Attack Type

Privacy Violation

Privacy is an unusual security category in AI because the data is often inside the model rather than next to it. Three failure modes dominate. First, training-data memorization: models can be coaxed into emitting verbatim PII or copyrighted text from their corpus — a documented vector against several frontier LLMs. Second, vendor data retention: applications routinely send user content to third-party APIs (OpenAI, Anthropic, Google) where it may be retained, logged for safety review, or used to improve future models, depending on the contract; under GDPR this is a controller-processor relationship that requires DPAs and lawful basis. Third, application-layer leakage: chat histories cached without per-tenant keys, vector stores indexed without ACLs, and logs containing full prompts. Compliance frameworks now address this directly: ISO 42001 Annex A 9.x, EU AI Act Article 10 (Data Governance), and GDPR Article 25 (Data Protection by Design).

104
Total CVEs
6
Pages
Page 2 of 6
Current
Severity CVE CVSS
MEDIUM CVE-2025-68477 6.5
CRITICAL CVE-2026-21445 9.1
HIGH CVE-2023-46315 7.5
HIGH CVE-2024-1728 7.5
UNKNOWN CVE-2024-1183 -
MEDIUM CVE-2024-4940 6.1
MEDIUM CVE-2024-47168 4.3
HIGH CVE-2024-47870 8.1
CRITICAL CVE-2024-47871 9.1
MEDIUM CVE-2024-47872 5.4
MEDIUM CVE-2024-48052 6.5
CRITICAL CVE-2024-41118 9.8
MEDIUM CVE-2025-63390 5.3
MEDIUM CVE-2026-25475 6.5
MEDIUM CVE-2024-37145 6.1
HIGH CVE-2025-25185 7.5
HIGH CVE-2025-59527 7.5
HIGH CVE-2025-61784 8.1
MEDIUM CVE-2024-5206 4.7
HIGH CVE-2025-61917 7.7

Page 2 of 6