AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1604 results
MEDIUM EXPLOIT AVAIL

TensorFlow: heap overflow in ragged tensor ops

CVE-2020-15201
4.8
EPSS 0.2%
Code Execution Data Extraction Framework Inference
tensorflow CWE-787 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: heap overflow in RaggedCountSparseOutput DoS

CVE-2020-15200
5.9
EPSS 0.3%
DoS Code Execution Framework Inference
tensorflow CWE-787 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS via malformed ragged tensor input

CVE-2020-15199
5.9
EPSS 0.2%
DoS Framework Inference
tensorflow CWE-20 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: heap OOB in SparseCountSparseOutput ops

CVE-2020-15198
5.4
EPSS 0.2%
Code Execution DoS Framework Inference
tensorflow CWE-119 3.7K 4 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS via malformed sparse tensor input

CVE-2020-15197
6.3
EPSS 0.2%
DoS Framework Inference
tensorflow 3.7K 3 ATLAS
CRITICAL EXPLOIT AVAIL

TensorFlow: heap OOB read in sparse/ragged count ops

CVE-2020-15196
9.9
EPSS 0.3%
Code Execution Data Extraction Framework Inference Training Data
tensorflow CWE-125 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: heap overflow in sparse gradient op

CVE-2020-15195
8.8
EPSS 0.4%
Code Execution Supply Chain Framework Inference Training Data
tensorflow CWE-787 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: DoS via SparseFillEmptyRowsGrad assertion

CVE-2020-15194
5.3
EPSS 0.2%
DoS Framework Inference
tensorflow CWE-617 3.7K 3 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: uninitialized memory corruption via dlpack

CVE-2020-15193
7.1
EPSS 0.2%
Code Execution DoS Framework Inference
tensorflow CWE-908 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: memory leak in dlpack DoS via low-priv input

CVE-2020-15192
4.3
EPSS 0.2%
DoS Framework Inference
tensorflow CWE-20 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: null ptr deref in dlpack causes remote DoS

CVE-2020-15191
5.3
EPSS 0.2%
DoS Code Execution Framework Inference
tensorflow CWE-252 3.7K 3 ATLAS
MEDIUM EXPLOIT AVAIL

TensorFlow: null ptr deref DoS via Switch op eager runtime

CVE-2020-15190
5.3
EPSS 0.2%
DoS Framework Inference
tensorflow CWE-476 3.7K 3 ATLAS
CRITICAL EXPLOIT AVAIL

scikit-learn: RCE via malicious joblib model deserialization

CVE-2020-13092
9.8
EPSS 0.9%
Code Execution Supply Chain Framework Model
scikit-learn CWE-502 27.9K 5 ATLAS
MEDIUM

TensorFlow: integer overflow leaks process memory via BMP

CVE-2018-21233
6.5
EPSS 0.1%
Data Extraction Privacy Violation Supply Chain Framework Inference
tensorflow CWE-125 3.7K 4 ATLAS
HIGH EXPLOIT AVAIL

TensorFlow: type confusion DoS crashes eager mode inference

CVE-2020-5215
7.5
EPSS 0.2%
DoS Supply Chain Framework Inference
tensorflow CWE-20 3.7K 5 ATLAS
CRITICAL

TensorFlow: heap overflow in UnsortedSegmentSum op

CVE-2019-16778
9.8
EPSS 0.3%
Code Execution Supply Chain Framework Inference
tensorflow CWE-681 3.7K 3 ATLAS
MEDIUM

Jupyter Notebook: XSS via missing CSP on served files

CVE-2018-21030
5.3
EPSS 0.4%
Code Execution Data Leakage Framework
notebook Patch: 5.5.0rc1 CWE-79 2.9K 3 ATLAS
UNKNOWN

TensorFlow: buffer overflow, potential RCE in 1.7.x

CVE-2018-7575
--
EPSS 0.2%
Code Execution Supply Chain Framework Model
tensorflow CWE-190 3.7K 4 ATLAS
UNKNOWN EXPLOIT AVAIL

TensorFlow: NULL ptr deref DoS via malformed GIF input

CVE-2019-9635
--
EPSS 0.1%
DoS Framework Inference
tensorflow CWE-476 3.7K 3 ATLAS
UNKNOWN

TensorFlow: Snappy memcpy overlap crash/mem disclosure

CVE-2018-7577
--
EPSS 0.2%
DoS Data Extraction Supply Chain Framework Training Data Inference
tensorflow CWE-20 3.7K 3 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial