AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
490 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
CVE-2023-31034
NVIDIA GPU Driver Kernel Mode Layer Contains Out-of-Bounds Write Vulnerability Allowing for Privilege Escalation
NVIDIA GPU Display Driver (Linux) < 535.129.03
NVIDIA GPU Display Driver (Windows) < 537.42
22 Jan 2026
1 views
Patched
HIGH
Previous
Page 16 of 41
Next
Indirect Prompt Injection in Web-Browsing AI Agents Enables Session Takeover and Data Exfiltration
AutoGPT
LangChain agents with browsing tools
LlamaIndex query engines with web retrieval
Any LLM-powered agent with internet access
10 Sept 2025
2 views
Unpatched
HIGH
Arbitrary Code Execution via Malicious Model Weights on Hugging Face Hub using Pickle Deserialization
Hugging Face Hub (via hosted models)
PyTorch < 2.1
Any Python application using pickle.load() on untrusted model files
20 June 2025
2 views
Unpatched
CRITICAL
CVE-2023-29374
Remote Code Execution in LangChain via Experimental PALChain Component
langchain <= 0.0.138
15 Feb 2025
2 views
Patched
CRITICAL
CVE-2024-28191
Hugging Face Hub CI/CD Takeover via Maliciously Crafted `config.json`
huggingface-hub <0.21.0
5 Nov 2025
2 views
Patched
HIGH
CVE-2023-36867
GitHub Copilot for VS Code Suggests Hardcoded Secrets from Public Training Data
Visual Studio Code GitHub Copilot Extension <1.97.0
10 June 2025
2 views
Patched
CRITICAL
Malicious PyPI Package `torchtriton` Steals Sensitive System Information from AI Developers
Python developers
Users of the 'torchtriton' PyPI package
20 Jan 2026
2 views
Patched
HIGH
Indirect Prompt Injection via Web Content Processing Leads to Agent Hijacking and Data Exfiltration
LangChain-based agents with browsing tools
LlamaIndex RAG pipelines
Custom AI agents with web browsing capabilities
AI-powered chatbots that summarize web pages
22 Aug 2025
2 views
Unpatched
CRITICAL
CVE-2023-29374
Arbitrary Code Execution in LangChain via Deserialization of Malicious `LLMMathChain` Input
LangChain <0.0.171
15 Apr 2025
2 views
Patched
CRITICAL
Server-Side Request Forgery (SSRF) in Cloud AI Service Web Data Ingestion Exposes Instance Metadata
AWS Bedrock
Azure OpenAI Service
GCP Vertex AI
22 Nov 2025
2 views
Patched
HIGH
GitHub Copilot Susceptible to Context Poisoning via Malicious Docstrings Leading to Credential Exfiltration
GitHub Copilot
Amazon CodeWhisperer
Tabnine
30 Jan 2026
2 views
Unpatched
HIGH
CVE-2024-0073
NVIDIA GPU Driver Kernel Mode Layer Contains Out-of-Bounds Write Vulnerability Leading to Privilege Escalation
NVIDIA GPU Driver for Linux (all branches prior to 550.54.14)
NVIDIA GPU Driver for Linux (all branches prior to 545.29.06)
NVIDIA GPU Driver for Linux (all branches prior to 535.154.05)
5 Oct 2025
2 views
Patched