AI-Found Vulnerabilities
47 vulnerabilities found by AI tools, each one checked at its official CVE record or vendor advisory
Real vulnerabilities that an AI tool found, from Google Big Sleep and XBOW to OpenAI's Aardvark and the open-source Vulnhuntr, compiled by YFarmX from the public CVE Program records and the vendors' own advisories. Each row shows how strong the evidence is, from a CVE record whose own credits name the AI tool down to a claim that rests on the finder's own write-up, and links straight to the record.
How this register is kept
what the number is, where it comes from, and how each row is checked
What the number is. 47 vulnerabilities on this register carry an identifier we checked at a primary record, a CVE record, a GitHub advisory or the merged fix, and are credited to an AI finder: 20 where the CVE record's own credits name the finder, 10 where the assigning CNA credits it in its own advisory, and 17 where the credit rests on the finder's or a researcher's publication against a record whose credits are empty or name people. Every row was checked against the CVE Program's cvelistV5 mirror on 12 and 19 September 2026.
Where it comes from. The CVE Program publishes every record for free public use under its terms of use. The register reads each record from the CVEProject/cvelistV5 mirror and takes the credit from the record's own credits field, then from the vendor's release note or advisory where the CNA files credit there, then from the finder's own publication. Each row links its record and the source that credits the AI, and its own page carries the credit verbatim.
The five tiers, strongest first. Credits array: the CVE record's own credits field names the finder, as CVE-2025-0133 does with XBOW and CVE-2024-9143 with Google OSS-Fuzz-Gen. CNA advisory: the assigning CNA credits the finder in its own release note or security page, which is how Apple and Chrome file credit. Outside claim: the finder or a researcher claims the row and the record's credits are empty or name people, which is where every Vulnhuntr, Aardvark and AISLE row sits. Awaiting record: an identifier quoted in public that the CVE Program's list will serve once the record publishes; the 9 rows here are depthfirst's FFmpeg identifiers, which answered 404 at the mirror on 12 and 19 September 2026. Aggregate total: a published headline count, such as XBOW's roughly 1,060 HackerOne reports; the 10 rows here are kept as their own tier because a total is a claim about a count rather than a record.
Reproduce a row. The weekly refresh is one command per row, run against the CVE Program's own mirror, reading the credits array rather than any announcement:
curl -sS "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/22xxx/CVE-2026-22795.json" \
| python3 -c "import json,sys; d=json.load(sys.stdin)['containers']['cna']; print(d.get('credits'))"The largest block is Google Big Sleep, 26 identified rows, with its origin in the October 2024 SQLite find. The control row is a human find: CVE-2026-87491, which headlines conflated with an AI exploit chain and which Google's release note credits to a person with a $2,500 reward.
Showing 69 of 69 entries
Overview
Entries · by finder
Entries · by month
Dated by the record's datePublic where it carries one, else the advisory or write-up date; the last twelve months of 24 tracked.
Evidence tier · all entries
- Credits array
- 2029.0%
- CNA advisory
- 1014.5%
- Outside claim
- 2029.0%
- Awaiting record
- 913.0%
- Aggregate total
- 1014.5%
Every entry · most recent first
- Google OSS-Fuzz-Gen reports 30 new bugs found by automatically generated fuzz targetsAggregate totalgoogle/oss-fuzz-gen README ↗
- Anthropic reports an autonomous exploit workflow yielding more than a dozen possible zero-days in a monthAggregate totalAnthropic, threat intelligence report, September 2026 ↗
- Chrome V8 out-of-bounds write exploited in the wild, found by a human researcher and paid $2,500 (the control row)CNA advisoryCVE record ↗Chrome Releases, Stable Channel Update, 8 September 2026 ↗
