Vulnerabilidades em aws

141 resultados
Análise Vexday

A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.

CVE-2026-83551HIGHCleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline pathEPSS 0.6%CVE-2026-13762HIGHHTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAFEPSS 0.6%CVE-2026-12283MEDIUMSQL injection in Amazon Athena Synapse connectorEPSS 0.6%CVE-2022-46174MEDIUMRace condition during concurrent TLS mounts in efs-utilsEPSS 0.6%CVE-2026-14471HIGHAuthenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registryEPSS 0.6%CVE-2026-19311HIGHMissing Authorization in Execute Monitor API in OpenSearch Alerting PluginEPSS 0.6%CVE-2026-18733HIGHPrompt injection bypasses shell tool consent gate in Strands Agents ToolsEPSS 0.6%CVE-2026-14904HIGHRES Auth.GetUserPrivateKey Arbitrary File ReadEPSS 0.6%CVE-2026-19643MEDIUMOut-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platformsEPSS 0.6%CVE-2026-84942MEDIUMStored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch DashboardsEPSS 0.5%CVE-2026-5190HIGHAWS C Event Stream Streaming Decoder Stack Buffer OverflowEPSS 0.5%CVE-2026-18394MEDIUMIncorrect authorization in Strands Agents Tools http_request proxy credential exfiltrationEPSS 0.5%CVE-2026-18952HIGHMissing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics PluginEPSS 0.5%CVE-2026-19111HIGHInsecure direct object reference in Strands Agents Tools memory tool namespace isolationEPSS 0.5%CVE-2026-77811MEDIUMStored Cross-Site Scripting via Integration Template Asset in OpenSearch DashboardsEPSS 0.5%CVE-2025-14503HIGHOverly Permissive Trust Policy in Harmonix on AWS EKSEPSS 0.5%CVE-2026-89090HIGHDenial of service in the event stream header decoder in AWS SDK for Go v2EPSS 0.5%CVE-2026-18481MEDIUMStored XSS in Participant URL Field leads to Account Takeover via Session Token TheftEPSS 0.5%CVE-2026-18830HIGHInsufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness APIEPSS 0.5%CVE-2026-75910HIGHIncorrect privilege assignment in the Amazon aws-athena-query-federation ClickHouse connector deployment templateEPSS 0.5%