Vulnerabilities in aws

141 results
Vexday analysis

A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.

CVE-2026-11400HIGHPrivilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQLEPSS 0.3%CVE-2026-6967HIGHMissing Delegated Metadata Validation in awslabs/toughEPSS 0.3%CVE-2026-18654MEDIUMDisabled SSH host key verification in Amazon AWS CLI EMR helper commandsEPSS 0.3%CVE-2025-12815MEDIUMAn ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.EPSS 0.3%CVE-2026-10740MEDIUMExcessive memory allocation in s2n-quicEPSS 0.3%CVE-2026-7422HIGHMAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet ProcessingEPSS 0.3%CVE-2025-2598MEDIUMAWS CDK CLI prints AWS credentials retrieved by custom credential pluginsEPSS 0.3%CVE-2026-18061MEDIUMImproper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePluginEPSS 0.3%CVE-2025-0508MEDIUMMD5 Hash Collision in SageMaker Workflow in aws/sagemaker-python-sdkEPSS 0.3%CVE-2026-4428CRITICALCRL Distribution Point Scope Check Logic Error in AWS-LCEPSS 0.3%CVE-2026-1778HIGHTLS disabled by default in select aws/sagemaker-python-sdk configurationsEPSS 0.3%CVE-2026-16317HIGHSilent Drop of TLS 1.3 Encrypted Records in s2n-tlsEPSS 0.2%CVE-2025-13524MEDIUMImproper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call pEPSS 0.2%CVE-2026-22611LOWAWS SDK for .NET V4 adopted defense in depth enhancement for region parameter valueEPSS 0.2%CVE-2026-89066HIGHOS command injection in the task synthesis component in projenEPSS 0.2%CVE-2026-5429HIGHKiro IDE Webview Cross-Site Scripting via Workspace Color ThemeEPSS 0.2%CVE-2026-16584HIGHAWS API MCP Server Security Policy Bypass via Startup FailureEPSS 0.2%CVE-2026-1386MEDIUMArbitrary Host File Overwrite via Symlink in Firecracker JailerEPSS 0.2%CVE-2025-11462CRITICALLocal Privilege Escalation Vulnerability in AWS Client VPN macOS ClientEPSS 0.2%CVE-2025-14761MEDIUMMissing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to introduce a new EDK that EPSS 0.2%