Vulnerabilidades en AWS

140 resultados
Análisis Vexday

Com 69 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil do AWS situa-se abaixo da média geral do catálogo nesse indicador, o que representa um panorama relativamente controlado em termos de ameaças imediatas. No entanto, 33 vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige acompanhamento contínuo. O tipo de falha mais recorrente é CWE-327 (uso de algoritmo criptográfico quebrado ou arriscado), padrão que tende a impactar a confidencialidade e integridade de dados em escala. A CVE mais relevante no momento, CVE-2025-0851, apresenta score EPSS de 0,23, e embora existam 3 CVEs com prova de conceito pública e 5 de severidade crítica, nenhuma delas atingiu exploração confirmada até o momento — condição que pode mudar rapidamente diante da disponibilidade de PoCs.

CVE-2025-14503HIGHOverly Permissive Trust Policy in Harmonix on AWS EKSEPSS 0.5%CVE-2026-75897HIGHUncontrolled Resource Consumption in Capabilities Route in OpenSearch DashboardsEPSS 0.5%CVE-2026-1777HIGHCleartext transmission of sensitive materials in aws/sagemaker-python-sdkEPSS 0.5%CVE-2022-23511HIGHA privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2EPSS 0.5%CVE-2026-86831HIGHImproper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKSEPSS 0.5%CVE-2025-12967HIGHAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticateEPSS 0.5%CVE-2026-7191HIGHArbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWSEPSS 0.4%CVE-2026-18140HIGHUncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated serversEPSS 0.4%CVE-2026-19311HIGHMissing Authorization in Execute Monitor API in OpenSearch Alerting PluginEPSS 0.4%CVE-2024-34072HIGHDeserialization of Untrusted Data in sagemaker-python-sdkEPSS 0.4%CVE-2026-15643CRITICALAWS HealthLake MCP Server SSRF via Pagination URLEPSS 0.4%CVE-2026-15737MEDIUMSensitive content disclosure via OpenTelemetry spans in AgentCore Python SDKEPSS 0.4%CVE-2026-86830HIGHIncorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity CenterEPSS 0.4%CVE-2026-9291HIGHInsecure Deserialization in Amazon Braket SDK Job Results ProcessingEPSS 0.4%CVE-2026-83551HIGHCleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline pathEPSS 0.4%CVE-2026-18952HIGHMissing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics PluginEPSS 0.4%CVE-2026-5190HIGHAWS C Event Stream Streaming Decoder Stack Buffer OverflowEPSS 0.4%CVE-2023-51651MEDIUMPotential URI resolution path traversal in the AWS SDK for PHPEPSS 0.4%CVE-2026-77811MEDIUMStored Cross-Site Scripting via Integration Template Asset in OpenSearch DashboardsEPSS 0.4%CVE-2026-75910HIGHIncorrect privilege assignment in the Amazon aws-athena-query-federation ClickHouse connector deployment templateEPSS 0.4%