Vulnerabilidades em aws

141 resultados
Análise Vexday

A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.

CVE-2022-23511HIGHA privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2EPSS 0.5%CVE-2026-19642MEDIUMOut-of-bounds write in the Base64 decoder in Amazon aws-sdk-cppEPSS 0.5%CVE-2026-1777HIGHCleartext transmission of sensitive materials in aws/sagemaker-python-sdkEPSS 0.5%CVE-2026-3337HIGHTiming Side-Channel in AES-CCM Tag Verification in AWS-LCEPSS 0.5%CVE-2025-12967HIGHAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticateEPSS 0.5%CVE-2026-85781MEDIUMUnverified access point ownership in Amazon EFS CSI DriverEPSS 0.4%CVE-2026-87913MEDIUMMissing S3 bucket ownership verification in the AWS Security Agent MCP serverEPSS 0.4%CVE-2026-87912MEDIUMMissing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecopsEPSS 0.4%CVE-2026-18140HIGHUncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated serversEPSS 0.4%CVE-2026-18655HIGHBroker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt InjectionEPSS 0.4%CVE-2026-6911CRITICALAuthentication Bypass via Missing JWT Signature Verification in AWS Ops WheelEPSS 0.4%CVE-2026-4269MEDIUMImproper S3 ownership verification in Bedrock AgentCore Starter ToolkitEPSS 0.4%CVE-2024-34072HIGHDeserialization of Untrusted Data in sagemaker-python-sdkEPSS 0.4%CVE-2026-7426MEDIUMOut-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plus-TCPEPSS 0.4%CVE-2026-15643CRITICALAWS HealthLake MCP Server SSRF via Pagination URLEPSS 0.4%CVE-2026-3338HIGHPKCS7_verify Signature Validation Bypass in AWS-LCEPSS 0.4%CVE-2026-15737MEDIUMSensitive content disclosure via OpenTelemetry spans in AgentCore Python SDKEPSS 0.4%CVE-2026-92943CRITICALImproper validation of certificate with host mismatch in AWS IoT Device SDK for PythonEPSS 0.4%CVE-2026-3336HIGHPKCS7_verify Certificate Chain Validation Bypass in AWS-LCEPSS 0.4%CVE-2023-51651MEDIUMPotential URI resolution path traversal in the AWS SDK for PHPEPSS 0.4%