YFarmX logoYFarmX
Security Desk · live register

AI-Found Vulnerabilities

47 vulnerabilities found by AI tools, each one checked at its official CVE record or vendor advisory

Real vulnerabilities that an AI tool found, from Google Big Sleep and XBOW to OpenAI's Aardvark and the open-source Vulnhuntr, compiled by YFarmX from the public CVE Program records and the vendors' own advisories. Each row shows how strong the evidence is, from a CVE record whose own credits name the AI tool down to a claim that rests on the finder's own write-up, and links straight to the record.

How this register is kept

what the number is, where it comes from, and how each row is checked

What the number is. 47 vulnerabilities on this register carry an identifier we checked at a primary record, a CVE record, a GitHub advisory or the merged fix, and are credited to an AI finder: 20 where the CVE record's own credits name the finder, 10 where the assigning CNA credits it in its own advisory, and 17 where the credit rests on the finder's or a researcher's publication against a record whose credits are empty or name people. Every row was checked against the CVE Program's cvelistV5 mirror on 12 and 19 September 2026.

Where it comes from. The CVE Program publishes every record for free public use under its terms of use. The register reads each record from the CVEProject/cvelistV5 mirror and takes the credit from the record's own credits field, then from the vendor's release note or advisory where the CNA files credit there, then from the finder's own publication. Each row links its record and the source that credits the AI, and its own page carries the credit verbatim.

The five tiers, strongest first. Credits array: the CVE record's own credits field names the finder, as CVE-2025-0133 does with XBOW and CVE-2024-9143 with Google OSS-Fuzz-Gen. CNA advisory: the assigning CNA credits the finder in its own release note or security page, which is how Apple and Chrome file credit. Outside claim: the finder or a researcher claims the row and the record's credits are empty or name people, which is where every Vulnhuntr, Aardvark and AISLE row sits. Awaiting record: an identifier quoted in public that the CVE Program's list will serve once the record publishes; the 9 rows here are depthfirst's FFmpeg identifiers, which answered 404 at the mirror on 12 and 19 September 2026. Aggregate total: a published headline count, such as XBOW's roughly 1,060 HackerOne reports; the 10 rows here are kept as their own tier because a total is a claim about a count rather than a record.

Reproduce a row. The weekly refresh is one command per row, run against the CVE Program's own mirror, reading the credits array rather than any announcement:

curl -sS "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/22xxx/CVE-2026-22795.json" \
  | python3 -c "import json,sys; d=json.load(sys.stdin)['containers']['cna']; print(d.get('credits'))"

The largest block is Google Big Sleep, 26 identified rows, with its origin in the October 2024 SQLite find. The control row is a human find: CVE-2026-87491, which headlines conflated with an AI exploit chain and which Google's release note credits to a person with a $2,500 reward.

Showing 69 of 69 entries

Overview
Checked at a recordCVE record, advisory or merged fix47of 69 entries · checked 19 September 2026
Strongest tierThe CVE record's own credits name the finder2010 more credited in the CNA's own advisory
Google Big SleepIdentified rows2618 at the record, 7 in Apple's and Google's advisories
Awaiting a CVE recordQuoted in public, 404 at the mirror9depthfirst's FFmpeg identifiers, re-queried 12 and 19 September
Aggregate totalsHeadline counts, their own tier10from XBOW's roughly 1,060 reports to CodeMender's 72 patches
Published bountyAmong identified rows1of 47, and it is the human control: $2,500 for CVE-2026-87491

Entries · by finder

  1. Google Big Sleep2637.7%
  2. depthfirst1014.5%
  3. Vulnhuntr1014.5%
  4. Other programmes and reports68.7%
  5. OpenAI Aardvark57.2%
  6. AISLE57.2%
  7. Google OSS-Fuzz-Gen22.9%
  8. XBOW22.9%
  9. OpenAI o3 (Sean Heelan)22.9%
  10. Human researcher (control)11.4%

Entries · by month

Dated by the record's datePublic where it carries one, else the advisory or write-up date; the last twelve months of 24 tracked.

Evidence tier · all entries

69entries
Credits array
2029.0%
CNA advisory
1014.5%
Outside claim
2029.0%
Awaiting record
913.0%
Aggregate total
1014.5%