- WebKitGTK memory corruption in OpenTypeVerticalData, found by Google Big SleepCredits arrayCVE record ↗
- Anthropic attributes 500 or more high-severity vulnerabilities that survived decades of scrutiny to Claude OpusAggregate totalYFarmX, Claude Security now scans on Mythos 5 ↗
- Anthropic says Project Glasswing partners found more than 10,000 high- or critical-severity flawsAggregate totalYFarmX, Claude Security now scans on Mythos 5 ↗
- depthfirst reports 21 FFmpeg zero-days from a $1,000 scan of 1.5 million linesAggregate totaldepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg heap overflow in the DASH demuxer, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg integer overflow in the swscale, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- FFmpeg heap overflow in the MPEG-TS demuxer, claimed by depthfirst under an identifier the CVE list does not yet serveAwaiting recorddepthfirst, 21 zero-days in FFmpeg ↗
- Google CodeMender upstreamed 72 security fixes in its first six monthsAggregate totalGoogle DeepMind, Introducing CodeMender ↗
- Gogs unauthenticated file upload, disclosed by OpenAI Security ResearchCNA advisoryCVE record ↗GitHub advisory GHSA-fc3h-92p8-h36f ↗
- Gogs two-factor bypass via recovery code, disclosed by OpenAI Security ResearchCNA advisoryCVE record ↗GitHub advisory GHSA-p6x6-9mx6-26wj ↗
- AISLE claims more than 225 CVEs across OpenSSL, the Linux kernel, curl, Apache, Mozilla, Redis and ElasticAggregate totalOpenSSL security advisory, 27 January 2026 ↗
- OpenSSL invalid or NULL pointer dereference in PKCS#12 ASN1_TYPE validation, credited to Aisle ResearchOutside claimCVE record ↗OpenSSL security advisory, 27 January 2026 ↗
- OpenSSL NULL pointer dereference in PKCS12_item_decrypt_d2i_ex(), credited to Aisle ResearchOutside claimCVE record ↗OpenSSL security advisory, 27 January 2026 ↗
- OpenSSL stack overflow, invalid or NULL pointer in PKCS#12 PBMAC1 MAC verification, credited to Aisle ResearchOutside claimCVE record ↗OpenSSL security advisory, 27 January 2026 ↗
- OpenSSL stack buffer overflow, AEAD parameters in CMS (Auth)EnvelopedData parsing, credited to Aisle ResearchOutside claimCVE record ↗OpenSSL security advisory, 27 January 2026 ↗
- Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
- Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
- Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
- Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
- Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by AppleCNA advisoryCVE record ↗Apple, About the security content of Safari 26.1 ↗
- libxslt type confusion in exsltFuncResultComp, found by Google Big SleepCredits arrayCVE record ↗
- curl merged about 50 fixes from Joshua Rogers' AI-assisted scanner runAggregate totalDaniel Stenberg's blog ↗
- curl out-of-bounds read in cookie path handling, found by Google Big SleepCredits arrayCVE record ↗
- Chrome ANGLE use-after-free, critical, reported by Google Big SleepCNA advisoryCVE record ↗Chrome Releases, Stable Channel Update, 26 August 2025 ↗
- FFmpeg SANM process_ftch: use-after-free write, found by Google Big SleepCredits arrayCVE record ↗
- Chrome V8 out-of-bounds write, reported by Google Big SleepCNA advisoryCVE record ↗Chrome Releases, Stable Channel Update, 19 August 2025 ↗
- AIxCC finalists surfaced 18 previously unknown real-world flaws and patched 11 of themAggregate totalTeam Atlanta, Atlantis CRS repository ↗
- FFmpeg EXR dwa_uncompress: mixed channel pixel types, found by Google Big SleepCredits arrayCVE record ↗
- FFmpeg EXR dwa_uncompress: dimensions not divisible by 8, found by Google Big SleepCredits arrayCVE record ↗
- FFmpeg EXR dwa_uncompress: RLE raw length unchecked, found by Google Big SleepCredits arrayCVE record ↗
- FFmpeg SANM old_codec48: heap overflow write, found by Google Big SleepCredits arrayCVE record ↗
- QuickJS js_bigint_from_string: integer overflow, found by Google Big SleepCredits arrayCVE record ↗
