Vulnerabilities in aws

110 results
Vexday analysis

A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.

CVE-2025-13524MEDIUMImproper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call pEPSS 0.2%CVE-2026-7425MEDIUMOut-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCPEPSS 0.2%CVE-2026-7424HIGHInteger Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCPEPSS 0.2%CVE-2026-7423MEDIUMInteger Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCPEPSS 0.2%CVE-2026-15643CRITICALAWS HealthLake MCP Server SSRF via Pagination URLEPSS 0.2%CVE-2026-15737MEDIUMSensitive content disclosure via OpenTelemetry spans in AgentCore Python SDKEPSS 0.2%CVE-2025-11462CRITICALLocal Privilege Escalation Vulnerability in AWS Client VPN macOS ClientEPSS 0.2%CVE-2026-22611LOWAWS SDK for .NET V4 adopted defense in depth enhancement for region parameter valueEPSS 0.2%CVE-2026-5747HIGHOut-of-bounds Write in Firecracker virtio-pci TransportEPSS 0.2%CVE-2026-4295HIGHArbitrary code execution via crafted project files in Kiro IDEEPSS 0.2%CVE-2025-14762MEDIUMMissing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK thatEPSS 0.2%CVE-2026-1386MEDIUMArbitrary Host File Overwrite via Symlink in Firecracker JailerEPSS 0.2%CVE-2025-14761MEDIUMMissing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to introduce a new EDK that EPSS 0.2%CVE-2026-16317HIGHSilent Drop of TLS 1.3 Encrypted Records in s2n-tlsEPSS 0.2%CVE-2026-7422HIGHMAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet ProcessingEPSS 0.2%CVE-2025-8069HIGHLocal Privilege Escalation Vulnerability in AWS Client VPN Windows ClientEPSS 0.2%CVE-2026-5429HIGHKiro IDE Webview Cross-Site Scripting via Workspace Color ThemeEPSS 0.2%CVE-2025-14760MEDIUMMissing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to introduce a new EDK that EPSS 0.1%CVE-2026-18953MEDIUMImproper limitation of a pathname to a restricted directory in aws-transform-mcp-serverEPSS 0.1%CVE-2026-4270MEDIUMAWS API MCP File Access Restriction BypassEPSS 0.1%