Vulnerabilidades en amazon

43 resultados
Análisis Vexday

A Amazon tem 5 vulnerabilidades catalogadas na base Vexday, nenhuma delas sob ataque ativo ou com severidade crítica. A fraqueza dominante é CWE-863 (controle de acesso impróprio), indicando exposição potencial a escalação de privilégios; porém, a ausência de atualizações recentes sugere que o panorama atual é estável e sem pressão temporal imediata.

CVE-2026-15738MEDIUMCross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer ControllerEPSS 0.4%CVE-2024-8901MEDIUMLack of JWT issuer and signer validationEPSS 0.4%CVE-2024-52312MEDIUMdata.all authenticated users can perform restricted operations against DataSets and EnvironmentsEPSS 0.3%CVE-2025-8904CRITICALPrivilege escalation issue in Amazon EMR Secret Agent componentEPSS 0.3%CVE-2023-1385HIGHImproper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to uEPSS 0.3%CVE-2024-10125MEDIUMLack of JWT issuer and signer validationEPSS 0.3%CVE-2025-5688HIGHOut of Bounds Write in FreeRTOS-Plus-TCPEPSS 0.3%CVE-2024-52313MEDIUMdata.all authenticated users can obtain incorrect object level authorizationsEPSS 0.3%CVE-2024-10953MEDIUMdata.all authenticated users can perform mutating update operations on persisted notification recordsEPSS 0.3%CVE-2026-3494MEDIUMMariaDB Server Audit Plugin Comment Handling BypassEPSS 0.3%CVE-2026-35558HIGHImproper neutralization of special elements in authentication components in Amazon Athena ODBC driverEPSS 0.3%CVE-2026-35559HIGHOut-of-bounds write in query processing components in Amazon Athena ODBC driverEPSS 0.3%CVE-2025-5279HIGHIssue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider pluginEPSS 0.3%CVE-2026-35560CRITICALImproper certificate validation in identity provider connection components in Amazon Athena ODBC driverEPSS 0.3%CVE-2025-6031HIGHInsecure device pairing in end of life Amazon Cloud CamEPSS 0.3%CVE-2025-9039MEDIUMInformation Disclosure in Amazon ECS Container AgentEPSS 0.2%CVE-2026-15746MEDIUMCredential disclosure in Strands Agents Tools elasticsearch_memory toolEPSS 0.2%CVE-2025-8217MEDIUMInert Malicious script injected into Amazon Q Developer Visual Studio Code (VS Code) ExtensionEPSS 0.2%CVE-2025-12779HIGHImproper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authEPSS 0.2%CVE-2026-18657HIGHExecutable Resolution from Untrusted Project Directory in Kiro CLI on WindowsEPSS 0.2%