amazon

196 tracked vulnerabilities.

CVE-2026-3338 HIGH
AWS-LC < 1.69.0 - Improper Verification of Cryptographic Signature in PKCS7_verify()
Mar 02, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-3337 MEDIUM
AWS-LC < 1.69.0 and 3.0.0-3.1.9 - Observable Timing Discrepancy in AES-CCM Decryption via EVP CIPHER API
Mar 02, 2026
CVSS 5.9
EPSS 0.00
CVE-2026-3336 HIGH
AWS-LC 1.41.0-1.68.0 - Unauthenticated Certificate Chain Verification Bypass in PKCS7_verify()
Mar 02, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-1386 MEDIUM
Firecracker <1.13.2-1.14.1 - Privilege Escalation
Jan 23, 2026
CVSS 6.0
EPSS 0.00
CVE-2026-0830 HIGH
Kiro IDE <0.6.18 - Command Injection
Jan 09, 2026
CVSS 7.8
EPSS 0.00
CVE-2025-14503 HIGH
Harmonix on AWS <0.4.2 - Privilege Escalation
Dec 15, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-9624 HIGH
OpenSearch 3.0.0-3.2.9 and < 2.19.4 - Denial of Service via Complex Query String Input
Nov 25, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-12829 MEDIUM
Amazon Ion-C <v1.1.4 - Info Disclosure
Nov 07, 2025
CVSS 6.2
EPSS 0.00
CVE-2025-12779 HIGH
Amazon WorkSpaces client <2024.8 - Info Disclosure
Nov 05, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-62371 HIGH
OpenSearch Data Prepper < 2.12.2 - Improper Certificate Validation in OpenSearch Sink and Source Plugins
Oct 15, 2025
CVSS 7.4
EPSS 0.00
CVE-2025-11618 MEDIUM
FreeRTOS-Plus-TCP 4.0.0-4.3.3 - Null Pointer Dereference in UDP/IPv6 Packet Processing
Oct 10, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11617 MEDIUM
FreeRTOS-Plus-TCP 4.0.0-4.3.3 - Buffer Over-read in IPv6 Packet Processing
Oct 10, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-11616 MEDIUM
FreeRTOS-Plus-TCP 4.0.0-4.3.3 - Buffer Over-read in ICMPv6 Packet Processing
Oct 10, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-11573 HIGH
Amazon.IonDotnet < 1.3.2 - Denial of Service via Infinite Loop in Text Input Parser
Oct 09, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-9039 MEDIUM
Amazon ECS <1.97.1 - Info Disclosure
Aug 14, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-8904 HIGH
Amazon EMR <7.5 - Privilege Escalation
Aug 13, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-8217 MEDIUM
Amazon Q Developer VS Code <1.85.0 - Info Disclosure
Jul 30, 2025
CVSS 4.0
EPSS 0.00
CVE-2025-6031 HIGH
Amazon Cloud Cam - Unauthenticated SSL Pinning Bypass via Deprecated Remote Service
Jun 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-5688 HIGH
Amazon FreeRTOS 2.3.4-4.3.2 - Out-of-bounds Write via LLMNR or mDNS Query Processing
Jun 04, 2025
EPSS 0.00
CVE-2025-5279 HIGH
Amazon Redshift Python Connector 2.0.872-2.1.7 - Improper Certificate Validation
May 27, 2025
EPSS 0.00
CVE-2025-4318 CRITICAL
AWS Amplify Studio - Code Injection
May 05, 2025
EPSS 0.00
CVE-2025-3857 HIGH
Amazon.IonDotnet < 1.3.1 - Denial of Service via RawBinaryReader Binary Deserialization
Apr 21, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-2888 MEDIUM
Amazon Tough < 0.20.0 - Incorrect Timestamp Validation During Snapshot Rollback
Mar 27, 2025
CVSS 4.5
EPSS 0.00
CVE-2025-2887 MEDIUM
Amazon Tough < 0.20.0 - Incorrect Target Rollback Detection
Mar 27, 2025
CVSS 4.5
EPSS 0.00
CVE-2025-2886 MEDIUM
Amazon Tough < 0.20.0 - Incorrect Target Source Validation via Delegation Chain
Mar 27, 2025
CVSS 4.5
EPSS 0.00