Vulnerabilities in aws

110 results
Vexday analysis

A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.

CVE-2026-5190HIGHAWS C Event Stream Streaming Decoder Stack Buffer OverflowEPSS 0.4%CVE-2023-51651MEDIUMPotential URI resolution path traversal in the AWS SDK for PHPEPSS 0.4%CVE-2026-19111HIGHInsecure direct object reference in Strands Agents Tools memory tool namespace isolationEPSS 0.4%CVE-2025-0693MEDIUMIssue with AWS Sign-in IAM User Login Flow - Possible Username EnumerationEPSS 0.4%CVE-2026-12043HIGHHeap double-free in AWS Common Runtime aws-c-httpEPSS 0.4%CVE-2026-9133HIGHArbitrary file read in rabbitmq-aws pluginEPSS 0.3%CVE-2026-16796HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.3%CVE-2026-14471HIGHAuthenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registryEPSS 0.3%CVE-2025-1969MEDIUMRequest approval spoofing in Temporary Elevated Access Management (TEAM) for AWS IAM Identity CenterEPSS 0.3%CVE-2026-11393HIGHCode injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent importEPSS 0.3%CVE-2026-18733HIGHPrompt injection bypasses shell tool consent gate in Strands Agents ToolsEPSS 0.3%CVE-2025-23206LOWIAM OIDC custom resource allows connection to unauthorized OIDC provider in aws-cdkEPSS 0.3%CVE-2025-11618MEDIUMInvalid Pointer Dereference when receiving UDP/IPv6 packets in FreeRTOS-Plus-TCPEPSS 0.3%CVE-2024-45037MEDIUMAWS CDK RestApi not generating authorizationScope correctly in resultant CFN templateEPSS 0.3%CVE-2025-2888MEDIUMImproper timestamp caching during snapshot rollback in toughEPSS 0.3%CVE-2025-2887MEDIUMFailure to detect delegated target rollback in toughEPSS 0.3%CVE-2025-2886MEDIUMTerminating targets role delegations are not respected in toughEPSS 0.3%CVE-2025-2885MEDIUMRoot metadata version not validated in toughEPSS 0.3%CVE-2026-11400HIGHPrivilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQLEPSS 0.3%CVE-2026-11401HIGHPrivilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQLEPSS 0.3%