Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ion HIGH 7.5
CVE-2024-21634

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for a…

Fix: 1.10.5+
Fix from $1,950 2024-01-03
Awslabs Sandbox Accounts For Events CRITICAL 9.0
CVE-2023-50928

"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Au…

Fix: 1.1.0+
Fix from $2,300 2023-12-22
Freertos HIGH 7.8
CVE-2021-27504

Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an intege…

Fix: 4.10.03 / 4.40.00+
Fix from $1,950 2023-11-21
Opensearch MEDIUM 5.4
CVE-2023-45807

OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 2021. There is an issue with the…

Fix: 1.3.14.0 / 2.11.0.0+
Fix from $1,600 2023-10-16
Aws Dataall HIGH 8.8
CVE-2023-36467

AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1…

Fix: after 1.5.1
Fix from $1,950 2023-06-28
Aws Cloud Development Kit HIGH 8.8
CVE-2023-35165

AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through …

Fix: 1.202.0 / 2.80.0+
Fix from $1,950 2023-06-23
Alexa HIGH 7.6
CVE-2023-33248

Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relev…

No fix yet
Fix from $1,950 2023-05-24
Opensearch MEDIUM 5.9
CVE-2023-31141

OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue…

Fix: 1.3.10 / 2.7.0+
Fix from $1,600 2023-05-08
Fire Os HIGH 8.8
CVE-2023-1385

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthoriz…

Fix: 6.2.9.5 / 7.6.3.3+
Fix from $1,950 2023-05-03
Fire Os MEDIUM 6.1
CVE-2023-1384

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run Th…

Fix: 6.2.9.5 / 7.6.3.3+
Fix from $1,600 2023-05-03
Aws Sigv4 MEDIUM 5.5
CVE-2023-30610

aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` impl…

Mitigation only
Fix from $1,600 2023-04-19
Opensearch MEDIUM 5.3
CVE-2023-25806

OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the au…

Fix: 1.3.9 / 2.6.0+
Fix from $1,600 2023-03-02
Opensearch HIGH 8.8
CVE-2023-23612

OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained from the Identity Provider (Id…

Fix: 1.3.8 / 2.5.0+
Fix from $1,950 2023-01-26
Opensearch MEDIUM 6.5
CVE-2023-23613

OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implementation of field-level secur…

Fix: 1.3.8 / 2.5.0+
Fix from $1,600 2023-01-26
Aws Software Development Kit CRITICAL 9.8
CVE-2022-4725

A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-co…

Fix: 2.59.1+
Fix from $2,300 2022-12-27
Cloudwatch Agent MEDIUM 6.8
CVE-2022-23511

A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instance…

Fix: 1.247355+
Fix from $1,600 2022-12-12
Opensearch MEDIUM 6.3
CVE-2022-41918

OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access cont…

Fix: 1.3.7 / 2.4.0+
Fix from $1,600 2022-11-15
Opensearch Notifications HIGH 8.7
CVE-2022-41906

OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Cu…

Fix: 2.2.1.0+
Fix from $1,950 2022-11-11
Amazon Web Services Redshift Java Database Connectivity Driver HIGH 8.1
CVE-2022-41828

In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class t…

Fix: 2.1.0.8+
Fix from $1,950 2022-09-29
Fhir Works On Aws Authz Smart MEDIUM 6.5
CVE-2022-39230

fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Versions 3.1.1 and 3.1.2 are subject…

Fix: 3.1.3+
Fix from $1,600 2022-09-23
Opensearch HIGH 7.5
CVE-2022-35980

OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security…

Patch available
Fix from $1,950 2022-08-12
Aws Sdk Java MEDIUM 6.5
CVE-2022-31159

The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` m…

Fix: after 1.12.260
Fix from $1,600 2022-07-15
Opensearch HIGH 8.8
CVE-2022-31115

opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used inst…

Fix: 2.0.2+
Fix from $1,950 2022-06-30
Hotpatch HIGH 7.0
CVE-2022-33915

Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead …

Fix: 1.3.5+
Fix from $1,950 2022-06-17
Amazon Ssm Agent HIGH 7.0
CVE-2022-29527

Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate p…

Fix: 3.1.1208.0+
Fix from $1,950 2022-04-20
Log4jhotpatch HIGH 8.8
CVE-2021-3100

The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to e…

Fix: 1.1-13+
Fix from $1,950 2022-04-19
Log4jhotpatch HIGH 8.8
CVE-2022-0070

Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the …

Fix: 1.1-16+
Fix from $1,950 2022-04-19
Aws Client Vpn HIGH 7.0
CVE-2022-25165

An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows …

No fix yet
Fix from $1,950 2022-04-14
Aws Client Vpn MEDIUM 5.0
CVE-2022-25166

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file …

No fix yet
Fix from $1,600 2022-04-14
Awsui\/components React MEDIUM 6.1
CVE-2022-24709

@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface developme…

Fix: 3.0.367+
Fix from $1,600 2022-02-24