AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1604 results
HIGH

TensorFlow: heap OOB read via tensor restore API

CVE-2021-37639
7.8
EPSS 0.0%
Code Execution Data Extraction Framework Training Data
tensorflow CWE-125 3.7K 3 ATLAS
HIGH

TensorFlow: null ptr deref in RaggedTensorToTensor op

CVE-2021-37638
7.8
EPSS 0.0%
Code Execution DoS Framework Inference
tensorflow 3.7K 3 ATLAS
MEDIUM

TensorFlow: null ptr dereference in CompressElement (DoS)

CVE-2021-37637
5.5
EPSS 0.0%
DoS Framework Training Data
tensorflow 3.7K 3 ATLAS
MEDIUM

TensorFlow: DoS via divide-by-zero in inplace ops

CVE-2021-37660
5.5
EPSS 0.0%
DoS Framework
tensorflow 3.7K 3 ATLAS
MEDIUM

TensorFlow: DoS via divide-by-zero in ResourceGather op

CVE-2021-37653
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow 3.7K 3 ATLAS
MEDIUM

TensorFlow: ResourceScatterDiv div-by-zero enables DoS

CVE-2021-37642
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow 3.7K 3 ATLAS
MEDIUM

TensorFlow: SparseReshape div-by-zero crashes ML pipelines

CVE-2021-37640
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow 3.7K 3 ATLAS
MEDIUM

TensorFlow: div-by-zero DoS in SparseDenseCwiseDiv op

CVE-2021-37636
5.5
EPSS 0.0%
DoS Framework
tensorflow 3.7K 3 ATLAS
CRITICAL EXPLOIT AVAIL

TensorFlow: path traversal in get_file allows file overwrite

CVE-2021-35958
9.1
EPSS 1.1%
Supply Chain Code Execution Framework Training Data
tensorflow CWE-22 3.7K 4 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS via invalid SparseCount op args

CVE-2021-29619
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS crash via tf.transpose complex+conjugate

CVE-2021-29618
5.5
EPSS 0.0%
DoS Framework Inference
tensorflow 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS via CHECK-fail in strings.substr

CVE-2021-29617
5.5
EPSS 0.0%
DoS Framework
tensorflow CWE-755 3.7K 2 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: null ptr deref in graph optimizer

CVE-2021-29616
7.8
EPSS 0.0%
Code Execution DoS Framework Inference
tensorflow CWE-476 3.7K 2 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: uncontrolled recursion DoS in ParseAttrValue

CVE-2021-29615
5.5
EPSS 0.0%
DoS Supply Chain Framework Inference
tensorflow 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: OOB write in decode_raw crashes interpreter

CVE-2021-29614
7.8
EPSS 0.0%
Code Execution DoS Framework Training Data
tensorflow CWE-787 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: CTCLoss heap OOB read, info leak + crash

CVE-2021-29613
7.1
EPSS 0.0%
DoS Data Extraction Framework Inference
tensorflow CWE-125 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap overflow in linalg op, RCE risk

CVE-2021-29612
7.8
EPSS 0.0%
Code Execution Framework Inference
tensorflow CWE-787 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS via SparseReshape invalid tensor input

CVE-2021-29611
5.5
EPSS 0.0%
DoS Framework
tensorflow CWE-20 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap R/W via quantization axis underflow

CVE-2021-29610
7.8
EPSS 0.0%
Code Execution Data Extraction Framework Inference
tensorflow CWE-787 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: SparseAdd heap OOB write and null deref

CVE-2021-29609
7.8
EPSS 0.0%
Code Execution DoS Framework Inference
tensorflow CWE-476 3.7K 3 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial