Vulnerabilities in amazon

55 results
Vexday analysis

A Amazon tem 5 vulnerabilidades catalogadas na base Vexday, nenhuma delas sob ataque ativo ou com severidade crítica. A fraqueza dominante é CWE-863 (controle de acesso impróprio), indicando exposição potencial a escalação de privilégios; porém, a ausência de atualizações recentes sugere que o panorama atual é estável e sem pressão temporal imediata.

CVE-2019-3984—Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitiEPSS 3.8%CVE-2018-1169—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User intEPSS 2.5%CVE-2026-5485HIGHOS command injection in Amazon Athena ODBC driver on LinuxEPSS 1.1%CVE-2026-85656HIGHOS command injection in Amazon log4j-cve-2021-44228-hotpatchEPSS 1.1%CVE-2026-83497HIGHUnrestricted Java Deserialization in OpenSearch SQL Plugin Cursor PaginationEPSS 1.0%CVE-2025-4318CRITICALInput validation issue in AWS Amplify Studio UI component propertiesEPSS 0.9%CVE-2026-81849HIGHPath traversal in the aws:downloadContent plugin in amazon-ssm-agentEPSS 0.9%CVE-2026-6437MEDIUMAWS EFS CSI Driver Mount Option InjectionEPSS 0.7%CVE-2026-35561CRITICALInsufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driverEPSS 0.7%CVE-2026-8178CRITICALRemote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC DriverEPSS 0.7%CVE-2026-35562HIGHAllocation of resources without limits in parsing components in Amazon Athena ODBC driverEPSS 0.7%CVE-2026-15738MEDIUMCross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer ControllerEPSS 0.6%CVE-2025-3857HIGHInfinite loop condition in Amazon.IonDotnetEPSS 0.6%CVE-2026-84851HIGHUncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6EPSS 0.6%CVE-2024-12744HIGHSQL Injection in the Amazon Redshift JDBC Driver affecting v2.1.0.31EPSS 0.6%CVE-2026-85786HIGHIncomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-javaEPSS 0.6%CVE-2026-78379CRITICALConsent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents ToolsEPSS 0.6%CVE-2026-85228HIGHInteger overflow in tensor buffer validation in Deep Java LibraryEPSS 0.5%CVE-2024-12745HIGHSQL Injection in the Amazon Redshift Python Connector affecting v2.1.4EPSS 0.5%CVE-2026-16318MEDIUMQUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tlsEPSS 0.5%