AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
936 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
CVE-2023-31041
NVIDIA Triton Inference Server Path Traversal via Model Repository API
NVIDIA Triton Inference Server < 23.04
11 Feb 2025
5 views
Patched
CRITICAL
CVE-2023-4863
Heap Overflow in Official TensorFlow Container via Vulnerable libwebp Dependency
Previous
Page 77 of 78
Next
tensorflow/tensorflow:2.13.0
Official PyTorch Docker Images < 23.09
11 Feb 2025
5 views
Patched
CRITICAL
Malicious Pickle Deserialization in Hugging Face Hub Models Leading to Remote Code Execution
Hugging Face Hub
transformers
PyTorch
10 Feb 2025
2 views
Unpatched
HIGH
CVE-2024-0073
NVIDIA GPU Display Driver Kernel Mode Layer Privilege Escalation Vulnerability
NVIDIA GPU Display Driver (Windows) < 551.52
NVIDIA RTX/Quadro Driver (Windows) < R550 U1 (551.23)
10 Feb 2025
5 views
Patched
CRITICAL
CVE-2023-52303
Malicious PyPI Package 'torchtriton' Steals Sensitive Data from AI/ML Developers
torchtriton (PyPI package) versions 2.1.0
10 Feb 2025
6 views
Patched
HIGH
Indirect Prompt Injection in AI Email Assistant Exfiltrates Sensitive User Data
AI Email Assistant Applications
LLM Agents with Web Browsing/API tools
10 Feb 2025
6 views
Unpatched
CRITICAL
Malicious Model on Hugging Face Hub Leverages Unsafe Pickle Deserialization for Remote Code Execution
PyTorch
Hugging Face Transformers
Any application using torch.load on untrusted models
10 Feb 2025
173 views
Unpatched
CRITICAL
CVE-2024-0071
Command Injection in NVIDIA DGX BMC Allows Root Privilege Escalation
NVIDIA DGX A100 (BMC firmware versions prior to 00.22.06)
NVIDIA DGX H100 (BMC firmware versions prior to 01.03.02)
10 Feb 2025
5 views
Patched
HIGH
Indirect Prompt Injection in RAG Systems Enables Cross-Organizational Data Exfiltration
All RAG systems processing untrusted documents
LangChain Agents
LlamaIndex Agents
Custom AI Assistants with tool-use capabilities
10 Feb 2025
11 views
Unpatched
HIGH
Indirect Prompt Injection in AI Agents via Web Content Leads to Data Exfiltration
Microsoft Bing Chat (Copilot)
Google Gemini (formerly Bard)
ChatGPT (with browsing)
LangChain Agents (with web browsing tools)
10 Feb 2025
14 views
Unpatched
CRITICAL
Malicious `torchtriton` Package on PyPI Steals Sensitive Developer Credentials
Python developer environments
CI/CD build servers for ML projects
10 Feb 2025
38 views
Patched
CRITICAL
CVE-2024-21626
Container Escape via Insecure WORKDIR Handling in Docker/Buildkit Affects GPU-based ML Workloads
runc < 1.1.12
Docker < 25.0.2
Buildkit < 0.12.5
31 Jan 2025
5 views
Patched