Vulnerabilities in aws

107 results
Vexday analysis

A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.

CVE-2022-46174MEDIUMRace condition during concurrent TLS mounts in efs-utilsEPSS 0.6%CVE-2026-7461HIGHOS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume CredentialsEPSS 0.5%CVE-2026-18245MEDIUMIncomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-reactEPSS 0.5%CVE-2026-6968HIGHMultiple Path Traversal Variants in awslabs/toughEPSS 0.5%CVE-2022-23511HIGHA privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2EPSS 0.5%CVE-2026-13763HIGHHTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAFEPSS 0.5%CVE-2025-14503HIGHOverly Permissive Trust Policy in Harmonix on AWS EKSEPSS 0.5%CVE-2026-1777HIGHCleartext transmission of sensitive materials in aws/sagemaker-python-sdkEPSS 0.5%CVE-2025-12967HIGHAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticateEPSS 0.4%CVE-2026-13762HIGHHTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAFEPSS 0.4%CVE-2026-18140HIGHUncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated serversEPSS 0.4%CVE-2026-7191HIGHArbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWSEPSS 0.4%CVE-2026-12283MEDIUMSQL injection in Amazon Athena Synapse connectorEPSS 0.4%CVE-2026-6912HIGHPrivilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops WheelEPSS 0.4%CVE-2026-15957HIGHUncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapesEPSS 0.4%CVE-2026-16756HIGHAllocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of serviceEPSS 0.4%CVE-2026-14265HIGHRCE via Deserialization in AWS Advanced JDBC WrapperEPSS 0.4%CVE-2024-34072HIGHDeserialization of Untrusted Data in sagemaker-python-sdkEPSS 0.4%CVE-2026-14904HIGHRES Auth.GetUserPrivateKey Arbitrary File ReadEPSS 0.4%CVE-2026-9291HIGHInsecure Deserialization in Amazon Braket SDK Job Results ProcessingEPSS 0.4%