Vulnerabilities in aws

141 results
Vexday analysis

A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.

CVE-2025-3047MEDIUMPath Traversal in AWS SAM CLI allows file copy to build containerEPSS 0.8%CVE-2026-15957HIGHUncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapesEPSS 0.8%CVE-2026-16756HIGHAllocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of serviceEPSS 0.8%CVE-2026-5708HIGHImproper Control of User-Modifiable Attributes in RES CreateSession APIEPSS 0.7%CVE-2026-7191HIGHArbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWSEPSS 0.7%CVE-2026-14265HIGHRCE via Deserialization in AWS Advanced JDBC WrapperEPSS 0.7%CVE-2026-16796HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.7%CVE-2026-75897HIGHUncontrolled Resource Consumption in Capabilities Route in OpenSearch DashboardsEPSS 0.7%CVE-2022-24709HIGHCross site scripting in @awsui/components-reactEPSS 0.7%CVE-2026-86830HIGHIncorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity CenterEPSS 0.7%CVE-2026-13763HIGHHTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAFEPSS 0.7%CVE-2026-18420HIGHRCE via Prototype Pollution in OpenSearch DashboardsEPSS 0.7%CVE-2026-89049HIGHServer-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager AgentEPSS 0.7%CVE-2026-10591HIGHKiro IDE Insufficient File Write Restrictions to Execution-Sensitive PathsEPSS 0.7%CVE-2026-96883HIGHType confusion in AWS pgcollection allows remote code executionEPSS 0.7%CVE-2026-9291HIGHInsecure Deserialization in Amazon Braket SDK Job Results ProcessingEPSS 0.6%CVE-2025-3048MEDIUMPath Traversal in AWS SAM CLI allows file copy to local cacheEPSS 0.6%CVE-2026-6968HIGHMultiple Path Traversal Variants in awslabs/toughEPSS 0.6%CVE-2026-86831HIGHImproper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKSEPSS 0.6%CVE-2026-77810CRITICALCode Injection via Gremlin Query Passthrough in Amazon Athena Neptune ConnectorEPSS 0.6%