AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
916 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
Arbitrary Code Execution via Poisoned Model Weights on Hugging Face Hub Using Unsafe `pickle` Deserialization
Hugging Face Transformers
PyTorch
Hugging Face Hub
15 Jan 2026
12 views
Unpatched
HIGH
"PickleRick Roll" - Arbitrary Code Execution via Sideloaded Pickle File in Hugging Face Models
Previous
Page 34 of 77
Next
transformers (all versions when loading untrusted models)
torch (all versions)
15 Jan 2026
70 views
Unpatched
HIGH
CVE-2026-11451
NVIDIA vGPU Driver Vulnerability Allows Guest-to-Host Memory Leak
NVIDIA vGPU Software versions 15.x before 15.5
NVIDIA vGPU Software versions 16.x before 16.3
10 Jan 2026
0 views
Patched
HIGH
Indirect Prompt Injection in Web Browsing Agents Exfiltrates User Data
AutoGPT
LangChain Web-Browsing Agents
LlamaIndex Web Agents
Any LLM-based agent with un-sandboxed web browsing tools
10 Jan 2026
0 views
Unpatched
HIGH
Indirect Prompt Injection via Web Content Hijacks AI Assistants for Data Exfiltration
OpenAI GPT-4 with Browsing
Google Gemini with extensions
LangChain agents using search tools
Perplexity AI
10 Jan 2026
4 views
Unpatched
HIGH
CVE-2023-25515
NVIDIA DCGM Privilege Escalation in GPU-Accelerated Kubernetes Clusters
NVIDIA DCGM versions prior to 3.1.8
NVIDIA GPU Operator versions prior to v22.9.2
10 Jan 2026
3 views
Patched
HIGH
Data Exfiltration from Vision-Enabled LLMs via Malicious Markdown Image Rendering
OpenAI GPT-4V (API and ChatGPT)
Google Gemini Pro Vision (API and Bard/Gemini UI)
Anthropic Claude 3 Sonnet/Opus
10 Jan 2026
3 views
Unpatched
CRITICAL
CVE-2025-13370
Cross-Tenant Data Exfiltration in a Major Cloud AI Service via Model Training Cache Poisoning
GCP Vertex AI Training
AWS SageMaker
Azure Machine Learning
10 Jan 2026
6 views
Patched
HIGH
Data Exfiltration from AWS Bedrock Agents via Indirect Prompt Injection in Fetched Web Content
AWS Bedrock Agents
Azure OpenAI On Your Data
GCP Vertex AI Search
LangChain Agents
10 Jan 2026
6 views
Unpatched
HIGH
Cross-Tenant Prompt Leakage in AWS Bedrock's Multi-Model Endpoint Cache
AWS Bedrock (Provisioned Throughput with Multi-Model Endpoints)
10 Jan 2026
4 views
Patched
CRITICAL
Malicious Code Execution via Compromised `torch-optimizer` PyPI Package Targeting AI Developers
torch-optimizer 0.4.1
torch-optimizer 0.4.2
10 Jan 2026
10 views
Patched
CRITICAL
Malicious Payload in Popular Hugging Face Model Executes Code During Inference
Hugging Face Hub
PyTorch > 2.2.0
Hugging Face Transformers > 4.40.0
10 Jan 2026
7 views
Unpatched