Every entry · most recent first

  1. Google OSS-Fuzz-Gen reports 30 new bugs found by automatically generated fuzz targetsGoogle OSS-Fuzz-GenOSS-Fuzz projects (cJSON, libplist, hunspell, zstd, gdbm, pjsip, gpac, sqlite3, openssl and others)CONFIRMEDAggregate totalgoogle/oss-fuzz-gen README ↗
  2. Anthropic reports an autonomous exploit workflow yielding more than a dozen possible zero-days in a monthOther programmes and reportsnetwork appliances (unnamed)CONFIRMEDAggregate totalAnthropic, threat intelligence report, September 2026 ↗
  3. Chrome V8 out-of-bounds write exploited in the wild, found by a human researcher and paid $2,500 (the control row)CVE-2026-87491Human researcher (control)Google ChromeMediumCONFIRMEDCNA advisoryCVE record ↗Chrome Releases, Stable Channel Update, 8 September 2026 ↗
  4. WebKitGTK memory corruption in OpenTypeVerticalData, found by Google Big SleepCVE-2026-83596Google Big SleepWebKitGTK8.8 HighCONFIRMEDCredits arrayCVE record ↗
  5. Anthropic attributes 500 or more high-severity vulnerabilities that survived decades of scrutiny to Claude OpusOther programmes and reportsopen-source and partner codebases (unnamed)CONFIRMEDAggregate totalYFarmX, Claude Security now scans on Mythos 5 ↗
  6. Anthropic says Project Glasswing partners found more than 10,000 high- or critical-severity flawsOther programmes and reportsGlasswing partner codebases (about 200 organisations)CONFIRMEDAggregate totalYFarmX, Claude Security now scans on Mythos 5 ↗
  7. depthfirst reports 21 FFmpeg zero-days from a $1,000 scan of 1.5 million linesdepthfirstFFmpegCONFIRMEDAggregate totaldepthfirst, 21 zero-days in FFmpeg ↗
  8. FFmpeg heap overflow in the DASH demuxer, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39218depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  9. FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39217depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  10. FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39216depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  11. FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39215depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  12. FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39214depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  13. FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39213depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  14. FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39212depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  15. FFmpeg integer overflow in the swscale, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39211depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  16. FFmpeg heap overflow in the MPEG-TS demuxer, claimed by depthfirst under an identifier the CVE list does not yet serveCVE-2026-39210depthfirstFFmpegUNVERIFIEDAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
  17. Google CodeMender upstreamed 72 security fixes in its first six monthsOther programmes and reportsopen-source projects (unnamed), codebases up to 4.5 million linesSINGLEAggregate totalGoogle DeepMind, Introducing CodeMender ↗
  18. Gogs unauthenticated file upload, disclosed by OpenAI Security ResearchCVE-2026-25242OpenAI AardvarkGogs6.9 MediumCONFIRMEDCNA advisoryCVE record ↗GitHub advisory GHSA-fc3h-92p8-h36f ↗
  19. Gogs two-factor bypass via recovery code, disclosed by OpenAI Security ResearchCVE-2025-64175OpenAI AardvarkGogs7.7 HighCONFIRMEDCNA advisoryCVE record ↗GitHub advisory GHSA-p6x6-9mx6-26wj ↗
  20. AISLE claims more than 225 CVEs across OpenSSL, the Linux kernel, curl, Apache, Mozilla, Redis and ElasticAISLEOpenSSL, Linux kernel, curl, Apache, Mozilla, Redis, ElasticSINGLEAggregate totalOpenSSL security advisory, 27 January 2026 ↗
  21. OpenSSL invalid or NULL pointer dereference in PKCS#12 ASN1_TYPE validation, credited to Aisle ResearchCVE-2026-22795AISLEOpenSSLLowCONFIRMEDOutside claimCVE record ↗OpenSSL security advisory, 27 January 2026 ↗
  22. OpenSSL NULL pointer dereference in PKCS12_item_decrypt_d2i_ex(), credited to Aisle ResearchCVE-2025-69421AISLEOpenSSLLowCONFIRMEDOutside claimCVE record ↗OpenSSL security advisory, 27 January 2026 ↗
  23. OpenSSL stack overflow, invalid or NULL pointer in PKCS#12 PBMAC1 MAC verification, credited to Aisle ResearchCVE-2025-11187AISLEOpenSSLModerateCONFIRMEDOutside claimCVE record ↗OpenSSL security advisory, 27 January 2026 ↗
