Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aws Software Development Kit MEDIUM 5.9
CVE-2026-19642

An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or …

No fix yet
Fix from $4,000 2026-08-12
Aws Software Development Kit MEDIUM 5.3
CVE-2026-19643

An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user t…

No fix yet
Fix from $4,000 2026-08-12
Documentdb Mcp Server MEDIUM 5.5
CVE-2026-18954

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clie…

Fix: 1.0.12+
Fix from $1,600 2026-08-05
Aws Transform Mcp Server HIGH 8.8
CVE-2026-18953

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 m…

Fix: 0.1.5+
Fix from $1,950 2026-08-05
Kiro Ide HIGH 7.8
CVE-2026-18656

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary cod…

No fix yet
Fix from $1,950 2026-08-04
Kiro Cli HIGH 7.8
CVE-2026-18657

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code…

No fix yet
Fix from $1,950 2026-08-04
Amplify Codegen Ui HIGH 8.8
CVE-2026-18245

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrar…

Fix: 2.20.6+
Fix from $1,950 2026-07-30
Aws Smithy Json HIGH 7.5
CVE-2026-18140

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes fr…

Fix: 0.62.7+
Fix from $1,950 2026-07-30
Advanced Jdbc Wrapper HIGH 8.8
CVE-2026-14265

Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an a…

Fix: 4.0.1+
Fix from $1,950 2026-07-01
Cloudfront CRITICAL 9.8
CVE-2026-13762

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule bod…

Mitigation only
Fix from $2,300 2026-06-29
Application Load Balancer CRITICAL 9.8
CVE-2026-13763

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF mana…

Mitigation only
Fix from $2,300 2026-06-29
Kiro Ide HIGH 8.8
CVE-2026-10591

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to e…

Fix: 0.11+
Fix from $1,950 2026-06-02
Kiro Cli HIGH 7.8
CVE-2026-9255

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, includ…

Fix: 1.28.0+
Fix from $1,950 2026-05-22
Amazon Ecs Container Agent HIGH 7.2
CVE-2026-7461

Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows befor…

Fix: 1.103.0+
Fix from $1,950 2026-04-30
Freertos Plus Tcp HIGH 8.1
CVE-2026-7426

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an ad…

Fix: 4.2.6 / 4.4.1+
Fix from $1,950 2026-04-29
Freertos Plus Tcp MEDIUM 6.5
CVE-2026-7425

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent networ…

Fix: 4.2.6 / 4.4.1+
Fix from $1,600 2026-04-29
Freertos Plus Tcp HIGH 8.1
CVE-2026-7424

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the devic…

Fix: 4.2.6 / 4.4.1+
Fix from $1,950 2026-04-29
Freertos Plus Tcp MEDIUM 6.5
CVE-2026-7422

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size…

Fix: 4.2.6 / 4.4.1+
Fix from $1,600 2026-04-29
Freertos Plus Tcp MEDIUM 6.5
CVE-2026-7423

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a…

Fix: 4.2.6 / 4.4.1+
Fix from $1,600 2026-04-29
Tough MEDIUM 6.5
CVE-2026-6967

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated u…

Fix: 0.15.0 / 0.22.0+
Fix from $1,600 2026-04-24
Tough MEDIUM 6.5
CVE-2026-6968

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write file…

Fix: 0.15.0 / 0.22.0+
Fix from $1,600 2026-04-24
Tough MEDIUM 6.5
CVE-2026-6966

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenti…

Fix: 0.15.0 / 0.22.0+
Fix from $1,600 2026-04-24
Efs Csi Driver MEDIUM 6.5
CVE-2026-6437

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remot…

Fix: 3.0.1+
Fix from $1,600 2026-04-17
Firecracker HIGH 7.5
CVE-2026-5747

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local gu…

Fix: after 1.14.3
Fix from $1,950 2026-04-08
Research And Engineering Studio HIGH 8.8
CVE-2026-5707

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through …

Fix: 2026.03+
Fix from $1,950 2026-04-06
Research And Engineering Studio HIGH 8.8
CVE-2026-5708

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 202…

Fix: 2026.03+
Fix from $1,950 2026-04-06
Research And Engineering Studio HIGH 8.8
CVE-2026-5709

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authent…

Fix: 2026.03+
Fix from $1,950 2026-04-06
Athena Odbc CRITICAL 9.8
CVE-2026-35561

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow …

Fix: 2.1.0.0+
Fix from $2,300 2026-04-03
Athena Odbc HIGH 7.8
CVE-2026-5485

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to…

Fix: 2.0.5.1+
Fix from $1,950 2026-04-03
Athena Odbc HIGH 7.5
CVE-2026-35562

Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a de…

Fix: 2.1.0.0+
Fix from $1,950 2026-04-03