Vulnerabilidades em Amazon

55 resultados
Análise Vexday

A Amazon apresenta 35 vulnerabilidades catalogadas na base, com 5 classificadas como críticas, mas nenhuma sob ataque ativo confirmado no momento. A fraqueza dominante é validação inadequada de certificados (CWE-295), padrão típico em integrações cloud, e apenas 4 CVEs foram publicadas nos últimos 90 dias, indicando risco atual moderado e sem pressão imediata de exploração.

CVE-2024-52313MEDIUMdata.all authenticated users can obtain incorrect object level authorizationsEPSS 0.3%CVE-2024-10953MEDIUMdata.all authenticated users can perform mutating update operations on persisted notification recordsEPSS 0.3%CVE-2025-6031HIGHInsecure device pairing in end of life Amazon Cloud CamEPSS 0.3%CVE-2025-5279HIGHIssue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider pluginEPSS 0.3%CVE-2025-9039MEDIUMInformation Disclosure in Amazon ECS Container AgentEPSS 0.3%CVE-2026-94384MEDIUMMissing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce LambdaEPSS 0.3%CVE-2026-18657HIGHExecutable Resolution from Untrusted Project Directory in Kiro CLI on WindowsEPSS 0.2%CVE-2026-18656HIGHExecutable Resolution from Untrusted Project Directory in Kiro IDE on WindowsEPSS 0.2%CVE-2026-85654HIGHCode injection in the CDK generator in Amazon awslabs.dynamodb-mcp-serverEPSS 0.2%CVE-2025-8217MEDIUMInert Malicious script injected into Amazon Q Developer Visual Studio Code (VS Code) ExtensionEPSS 0.2%CVE-2025-12779HIGHImproper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authEPSS 0.2%CVE-2023-32803HIGHThe ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certEPSS 0.2%CVE-2025-12829MEDIUMAn uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to IoEPSS 0.2%CVE-2026-7791HIGHImproper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows beforeEPSS 0.1%CVE-2026-95985HIGHKiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted WorkspacesEPSS —