Vulnerabilidades em amazon
54 resultadosAnálise Vexday
A Amazon tem 5 vulnerabilidades catalogadas na base Vexday, nenhuma delas sob ataque ativo ou com severidade crítica. A fraqueza dominante é CWE-863 (controle de acesso impróprio), indicando exposição potencial a escalação de privilégios; porém, a ausência de atualizações recentes sugere que o panorama atual é estável e sem pressão temporal imediata.
CVE-2019-3984—Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitiEPSS 3.8%CVE-2018-1169—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User intEPSS 2.5%CVE-2026-85656HIGHOS command injection in Amazon log4j-cve-2021-44228-hotpatchEPSS 1.1%CVE-2025-4318CRITICALInput validation issue in AWS Amplify Studio UI component propertiesEPSS 0.9%CVE-2026-5485HIGHOS command injection in Amazon Athena ODBC driver on LinuxEPSS 0.7%CVE-2026-15738MEDIUMCross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer ControllerEPSS 0.6%CVE-2025-3857HIGHInfinite loop condition in Amazon.IonDotnetEPSS 0.6%CVE-2024-12744HIGHSQL Injection in the Amazon Redshift JDBC Driver affecting v2.1.0.31EPSS 0.6%CVE-2026-8178CRITICALRemote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC DriverEPSS 0.6%CVE-2026-81849HIGHPath traversal in the aws:downloadContent plugin in amazon-ssm-agentEPSS 0.6%CVE-2024-12745HIGHSQL Injection in the Amazon Redshift Python Connector affecting v2.1.4EPSS 0.5%CVE-2026-6437MEDIUMAWS EFS CSI Driver Mount Option InjectionEPSS 0.5%CVE-2026-83497HIGHUnrestricted Java Deserialization in OpenSearch SQL Plugin Cursor PaginationEPSS 0.5%CVE-2025-0500HIGHIssue affecting Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV clientsEPSS 0.5%CVE-2024-52311MEDIUMdata.all does not invalidate authentication token upon user logoutEPSS 0.5%CVE-2026-35561CRITICALInsufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driverEPSS 0.5%CVE-2024-12746HIGHSQL Injection in the Amazon Redshift ODBC Driver affecting v2.1.5.0EPSS 0.5%CVE-2025-0501HIGHIssue affecting Amazon WorkSpaces Clients (when running PCoIP protocol)EPSS 0.5%CVE-2025-11573HIGHDenial of Service issue in Amazon.IonDotnetEPSS 0.4%CVE-2026-15746MEDIUMCredential disclosure in Strands Agents Tools elasticsearch_memory toolEPSS 0.4%