AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
932 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
CVE-2024-0072
Privilege Escalation via Out-of-Bounds Write in NVIDIA CUDA Driver
NVIDIA GPU Driver for Linux (versions < 535.154.05)
NVIDIA GPU Driver for Windows (versions < 538.33)
30 June 2025
7 views
Patched
HIGH
Previous
Page 61 of 78
Next
Indirect Prompt Injection in Azure OpenAI 'On Your Data' Leads to Cross-Tenant Data Exfiltration
Azure OpenAI Service (On Your Data feature)
30 June 2025
9 views
Patched
HIGH
CVE-2023-36410
SSRF Vulnerability in Azure OpenAI 'On Your Data' Feature Exposes Internal Services
Azure OpenAI Service
30 June 2025
14 views
Patched
MEDIUM
Azure OpenAI Service Insecure Default Network Settings Allow Unauthorized Endpoint Discovery
Azure OpenAI Service
30 June 2025
10 views
Patched
HIGH
Hugging Face Hub Misconfiguration Leaks Sensitive Tokens in Multi-Tenant Inference Environments
Hugging Face Text Generation Inference (TGI) < 1.1.0
Hugging Face Inference Endpoints (prior to Oct 2023 patch)
22 June 2025
11 views
Patched
HIGH
Data Exfiltration via Indirect Prompt Injection in Markdown Image Rendering
AI agents processing external markdown content
ChatGPT with browsing capabilities
Custom LangChain/LlamaIndex agents with web retrieval tools
22 June 2025
4 views
Unpatched
HIGH
Indirect Prompt Injection in AI Agents via Unsanitized Web Content Leading to Data Exfiltration
LangChain agents
LlamaIndex RAG pipelines
AutoGPT
Web-browsing AI assistants
22 June 2025
61 views
Unpatched
CRITICAL
CVE-2022-42927
Arbitrary Code Execution via Malicious Pickle-Serialized Models on Hugging Face Hub
Any application loading `.pkl` or `.pth` model files from untrusted sources
Hugging Face Transformers <4.24.0 (when using TensorFlow checkpoints)
PyTorch (all versions without specific precautions)
20 June 2025
1 views
Patched
CRITICAL
Malicious AI Model on Hugging Face Hub Leads to Supply Chain Compromise via Pickle Deserialization
PyTorch < 2.1.0
Hugging Face Hub
MLOps Pipelines
20 June 2025
154 views
Unpatched
HIGH
Arbitrary Code Execution via Malicious Model Weights on Hugging Face Hub using Pickle Deserialization
Hugging Face Hub (via hosted models)
PyTorch < 2.1
Any Python application using pickle.load() on untrusted model files
20 June 2025
5 views
Unpatched
CRITICAL
Malicious PyPI Package 'torch-optimizer-utils' Steals Cloud and AI Service Credentials
Python developers using PyPI
20 June 2025
5 views
Patched
HIGH
Cross-Tenant Data Exfiltration in AI Coding Assistants via Indirect Prompt Injection
GitHub Copilot
Cursor IDE
Amazon CodeWhisperer
Various LLM-integrated IDEs
20 June 2025
6 views
Unpatched