Vulnerabilidades em aws

141 resultados
Análise Vexday

A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.

CVE-2025-0851CRITICALPath traversal issue in Deep Java LibraryEPSS 23.3%CVE-2026-85012HIGHOS command injection in the Amazon CodeCatalyst blueprints SDKEPSS 2.3%CVE-2026-94450HIGHPotential denial of service when configured to send Retry packets in s2n-quicEPSS 1.9%CVE-2026-87911CRITICALRead-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-serverEPSS 1.7%CVE-2022-31159HIGHPartial Path Traversal in com.amazonaws:aws-java-sdk-s3 EPSS 1.5%CVE-2026-0830HIGHCommand Injection in Kiro GitLab Merge Request HelperEPSS 1.5%CVE-2026-13760HIGHOS Command Injection in aws-cdk-lib Docker BundlingEPSS 1.2%CVE-2024-34073HIGHCommand Injection in sagemaker-python-sdkEPSS 1.2%CVE-2026-9133HIGHArbitrary file read in rabbitmq-aws pluginEPSS 1.1%CVE-2026-15895HIGHOS command injection in jsii-diff in AWS jsiiEPSS 1.1%CVE-2026-18428HIGHSQL Query Validation Bypass in OpenSearch Direct QueryEPSS 1.0%CVE-2026-11417HIGHOS Command Injection in NodejsFunction Bundling in aws-cdk-libEPSS 1.0%CVE-2026-18245MEDIUMIncomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-reactEPSS 1.0%CVE-2026-5709HIGHAWS Research and Engineering Studio (RES) FileBrowser Command InjectionEPSS 1.0%CVE-2026-5707HIGHCommand Injection via Virtual Desktop Session Name in AWS Research and Engineering Studio (RES)EPSS 1.0%CVE-2026-6912HIGHPrivilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops WheelEPSS 1.0%CVE-2023-35165MEDIUMAWS CDK EKS overly permissive trust policiesEPSS 0.9%CVE-2026-7461HIGHOS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume CredentialsEPSS 0.8%CVE-2026-8838CRITICALRemote Code Execution via eval() Injection in amazon-redshift-python-driverEPSS 0.8%CVE-2024-32888CRITICALAmazon JDBC Driver for Redshift SQL Injection via line comment generationEPSS 0.8%