Tensorflow

Vendor:

First CVE: Apr 23, 2019 · Active for 7 years

432
Total CVEs
More Total CVEs than 100% of tracked products
61.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tensorflow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2019
7 years ago
Most Recent CVE
Sep 25, 2025
302 days ago

CVE Severity & Scoring

Tensorflow432 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local232 (53.7%)
Network200 (46.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low418 (96.8%)
High14 (3.2%)
Unknown0 (0.0%)
User Interaction
None425 (98.4%)
Unknown0 (0.0%)
Required7 (1.6%)
Privileges Required
Low287 (66.4%)
High0 (0.0%)
None145 (33.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (432 CVEs).

432 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.
Mar 25, 20239.831NONO
TensorFlow is an open source platform for machine learning. The `ScatterNd` function takes an input argument that determines the indices of of the output tensor. An input index gre
Sep 16, 20229.831NONO
TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater
Sep 16, 20229.130NONO
Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vulnerable to an integer overflow during cost estimation for c
Feb 4, 20229.830NONO
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside o
Sep 25, 20209.830NONO
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values tha
Sep 25, 20209.830NONO
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields ar
Dec 16, 20199.830NONO
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
Apr 24, 20199.830NONO
TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. Attackers using Tensorflow can
Nov 18, 20229.829NONO
TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater
Sep 16, 20229.129NONO

Exploit Exposure

Signals from CVEs in this product scope (432 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (432 CVEs).

Media Mentions

Signals from CVEs in this product scope (432 CVEs).

Top CNAs Publishing CVEs For Tensorflow

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.9.0265.80.3%00
2.8.0245.80.3%00
2.7.0876.50.5%00
2.6.0676.50.2%00
2.5.0576.50.2%00
2.4.017.50.7%00
2.3.086.20.7%00
2.2.035.60.7%00
2.18.027.00.2%00
2.10.0137.90.4%00
2.10597.60.4%00