platform for machine learning. In affected versions when running shape functions, some functions (such as `MutableHashTableShape`) produce extra output...

CVSS 6.6 tensorflow
View details
MEDIUM CVE-2021-37692

TensorFlow is an end-to-end open source platform for machine learning. In affected versions under certain conditions, Go code can trigger a segfault in string deallocation. For string tensors,...

CVSS 5.5 EPSS 0.0% tensorflow CWE-20
View details
MEDIUM CVE-2021-37691

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a division by zero error in LSH...

CVSS 5.5 tensorflow CWE-369
View details
MEDIUM CVE-2021-37687

TensorFlow is an end-to-end open source platform for machine learning. In affected versions TFLite's [`GatherNd`...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37685

TensorFlow is an end-to-end open source platform for machine learning. In affected versions TFLite's...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37684

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementations of pooling in TFLite are vulnerable to division by 0 errors as there are no checks for...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37683

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of division in TFLite is [vulnerable to a division by 0...

CVSS 5.5 tensorflow CWE-369
View details
MEDIUM CVE-2021-37677

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the shape inference code for `tf.raw_ops.Dequantize` has a vulnerability that could trigger a denial of...

CVSS 5.5 tensorflow CWE-1284
View details
MEDIUM CVE-2021-37674

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a segmentation fault in `tf.raw_ops.MaxPoolGrad` caused by...

CVSS 5.5 tensorflow CWE-1284
View details
MEDIUM CVE-2021-37673

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.MapStage`. The...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37672

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37670

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37669

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37668

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using `tf.raw_ops.UnravelIndex` by...

CVSS 5.5 tensorflow CWE-369
View details
MEDIUM CVE-2021-37689

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a null pointer dereference, which would result in a...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37688

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a null pointer dereference, which would result in a...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37686

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the strided slice implementation in TFLite has a logic bug which can allow an attacker to trigger an...

CVSS 5.5 EPSS 0.0% tensorflow CWE-835
View details
MEDIUM CVE-2021-37680

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of fully connected layers in TFLite is [vulnerable to a division by zero...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37675

TensorFlow is an end-to-end open source platform for machine learning. In affected versions most implementations of convolution operators in TensorFlow are affected by a division by 0 vulnerability...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37661

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a denial of service in `boosted_trees_create_quantile_stream_resource` by using...

CVSS 5.5 tensorflow CWE-681
View details
MEDIUM CVE-2021-37646

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.StringNGrams` is vulnerable to an integer overflow issue caused by...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37645

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` is vulnerable to an integer overflow issue...

CVSS 5.5 tensorflow
View details
MEDIUM CVE-2021-37644

TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the...

CVSS 5.5 tensorflow
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial