Vulnerabilidades em AWS

109 resultados
Análise Vexday

Com 69 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil do AWS situa-se abaixo da média geral do catálogo nesse indicador, o que representa um panorama relativamente controlado em termos de ameaças imediatas. No entanto, 33 vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige acompanhamento contínuo. O tipo de falha mais recorrente é CWE-327 (uso de algoritmo criptográfico quebrado ou arriscado), padrão que tende a impactar a confidencialidade e integridade de dados em escala. A CVE mais relevante no momento, CVE-2025-0851, apresenta score EPSS de 0,23, e embora existam 3 CVEs com prova de conceito pública e 5 de severidade crítica, nenhuma delas atingiu exploração confirmada até o momento — condição que pode mudar rapidamente diante da disponibilidade de PoCs.

CVE-2022-46174MEDIUMRace condition during concurrent TLS mounts in efs-utilsEPSS 0.6%CVE-2026-7461HIGHOS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume CredentialsEPSS 0.5%CVE-2026-18245MEDIUMIncomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-reactEPSS 0.5%CVE-2026-6968HIGHMultiple Path Traversal Variants in awslabs/toughEPSS 0.5%CVE-2022-23511HIGHA privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2EPSS 0.5%CVE-2026-13763HIGHHTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAFEPSS 0.5%CVE-2025-14503HIGHOverly Permissive Trust Policy in Harmonix on AWS EKSEPSS 0.5%CVE-2026-1777HIGHCleartext transmission of sensitive materials in aws/sagemaker-python-sdkEPSS 0.5%CVE-2025-12967HIGHAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticateEPSS 0.5%CVE-2026-13762HIGHHTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAFEPSS 0.4%CVE-2026-18140HIGHUncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated serversEPSS 0.4%CVE-2026-7191HIGHArbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWSEPSS 0.4%CVE-2026-12283MEDIUMSQL injection in Amazon Athena Synapse connectorEPSS 0.4%CVE-2026-6912HIGHPrivilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops WheelEPSS 0.4%CVE-2026-16756HIGHAllocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of serviceEPSS 0.4%CVE-2026-15957HIGHUncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapesEPSS 0.4%CVE-2026-14265HIGHRCE via Deserialization in AWS Advanced JDBC WrapperEPSS 0.4%CVE-2024-34072HIGHDeserialization of Untrusted Data in sagemaker-python-sdkEPSS 0.4%CVE-2026-14904HIGHRES Auth.GetUserPrivateKey Arbitrary File ReadEPSS 0.4%CVE-2026-9291HIGHInsecure Deserialization in Amazon Braket SDK Job Results ProcessingEPSS 0.4%