AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
490 vulnerabilities tracked — CVEs, prompt injection, model exploits.
MEDIUM
GitHub Copilot Vulnerable to Malicious Repository Suggestion Hijacking
GitHub Copilot (VS Code extension)
GitHub Copilot (JetBrains extension)
10 Nov 2025
1 views
Patched
HIGH
Indirect Prompt Injection in Azure OpenAI 'On Your Data' Leads to Cross-Tenant Data Exfiltration
Previous
Page 11 of 41
Next
Azure OpenAI Service (On Your Data feature)
30 June 2025
0 views
Patched
HIGH
CVE-2024-0089
NVIDIA GPU Driver Kernel Mode Layer Allows Privilege Escalation in Multi-Tenant AI Clusters
NVIDIA GPU Driver for Linux (versions prior to 550.76)
18 Jan 2026
1 views
Patched
CRITICAL
'Sleeper Agent' Model Poisoning Attack on Hugging Face Hub Compromises Downstream Applications
huggingface-hub
transformers
any application using poisoned models
22 Sept 2025
0 views
Unpatched
CRITICAL
CVE-2023-36258
Remote Code Execution via Deserialization in LangChain's Agent Tool Parser
LangChain 0.1.x
LangChain 0.2.x
15 Apr 2025
1 views
Patched
MEDIUM
GitHub Copilot Vulnerable to 'Tabnabbing' via Malicious Code Suggestions
GitHub Copilot for VS Code
GitHub Copilot for JetBrains
Other AI coding assistants with cross-file contextual awareness
22 Sept 2025
0 views
Unpatched
HIGH
CVE-2024-0073
NVIDIA GPU Driver Kernel Mode Layer Contains Out-of-Bounds Write Vulnerability
NVIDIA GPU Driver for Linux (all GPUs) < 550.54.14
NVIDIA GPU Driver for Windows (all GPUs) < 551.61
NVIDIA Tesla Driver < 535.161.07
30 July 2025
0 views
Patched
HIGH
Data Exfiltration from Vision-Enabled LLMs via Malicious Markdown Image Rendering
OpenAI GPT-4V (API and ChatGPT)
Google Gemini Pro Vision (API and Bard/Gemini UI)
Anthropic Claude 3 Sonnet/Opus
10 Jan 2026
0 views
Unpatched
CRITICAL
CVE-2023-49086
Malicious PyPI Package 'torchtriton' Steals Sensitive Credentials from AI Developers
Python environments where `torchtriton` was installed via pip
18 Feb 2025
0 views
Patched
CRITICAL
Indirect Prompt Injection in LangChain Agents via Web Content Allows Arbitrary Tool Execution
LangChain 0.1.x
LangChain-based agent applications
15 Apr 2025
0 views
Unpatched
CRITICAL
CVE-2025-31337
Server-Side Request Forgery in AWS Bedrock via Malicious Multimodal URL Input
AWS Bedrock (specific multimodal models, service patched on 2025-11-06)
5 Nov 2025
0 views
Patched
HIGH
CVE-2026-23456
Cross-Tenant GPU Memory Leak in Cloud ML Infrastructure via 'LeftoverLocals' Variant
NVIDIA H200 Tensor Core GPUs (Firmware prior to 560.x.x)
AMD Instinct MI400 series (Firmware prior to 6.2.x)
22 Jan 2026
0 views
Patched