  24. OpenSSL stack buffer overflow, AEAD parameters in CMS (Auth)EnvelopedData parsing, credited to Aisle ResearchCVE-2025-15467AISLEOpenSSLHighCONFIRMEDOutside claimCVE record ↗OpenSSL security advisory, 27 January 2026 ↗
  25. Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCVE-2025-43434Google Big SleepSafariCONFIRMEDCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
  26. Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCVE-2025-43433Google Big SleepSafariCONFIRMEDCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
  27. Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCVE-2025-43431Google Big SleepSafariCONFIRMEDCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
  28. Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCVE-2025-43430Google Big SleepSafariCONFIRMEDCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
  29. Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCVE-2025-43429Google Big SleepSafariCONFIRMEDCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
  30. libxslt type confusion in exsltFuncResultComp, found by Google Big SleepCVE-2025-11731Google Big Sleeplibxslt3.1 LowCONFIRMEDCredits arrayCVE record ↗
  31. curl merged about 50 fixes from Joshua Rogers' AI-assisted scanner runOther programmes and reportscurlSINGLEAggregate totalDaniel Stenberg's blog ↗
  32. curl out-of-bounds read in cookie path handling, found by Google Big SleepCVE-2025-9086Google Big SleepcurlCONFIRMEDCredits arrayCVE record ↗
  33. Chrome ANGLE use-after-free, critical, reported by Google Big SleepCVE-2025-9478Google Big SleepGoogle ChromeCriticalCONFIRMEDCNA advisoryCVE record ↗Chrome Releases, Stable Channel Update, 26 August 2025 ↗
  34. FFmpeg SANM process_ftch: use-after-free write, found by Google Big SleepCVE-2025-59734Google Big SleepFFmpeg8.7 HighCONFIRMEDCredits arrayCVE record ↗
  35. Chrome V8 out-of-bounds write, reported by Google Big SleepCVE-2025-9132Google Big SleepGoogle ChromeCONFIRMEDCNA advisoryCVE record ↗Chrome Releases, Stable Channel Update, 19 August 2025 ↗
  36. AIxCC finalists surfaced 18 previously unknown real-world flaws and patched 11 of themOther programmes and reportsAIxCC challenge projects (open-source)SINGLEAggregate totalTeam Atlanta, Atlantis CRS repository ↗
  37. FFmpeg EXR dwa_uncompress: mixed channel pixel types, found by Google Big SleepCVE-2025-59733Google Big SleepFFmpeg8.7 HighCONFIRMEDCredits arrayCVE record ↗
  38. FFmpeg EXR dwa_uncompress: dimensions not divisible by 8, found by Google Big SleepCVE-2025-59732Google Big SleepFFmpeg8.7 HighCONFIRMEDCredits arrayCVE record ↗
  39. FFmpeg EXR dwa_uncompress: RLE raw length unchecked, found by Google Big SleepCVE-2025-59731Google Big SleepFFmpeg6.9 MediumCONFIRMEDCredits arrayCVE record ↗
  40. FFmpeg SANM old_codec48: heap overflow write, found by Google Big SleepCVE-2025-59730Google Big SleepFFmpeg5.7 MediumCONFIRMEDCredits arrayCVE record ↗
  41. QuickJS js_bigint_from_string: integer overflow, found by Google Big SleepCVE-2025-62496Google Big SleepQuickJS7.1 HighCONFIRMEDCredits arrayCVE record ↗
  42. QuickJS libregexp: bytecode size integer overflow, found by Google Big SleepCVE-2025-62495Google Big SleepQuickJS7.1 HighCONFIRMEDCredits arrayCVE record ↗
  43. QuickJS string addition: type confusion, found by Google Big SleepCVE-2025-62494Google Big SleepQuickJS7.1 HighCONFIRMEDCredits arrayCVE record ↗
  44. QuickJS js_bigint_to_string1: out-of-bounds read, found by Google Big SleepCVE-2025-62493Google Big SleepQuickJS5.9 MediumCONFIRMEDCredits arrayCVE record ↗
  45. QuickJS js_typed_array_indexOf: out-of-bounds read via float precision, found by Google Big SleepCVE-2025-62492Google Big SleepQuickJS5.9 MediumCONFIRMEDCredits arrayCVE record ↗
  46. QuickJS js_std_promise_rejection_check: use-after-free, found by Google Big SleepCVE-2025-62491Google Big SleepQuickJS8.8 HighCONFIRMEDCredits arrayCVE record ↗
  47. QuickJS js_print_object: use-after-free, found by Google Big SleepCVE-2025-62490Google Big SleepQuickJS8.8 HighCONFIRMEDCredits arrayCVE record ↗
  48. FFmpeg DHAV get_duration: heap overflow read, found by Google Big SleepCVE-2025-59729Google Big SleepFFmpeg5.7 MediumCONFIRMEDCredits arrayCVE record ↗
