Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Athena Odbc MEDIUM 5.9
CVE-2026-35560

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-m…

Fix: 2.1.0.0+
Fix from $1,600 2026-04-03
Athena Odbc HIGH 7.8
CVE-2026-35558

Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor t…

Fix: 2.1.0.0+
Fix from $1,950 2026-04-03
Athena Odbc MEDIUM 6.5
CVE-2026-35559

Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by …

Fix: 2.1.0.0+
Fix from $1,600 2026-04-03
Bedrock Agentcore Starter Toolkit HIGH 7.5
CVE-2026-4269

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during th…

Fix: 0.1.13+
Fix from $1,950 2026-03-16
Aws Api Mcp Server MEDIUM 5.5
CVE-2026-4270

Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all pla…

Fix: 1.3.9+
Fix from $1,600 2026-03-16
Aws Lc Sys HIGH 7.5
CVE-2026-3338

Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objec…

Fix: 0.38.0 / 1.69.0+
Fix from $1,950 2026-03-02
Aws Lc Fips Sys MEDIUM 5.9
CVE-2026-3337

Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via…

Fix: 0.13.12 / 0.38.0+
Fix from $1,600 2026-03-02
Aws Lc Sys HIGH 7.5
CVE-2026-3336

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing P…

Fix: 0.38.0 / 1.69.0+
Fix from $1,950 2026-03-02
Firecracker MEDIUM 6.0
CVE-2026-1386

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host u…

Fix: 1.13.2+
Fix from $1,600 2026-01-23
Kiro Ide HIGH 7.8
CVE-2026-0830

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE b…

Fix: 0.6.18+
Fix from $1,950 2026-01-09
Harmonix HIGH 7.2
CVE-2025-14503

An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via ro…

Fix: 0.4.2+
Fix from $1,950 2025-12-15
Opensearch HIGH 7.5
CVE-2025-9624

A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all …

Fix: 3.3.0+
Fix from $1,950 2025-11-25
Opensearch Data Prepper HIGH 7.4
CVE-2025-62371

OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins …

Fix: 2.12.2+
Fix from $1,950 2025-10-15
Freertos Plus Tcp MEDIUM 5.4
CVE-2025-11616

A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of ce…

Fix: 4.3.4+
Fix from $1,600 2025-10-10
Freertos Plus Tcp MEDIUM 5.4
CVE-2025-11617

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with inc…

Fix: 4.3.4+
Fix from $1,600 2025-10-10
Aws Cloud Development Kit MEDIUM 5.5
CVE-2025-2598

When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration proper…

Fix: 2.178.2+
Fix from $1,600 2025-03-21
Aws Cloud Development Kit HIGH 8.1
CVE-2025-23206

The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it thro…

Fix: 2.177.0+
Fix from $1,950 2025-01-17
Redshift Connector HIGH 8.0
CVE-2024-12745

A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_col…

Mitigation only
Fix from $1,950 2024-12-24
Redshift Odbc Driver HIGH 8.0
CVE-2024-12746

A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLCol…

Mitigation only
Fix from $1,950 2024-12-24
Amazon Web Services Redshift Java Database Connectivity Driver HIGH 8.0
CVE-2024-12744

A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColum…

Mitigation only
Fix from $1,950 2024-12-24
Opensearch Data Prepper MEDIUM 6.9
CVE-2024-55886

OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerabili…

Fix: 2.10.2+
Fix from $1,600 2024-12-12
Data.all MEDIUM 6.3
CVE-2024-52311

Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution…

Fix: 2.6.1+
Fix from $1,600 2024-11-09
Data.all MEDIUM 5.4
CVE-2024-52312

Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations ag…

Fix: 2.6.1+
Fix from $1,600 2024-11-09
Aws Cloud Development Kit MEDIUM 6.4
CVE-2024-45037

The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own ap…

Fix: 2.148.1+
Fix from $1,600 2024-08-27
Freertos Plus Tcp HIGH 8.1
CVE-2024-38373

FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the …

Fix: 4.1.1+
Fix from $1,950 2024-06-24
Aws Deployment Framework HIGH 7.8
CVE-2024-37293

The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization.…

Fix: 4.0.0+
Fix from $1,950 2024-06-11
Amplify Cli CRITICAL 9.8
CVE-2024-28056

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentica…

Fix: 12.10.1+
Fix from $2,300 2024-04-15
Freertos HIGH 7.8
CVE-2024-28115

FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local priv…

Fix: 10.6.2+
Fix from $1,950 2024-03-07
Fire Os MEDIUM 5.9
CVE-2024-27350

Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: som…

Fix: 7.6.6.9 / 8.1.0.3+
Fix from $1,600 2024-02-26
Aws Encryption Sdk MEDIUM 5.3
CVE-2024-23680

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Fix: 1.9.0 / 2.2.0+
Fix from $1,600 2024-01-19