Vulnerabilidades em AWS

109 resultados
Análise Vexday

Com 69 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil do AWS situa-se abaixo da média geral do catálogo nesse indicador, o que representa um panorama relativamente controlado em termos de ameaças imediatas. No entanto, 33 vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige acompanhamento contínuo. O tipo de falha mais recorrente é CWE-327 (uso de algoritmo criptográfico quebrado ou arriscado), padrão que tende a impactar a confidencialidade e integridade de dados em escala. A CVE mais relevante no momento, CVE-2025-0851, apresenta score EPSS de 0,23, e embora existam 3 CVEs com prova de conceito pública e 5 de severidade crítica, nenhuma delas atingiu exploração confirmada até o momento — condição que pode mudar rapidamente diante da disponibilidade de PoCs.

CVE-2025-0851CRITICALPath traversal issue in Deep Java LibraryEPSS 23.3%CVE-2022-31159HIGHPartial Path Traversal in com.amazonaws:aws-java-sdk-s3 EPSS 1.4%CVE-2026-0830HIGHCommand Injection in Kiro GitLab Merge Request HelperEPSS 1.3%CVE-2024-34073HIGHCommand Injection in sagemaker-python-sdkEPSS 1.1%CVE-2026-5709HIGHAWS Research and Engineering Studio (RES) FileBrowser Command InjectionEPSS 1.1%CVE-2026-3337HIGHTiming Side-Channel in AES-CCM Tag Verification in AWS-LCEPSS 1.1%CVE-2026-5707HIGHCommand Injection via Virtual Desktop Session Name in AWS Research and Engineering Studio (RES)EPSS 1.0%CVE-2026-11417HIGHOS Command Injection in NodejsFunction Bundling in aws-cdk-libEPSS 0.9%CVE-2023-35165MEDIUMAWS CDK EKS overly permissive trust policiesEPSS 0.9%CVE-2026-5708HIGHImproper Control of User-Modifiable Attributes in RES CreateSession APIEPSS 0.8%CVE-2026-8838CRITICALRemote Code Execution via eval() Injection in amazon-redshift-python-driverEPSS 0.8%CVE-2026-3338HIGHPKCS7_verify Signature Validation Bypass in AWS-LCEPSS 0.8%CVE-2024-32888CRITICALAmazon JDBC Driver for Redshift SQL Injection via line comment generationEPSS 0.8%CVE-2026-3336HIGHPKCS7_verify Certificate Chain Validation Bypass in AWS-LCEPSS 0.8%CVE-2025-3047MEDIUMPath Traversal in AWS SAM CLI allows file copy to build containerEPSS 0.7%CVE-2022-24709HIGHCross site scripting in @awsui/components-reactEPSS 0.7%CVE-2026-10591HIGHKiro IDE Insufficient File Write Restrictions to Execution-Sensitive PathsEPSS 0.7%CVE-2026-15895HIGHOS command injection in jsii-diff in AWS jsiiEPSS 0.6%CVE-2026-13760HIGHOS Command Injection in aws-cdk-lib Docker BundlingEPSS 0.6%CVE-2025-3048MEDIUMPath Traversal in AWS SAM CLI allows file copy to local cacheEPSS 0.6%