  49. FFmpeg MPEG-DASH resolve_content_path: heap overflow write, found by Google Big SleepCVE-2025-59728Google Big SleepFFmpeg8.7 HighCONFIRMEDCredits arrayCVE record ↗
  50. GnuTLS heap buffer overflow in certtool, attributed to OpenAI AardvarkCVE-2025-32990OpenAI AardvarkGnuTLS6.5 MediumCONFIRMEDOutside claimCVE record ↗OpenAI, Introducing Aardvark ↗
  51. GnuTLS heap buffer overread in SCT extension parsing, attributed to OpenAI AardvarkCVE-2025-32989OpenAI AardvarkGnuTLS5.3 MediumCONFIRMEDOutside claimCVE record ↗OpenAI, Introducing Aardvark ↗
  52. GnuTLS double free in otherName SAN export, attributed to OpenAI AardvarkCVE-2025-32988OpenAI AardvarkGnuTLS6.5 MediumCONFIRMEDOutside claimCVE record ↗OpenAI, Introducing Aardvark ↗
  53. SQLite integer truncation found with Google Big Sleep, cut off before exploitationCVE-2025-6965Google Big SleepSQLite7.2 HighCONFIRMEDCredits arrayCVE record ↗Google Cloud CISO Perspectives on Big Sleep ↗
  54. XBOW submitted close to 1,060 reports to HackerOne programmes and topped the US leaderboardXBOWHackerOne programmes (various)CONFIRMEDAggregate totalXBOW, how XBOW ranked number one ↗
  55. Linux ksmbd use-after-free in session logoff, found with OpenAI o3 by Sean HeelanCVE-2025-37899OpenAI o3 (Sean Heelan)Linux kernel8.8 HighCONFIRMEDOutside claimCVE record ↗Sean Heelan, how I used o3 to find CVE-2025-37899 ↗
  56. PAN-OS GlobalProtect reflected cross-site scripting, found by XBOWCVE-2025-0133XBOWPalo Alto Networks PAN-OS2.7 LowCONFIRMEDCredits arrayCVE record ↗Palo Alto Networks security advisory ↗
  57. Linux ksmbd dangling pointer in krb_authenticate, the benchmark bug Sean Heelan ran o3 againstCVE-2025-37778OpenAI o3 (Sean Heelan)Linux kernel9.8 CriticalCONFIRMEDOutside claimCVE record ↗Sean Heelan, how I used o3 to find CVE-2025-37899 ↗
  58. LLaVA server-side request forgery at POST /worker_generate_stream, found by VulnhuntrCVE-2024-9309Vulnhuntrhaotian-liu/LLaVA9.3 CriticalCONFIRMEDOutside claimCVE record ↗Vulnhuntr README ↗
  59. FastChat server-side request forgery at POST /worker_generate_stream, found by VulnhuntrCVE-2024-10044Vulnhuntrlm-sys/FastChat9.3 CriticalCONFIRMEDOutside claimCVE record ↗Vulnhuntr README ↗
  60. SQLite stack buffer underflow in seriesBestIndex, the first public Big Sleep find, fixed before releaseGoogle Big SleepSQLiteCONFIRMEDOutside claimGoogle Project Zero, From Naptime to Big Sleep ↗
  61. ragflow remote code execution in add_llm via llm_factory, found by VulnhuntrCVE-2024-10131Vulnhuntrinfiniflow/ragflow8.8 HighCONFIRMEDOutside claimCVE record ↗Vulnhuntr README ↗
  62. Langflow insecure direct object reference, found by Vulnhuntr, identifier redactedVulnhuntrLangflowCONFIRMEDOutside claimVulnhuntr README ↗
  63. Langflow remote code execution, found by Vulnhuntr, identifier redactedVulnhuntrLangflowCONFIRMEDOutside claimVulnhuntr README ↗
  64. letta arbitrary file overwrite, found by Vulnhuntr and fixed as a pull requestVulnhuntrletta-ai/lettaCONFIRMEDOutside claimThe merged fix ↗Vulnhuntr README ↗
  65. gpt-researcher arbitrary file overwrite, found by Vulnhuntr and fixed as a pull requestVulnhuntrassafelovic/gpt-researcherCONFIRMEDOutside claimThe merged fix ↗Vulnhuntr README ↗
  66. ComfyUI stored cross-site scripting via /api/upload/image, found by VulnhuntrCVE-2024-10099Vulnhuntrcomfyanonymous/ComfyUI6.1 MediumCONFIRMEDOutside claimCVE record ↗Vulnhuntr README ↗
  67. gpt_academic stored cross-site scripting at /file, found by VulnhuntrCVE-2024-10101Vulnhuntrbinary-husky/gpt_academic5.4 MediumCONFIRMEDOutside claimCVE record ↗Vulnhuntr README ↗
  68. gpt_academic path traversal via URL-encoded file parameter, found by VulnhuntrCVE-2024-10100Vulnhuntrbinary-husky/gpt_academic6.5 MediumCONFIRMEDOutside claimCVE record ↗Vulnhuntr README ↗
  69. OpenSSL out-of-bounds memory access from invalid GF(2^m) parameters, found by a Google OSS-Fuzz-Gen harnessCVE-2024-9143Google OSS-Fuzz-GenOpenSSLLowCONFIRMEDCredits arrayCVE record ↗google/oss-fuzz-gen README ↗

Each row opens the entry's own record page, with the credit as recorded and the sources; the small link under it opens the primary record. Download the data: CSV ·JSON ·RSS · CC BY 4.0 with attribution to YFarmX.

Severity is the record's own CVSS or the CNA's rating. A claim is reported as a claim, with the tier it rests on.Last checked · 19 Sept 2026