- QuickJS libregexp: bytecode size integer overflow, found by Google Big SleepCredits arrayCVE record ↗
- QuickJS string addition: type confusion, found by Google Big SleepCredits arrayCVE record ↗
- QuickJS js_bigint_to_string1: out-of-bounds read, found by Google Big SleepCredits arrayCVE record ↗
- QuickJS js_typed_array_indexOf: out-of-bounds read via float precision, found by Google Big SleepCredits arrayCVE record ↗
- QuickJS js_std_promise_rejection_check: use-after-free, found by Google Big SleepCredits arrayCVE record ↗
- QuickJS js_print_object: use-after-free, found by Google Big SleepCredits arrayCVE record ↗
- FFmpeg DHAV get_duration: heap overflow read, found by Google Big SleepCredits arrayCVE record ↗
- FFmpeg MPEG-DASH resolve_content_path: heap overflow write, found by Google Big SleepCredits arrayCVE record ↗
- GnuTLS heap buffer overflow in certtool, attributed to OpenAI AardvarkOutside claimCVE record ↗OpenAI, Introducing Aardvark ↗
- GnuTLS heap buffer overread in SCT extension parsing, attributed to OpenAI AardvarkOutside claimCVE record ↗OpenAI, Introducing Aardvark ↗
- GnuTLS double free in otherName SAN export, attributed to OpenAI AardvarkOutside claimCVE record ↗OpenAI, Introducing Aardvark ↗
- SQLite integer truncation found with Google Big Sleep, cut off before exploitationCredits arrayCVE record ↗Google Cloud CISO Perspectives on Big Sleep ↗
- XBOW submitted close to 1,060 reports to HackerOne programmes and topped the US leaderboardAggregate totalXBOW, how XBOW ranked number one ↗
- Linux ksmbd use-after-free in session logoff, found with OpenAI o3 by Sean HeelanOutside claimCVE record ↗Sean Heelan, how I used o3 to find CVE-2025-37899 ↗
- PAN-OS GlobalProtect reflected cross-site scripting, found by XBOWCredits arrayCVE record ↗Palo Alto Networks security advisory ↗
- Linux ksmbd dangling pointer in krb_authenticate, the benchmark bug Sean Heelan ran o3 againstOutside claimCVE record ↗Sean Heelan, how I used o3 to find CVE-2025-37899 ↗
- LLaVA server-side request forgery at POST /worker_generate_stream, found by VulnhuntrOutside claimCVE record ↗Vulnhuntr README ↗
- FastChat server-side request forgery at POST /worker_generate_stream, found by VulnhuntrOutside claimCVE record ↗Vulnhuntr README ↗
- SQLite stack buffer underflow in seriesBestIndex, the first public Big Sleep find, fixed before releaseOutside claimGoogle Project Zero, From Naptime to Big Sleep ↗
- ragflow remote code execution in add_llm via llm_factory, found by VulnhuntrOutside claimCVE record ↗Vulnhuntr README ↗
- Langflow insecure direct object reference, found by Vulnhuntr, identifier redactedOutside claimVulnhuntr README ↗
- Langflow remote code execution, found by Vulnhuntr, identifier redactedOutside claimVulnhuntr README ↗
- letta arbitrary file overwrite, found by Vulnhuntr and fixed as a pull requestOutside claimThe merged fix ↗Vulnhuntr README ↗
- gpt-researcher arbitrary file overwrite, found by Vulnhuntr and fixed as a pull requestOutside claimThe merged fix ↗Vulnhuntr README ↗
- ComfyUI stored cross-site scripting via /api/upload/image, found by VulnhuntrOutside claimCVE record ↗Vulnhuntr README ↗
- gpt_academic stored cross-site scripting at /file, found by VulnhuntrOutside claimCVE record ↗Vulnhuntr README ↗
- gpt_academic path traversal via URL-encoded file parameter, found by VulnhuntrOutside claimCVE record ↗Vulnhuntr README ↗
- OpenSSL out-of-bounds memory access from invalid GF(2^m) parameters, found by a Google OSS-Fuzz-Gen harnessCredits arrayCVE record ↗google/oss-fuzz-gen README ↗
No entries match those filters.
Each row opens the entry's own record page, with the credit as recorded and the sources; the small link under it opens the primary record. Download the data: CSV ·JSON ·RSS · CC BY 4.0 with attribution to YFarmX.
Severity is the record's own CVSS or the CNA's rating. A claim is reported as a claim, with the tier it rests on.Last checked · 19 Sept 2026
