AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
490 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
GitHub Copilot Log Injection Enables Exfiltration of Local Environment Variables
GitHub Copilot for VS Code < 1.185.0
1 Mar 2026
0 views
Patched
HIGH
Server-Side Request Forgery (SSRF) in Hugging Face Hub via Malicious Model Upload
Previous
Page 7 of 41
Next
Hugging Face Hub Platform
5 Nov 2025
0 views
Patched
HIGH
CVE-2024-0073
NVIDIA GPU Driver Kernel Mode Layer Allows for Privilege Escalation in Multi-Tenant AI Clusters
NVIDIA GPU Driver (Linux) < 551.81
NVIDIA GPU Driver (Windows) < 555.52
10 Sept 2025
0 views
Patched
CRITICAL
Malicious PyPI Package `torch-optimizer` Steals Cloud Credentials from AI Developer Environments
PyPI Registry users
Python developers
20 May 2025
0 views
Patched
CRITICAL
Remote Code Execution in LangChain ReAct Agents via `PythonREPLTool` Manipulation
LangChain < 0.1.5
15 Feb 2025
0 views
Patched
CRITICAL
CVE-2024-23963
Remote Code Execution in TensorFlow via Insecure Deserialization in SavedModel Format
TensorFlow < 2.15.1
TensorFlow < 2.14.2
TensorFlow < 2.13.3
22 Jan 2025
3 views
Patched
HIGH
Data Exfiltration from RAG Systems via Poisoned Document Ingestion
Custom RAG applications
Azure OpenAI On Your Data
AWS Bedrock Knowledge Bases
GCP Vertex AI Search
5 Mar 2026
4 views
Unpatched
HIGH
GitHub Copilot Suggests Vulnerable Code Snippets Leading to Common Security Flaws
GitHub Copilot
Amazon CodeWhisperer
Tabnine
10 Sept 2025
18 views
Unpatched
CRITICAL
CVE-2022-42927
Arbitrary Code Execution via Malicious Pickle-Serialized Models on Hugging Face Hub
Any application loading `.pkl` or `.pth` model files from untrusted sources
Hugging Face Transformers <4.24.0 (when using TensorFlow checkpoints)
PyTorch (all versions without specific precautions)
20 June 2025
3 views
Patched
CRITICAL
Indirect Prompt Injection in LangChain Agents Enables Arbitrary Python Code Execution
LangChain <0.1.0
15 Mar 2025
2 views
Patched
MEDIUM
Data Exfiltration via LLM-Generated Markdown Image Rendering in Web Applications
Web applications integrating LLM responses without strict output sanitization
AI-powered chatbots
Web-based AI coding assistants
Customer support AI tools
5 Nov 2025
2 views
Unpatched
CRITICAL
CVE-2024-0073
NVIDIA CUDA Driver Use-After-Free Vulnerability Allows for Code Execution and Privilege Escalation
NVIDIA GPU Display Driver for Windows (before 551.61)
NVIDIA GPU Display Driver for Linux (before 550.54.14, 545.29.06, 535.154.05)
29 Jan 2025
2 views
Patched