Vulnerabilidades en AWS

140 resultados
Análisis Vexday

Com 69 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil do AWS situa-se abaixo da média geral do catálogo nesse indicador, o que representa um panorama relativamente controlado em termos de ameaças imediatas. No entanto, 33 vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige acompanhamento contínuo. O tipo de falha mais recorrente é CWE-327 (uso de algoritmo criptográfico quebrado ou arriscado), padrão que tende a impactar a confidencialidade e integridade de dados em escala. A CVE mais relevante no momento, CVE-2025-0851, apresenta score EPSS de 0,23, e embora existam 3 CVEs com prova de conceito pública e 5 de severidade crítica, nenhuma delas atingiu exploração confirmada até o momento — condição que pode mudar rapidamente diante da disponibilidade de PoCs.

CVE-2026-75910HIGHIncorrect privilege assignment in the Amazon aws-athena-query-federation ClickHouse connector deployment templateEPSS 0.4%CVE-2025-0693MEDIUMIssue with AWS Sign-in IAM User Login Flow - Possible Username EnumerationEPSS 0.4%CVE-2026-89049HIGHServer-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager AgentEPSS 0.4%CVE-2026-15415MEDIUMPath traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-serverEPSS 0.4%CVE-2026-12043HIGHHeap double-free in AWS Common Runtime aws-c-httpEPSS 0.4%CVE-2026-77810CRITICALCode Injection via Gremlin Query Passthrough in Amazon Athena Neptune ConnectorEPSS 0.3%CVE-2026-12530HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.3%CVE-2026-11393HIGHCode injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent importEPSS 0.3%CVE-2026-19643MEDIUMOut-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platformsEPSS 0.3%CVE-2025-11618MEDIUMInvalid Pointer Dereference when receiving UDP/IPv6 packets in FreeRTOS-Plus-TCPEPSS 0.3%CVE-2026-84942MEDIUMStored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch DashboardsEPSS 0.3%CVE-2025-23206LOWIAM OIDC custom resource allows connection to unauthorized OIDC provider in aws-cdkEPSS 0.3%CVE-2025-1969MEDIUMRequest approval spoofing in Temporary Elevated Access Management (TEAM) for AWS IAM Identity CenterEPSS 0.3%CVE-2026-18733HIGHPrompt injection bypasses shell tool consent gate in Strands Agents ToolsEPSS 0.3%CVE-2025-2886MEDIUMTerminating targets role delegations are not respected in toughEPSS 0.3%CVE-2025-2885MEDIUMRoot metadata version not validated in toughEPSS 0.3%CVE-2025-2888MEDIUMImproper timestamp caching during snapshot rollback in toughEPSS 0.3%CVE-2025-2887MEDIUMFailure to detect delegated target rollback in toughEPSS 0.3%CVE-2024-45037MEDIUMAWS CDK RestApi not generating authorizationScope correctly in resultant CFN templateEPSS 0.3%CVE-2026-89090HIGHDenial of service in the event stream header decoder in AWS SDK for Go v2EPSS 0.3%