amazon
196 tracked vulnerabilities.
CVE-2026-3338
HIGH
AWS-LC < 1.69.0 - Improper Verification of Cryptographic Signature in PKCS7_verify()
Mar 02, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-3337
MEDIUM
AWS-LC < 1.69.0 and 3.0.0-3.1.9 - Observable Timing Discrepancy in AES-CCM Decryption via EVP CIPHER API
Mar 02, 2026
CVSS 5.9
EPSS 0.00
CVE-2026-3336
HIGH
AWS-LC 1.41.0-1.68.0 - Unauthenticated Certificate Chain Verification Bypass in PKCS7_verify()
Mar 02, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-1386
MEDIUM
Firecracker <1.13.2-1.14.1 - Privilege Escalation
Jan 23, 2026
CVSS 6.0
EPSS 0.00
CVE-2026-0830
HIGH
Kiro IDE <0.6.18 - Command Injection
Jan 09, 2026
CVSS 7.8
EPSS 0.00
CVE-2025-14503
HIGH
Harmonix on AWS <0.4.2 - Privilege Escalation
Dec 15, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-9624
HIGH
OpenSearch 3.0.0-3.2.9 and < 2.19.4 - Denial of Service via Complex Query String Input
Nov 25, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-12829
MEDIUM
Amazon Ion-C <v1.1.4 - Info Disclosure
Nov 07, 2025
CVSS 6.2
EPSS 0.00
CVE-2025-12779
HIGH
Amazon WorkSpaces client <2024.8 - Info Disclosure
Nov 05, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-62371
HIGH
OpenSearch Data Prepper < 2.12.2 - Improper Certificate Validation in OpenSearch Sink and Source Plugins
Oct 15, 2025
CVSS 7.4
EPSS 0.00
CVE-2025-11618
MEDIUM
FreeRTOS-Plus-TCP 4.0.0-4.3.3 - Null Pointer Dereference in UDP/IPv6 Packet Processing
Oct 10, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11617
MEDIUM
FreeRTOS-Plus-TCP 4.0.0-4.3.3 - Buffer Over-read in IPv6 Packet Processing
Oct 10, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-11616
MEDIUM
FreeRTOS-Plus-TCP 4.0.0-4.3.3 - Buffer Over-read in ICMPv6 Packet Processing
Oct 10, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-11573
HIGH
Amazon.IonDotnet < 1.3.2 - Denial of Service via Infinite Loop in Text Input Parser
Oct 09, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-9039
MEDIUM
Amazon ECS <1.97.1 - Info Disclosure
Aug 14, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-8904
HIGH
Amazon EMR <7.5 - Privilege Escalation
Aug 13, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-8217
MEDIUM
Amazon Q Developer VS Code <1.85.0 - Info Disclosure
Jul 30, 2025
CVSS 4.0
EPSS 0.00
CVE-2025-6031
HIGH
Amazon Cloud Cam - Unauthenticated SSL Pinning Bypass via Deprecated Remote Service
Jun 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-5688
HIGH
Amazon FreeRTOS 2.3.4-4.3.2 - Out-of-bounds Write via LLMNR or mDNS Query Processing
Jun 04, 2025
EPSS 0.00
CVE-2025-5279
HIGH
Amazon Redshift Python Connector 2.0.872-2.1.7 - Improper Certificate Validation
May 27, 2025
EPSS 0.00
CVE-2025-4318
CRITICAL
AWS Amplify Studio - Code Injection
May 05, 2025
EPSS 0.00
CVE-2025-3857
HIGH
Amazon.IonDotnet < 1.3.1 - Denial of Service via RawBinaryReader Binary Deserialization
Apr 21, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-2888
MEDIUM
Amazon Tough < 0.20.0 - Incorrect Timestamp Validation During Snapshot Rollback
Mar 27, 2025
CVSS 4.5
EPSS 0.00
CVE-2025-2887
MEDIUM
Amazon Tough < 0.20.0 - Incorrect Target Rollback Detection
Mar 27, 2025
CVSS 4.5
EPSS 0.00
CVE-2025-2886
MEDIUM
Amazon Tough < 0.20.0 - Incorrect Target Source Validation via Delegation Chain
Mar 27, 2025
CVSS 4.5
EPSS 0.00
Products
freertos 17
amazon_web_services_freertos 14
fire_os 13
opensearch 11
tough 10
freertos-plus-tcp 9
blink_xt2_sync_module_firmware 7
Amazon Athena ODBC driver 6
athena_odbc 6
data.all 5
payfort-php-sdk 5
amazon_web_services_internet_of_things_device_software_development_kit_v2 4
aws_cloud_development_kit 4
aws_software_development_kit 4
firecracker 4
amazon_web_services_aws-c-io 3
aws-lc-sys 3
aws_libcrypto 3
echo_dot_firmware 3
opensearch_data_prepper 3
research_and_engineering_studio 3
tuftool 3
WorkSpaces Client 2
amazon_linux 2
amazon_web_services_redshift_java_database_connectivity_driver 2
audible 2
aws_client_vpn 2
aws_encryption_sdk 2
aws_s3_crypto_sdk 2
awslabs_sandbox_accounts_for_events 2
Quick Filters