Known exploited vulnerabilities in AI software
14 advisories in this database are listed in the CISA Known Exploited Vulnerabilities catalog, which names vulnerabilities that CISA reports as exploited in the wild. The catalog covers all kinds of software. This list includes only the entries that match an advisory for AI software in this database.
Every CVE in the database is compared with the catalog on each fetch cycle. Fetch cycles run every six hours. The methods page describes how each field is produced and its limits.
Severity comes from the source advisory when it gives one, otherwise from the classifier. EPSS is the FIRST estimate of the probability that a CVE is exploited in the next 30 days, and it is read again about once a day. Ransomware use is the catalog's own field for known use in ransomware campaigns. A record stays on this list if CISA later removes its entry. Published dates are in UTC.