Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Aws Software Development Kit MEDIUM 5.9
CVE-2026-19642

An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or …

No fix yet
Fix from $4,000 2026-08-12
Aws Software Development Kit MEDIUM 5.3
CVE-2026-19643

An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user t…

No fix yet
Fix from $4,000 2026-08-12
Kiro Ide HIGH 7.8
CVE-2026-18656

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary cod…

No fix yet
Fix from $1,950 2026-08-04
Kiro Cli HIGH 7.8
CVE-2026-18657

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code…

No fix yet
Fix from $1,950 2026-08-04
Cloudfront CRITICAL 9.8
CVE-2026-13762

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule bod…

Mitigation only
Fix from $2,300 2026-06-29
Application Load Balancer CRITICAL 9.8
CVE-2026-13763

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF mana…

Mitigation only
Fix from $2,300 2026-06-29
Redshift Connector HIGH 8.0
CVE-2024-12745

A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_col…

Mitigation only
Fix from $1,950 2024-12-24
Redshift Odbc Driver HIGH 8.0
CVE-2024-12746

A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLCol…

Mitigation only
Fix from $1,950 2024-12-24
Amazon Web Services Redshift Java Database Connectivity Driver HIGH 8.0
CVE-2024-12744

A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColum…

Mitigation only
Fix from $1,950 2024-12-24
Alexa HIGH 7.6
CVE-2023-33248

Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relev…

No fix yet
Fix from $1,950 2023-05-24
Aws Sigv4 MEDIUM 5.5
CVE-2023-30610

aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` impl…

Mitigation only
Fix from $1,600 2023-04-19
Aws Client Vpn HIGH 7.0
CVE-2022-25165

An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows …

No fix yet
Fix from $1,950 2022-04-14
Aws Client Vpn MEDIUM 5.0
CVE-2022-25166

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file …

No fix yet
Fix from $1,600 2022-04-14
Echo Dot Firmware CRITICAL 9.8
CVE-2022-25809

Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices…

No fix yet
Fix from $2,300 2022-02-24
Amazon Cloudfront CRITICAL 9.8
CVE-2020-36363

Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consid…

Mitigation only
Fix from $2,300 2021-08-12
Firecracker MEDIUM 5.9
CVE-2020-16843

In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial o…

Mitigation only
Fix from $1,600 2020-08-04
Firecracker CRITICAL 9.8
CVE-2019-18960

Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.

Mitigation only
Fix from $2,300 2019-12-11
Freertos\+fat HIGH 7.5
CVE-2019-18178

Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by f…

No fix yet
Fix from $1,950 2019-11-04
Fire Os HIGH 7.5
CVE-2018-11021

kernel/omap/drivers/video/omap2/dsscomp/device.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a c…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11022

kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafte…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11023

kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a craft…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11024

kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a craft…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11025

kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted ar…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11019

kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafte…

No fix yet
Fix from $1,950 2018-10-16
Amazon Music HIGH 8.8
CVE-2018-1169

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction …

Mitigation only
Fix from $1,950 2018-03-02
Audible HIGH 7.8
CVE-2017-17069

ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched fr…

No fix yet
Fix from $1,950 2017-12-06
Merchant Sdk MEDIUM 5.8
CVE-2012-5780

The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

No fix yet
Fix from $1,600 2012-11-04
Elastic Load Balancing MEDIUM 5.8
CVE-2012-5781

Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAl…

No fix yet
Fix from $1,600 2012-11-04
Flexible Payments Service MEDIUM 5.8
CVE-2012-5782

Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) o…

No fix yet
Fix from $1,600 2012-11-04
Kindle For Pc MEDIUM 6.9
CVE-2010-5268

Untrusted search path vulnerability in Amazon Kindle for PC 1.3.0 30884 allows local users to gain privileges via a Trojan horse wintab32.dll file in…

Mitigation only
Fix from $1,600 2012-09-07