Vulnerabilidades en aws
141 resultadosAnálisis Vexday
A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.
CVE-2025-14762MEDIUMMissing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK thatEPSS 0.2%CVE-2026-5747HIGHOut-of-bounds Write in Firecracker virtio-pci TransportEPSS 0.2%CVE-2026-4295HIGHArbitrary code execution via crafted project files in Kiro IDEEPSS 0.2%CVE-2026-81838MEDIUMZip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)EPSS 0.2%CVE-2026-89065MEDIUMRelative path traversal in the generated file manifest cleanup component in projenEPSS 0.2%CVE-2026-85788MEDIUMIncomplete list of disallowed inputs in awslabs mysql-mcp-serverEPSS 0.2%CVE-2026-18953MEDIUMImproper limitation of a pathname to a restricted directory in aws-transform-mcp-serverEPSS 0.2%CVE-2026-4270MEDIUMAWS API MCP File Access Restriction BypassEPSS 0.2%CVE-2026-89332MEDIUMKiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace ConfigurationEPSS 0.2%CVE-2026-9255HIGHTool Execution Without Authorization via Piped Stdin in Kiro CLIEPSS 0.2%CVE-2026-85028HIGHCreation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development KitEPSS 0.2%CVE-2025-14760MEDIUMMissing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to introduce a new EDK that EPSS 0.2%CVE-2025-8069HIGHLocal Privilege Escalation Vulnerability in AWS Client VPN Windows ClientEPSS 0.2%CVE-2026-13769MEDIUMOverly permissive File Permissions in AWS CLIEPSS 0.2%CVE-2026-18954MEDIUMIncorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP ServerEPSS 0.2%CVE-2026-11931MEDIUMInsecure Permissions on Authentication Token Cache File in Kiro IDEEPSS 0.1%CVE-2025-14763MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to intrEPSS 0.1%CVE-2025-14764MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introdEPSS 0.1%CVE-2025-14759MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to intrEPSS 0.1%CVE-2026-10584HIGHHTTPS Fallback to HTTP in Graph ExplorerEPSS 0.1%