Vulnerabilidades em Amazon
43 resultadosAnálise Vexday
A Amazon apresenta 35 vulnerabilidades catalogadas na base, com 5 classificadas como críticas, mas nenhuma sob ataque ativo confirmado no momento. A fraqueza dominante é validação inadequada de certificados (CWE-295), padrão típico em integrações cloud, e apenas 4 CVEs foram publicadas nos últimos 90 dias, indicando risco atual moderado e sem pressão imediata de exploração.
CVE-2026-15738MEDIUMCross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer ControllerEPSS 0.4%CVE-2024-8901MEDIUMLack of JWT issuer and signer validationEPSS 0.4%CVE-2024-52312MEDIUMdata.all authenticated users can perform restricted operations against DataSets and EnvironmentsEPSS 0.3%CVE-2025-8904CRITICALPrivilege escalation issue in Amazon EMR Secret Agent componentEPSS 0.3%CVE-2023-1385HIGHImproper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to uEPSS 0.3%CVE-2024-10125MEDIUMLack of JWT issuer and signer validationEPSS 0.3%CVE-2025-5688HIGHOut of Bounds Write in FreeRTOS-Plus-TCPEPSS 0.3%CVE-2024-52313MEDIUMdata.all authenticated users can obtain incorrect object level authorizationsEPSS 0.3%CVE-2024-10953MEDIUMdata.all authenticated users can perform mutating update operations on persisted notification recordsEPSS 0.3%CVE-2026-3494MEDIUMMariaDB Server Audit Plugin Comment Handling BypassEPSS 0.3%CVE-2026-35558HIGHImproper neutralization of special elements in authentication components in Amazon Athena ODBC driverEPSS 0.3%CVE-2026-35559HIGHOut-of-bounds write in query processing components in Amazon Athena ODBC driverEPSS 0.3%CVE-2025-5279HIGHIssue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider pluginEPSS 0.3%CVE-2026-35560CRITICALImproper certificate validation in identity provider connection components in Amazon Athena ODBC driverEPSS 0.3%CVE-2025-6031HIGHInsecure device pairing in end of life Amazon Cloud CamEPSS 0.3%CVE-2025-9039MEDIUMInformation Disclosure in Amazon ECS Container AgentEPSS 0.2%CVE-2026-15746MEDIUMCredential disclosure in Strands Agents Tools elasticsearch_memory toolEPSS 0.2%CVE-2025-8217MEDIUMInert Malicious script injected into Amazon Q Developer Visual Studio Code (VS Code) ExtensionEPSS 0.2%CVE-2025-12779HIGHImproper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authEPSS 0.2%CVE-2026-18657HIGHExecutable Resolution from Untrusted Project Directory in Kiro CLI on WindowsEPSS 0.2%