Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-19642 An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or … Aws Software Development Kit No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-19643 An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user t… Aws Software Development Kit No fix yet Fix from $4,0002026-08-12 MEDIUM 5.5 CVE-2026-18954 Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clie… Documentdb Mcp Server 1.0.12+ Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-18953 Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 m… Aws Transform Mcp Server 0.1.5+ Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-18656 An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary cod… Kiro Ide No fix yet Fix from $1,9502026-08-04 HIGH 7.8 CVE-2026-18657 An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code… Kiro Cli No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-18245 Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrar… Amplify Codegen Ui 2.20.6+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-18140 Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes fr… Aws Smithy Json 0.62.7+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-14265 Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an a… Advanced Jdbc Wrapper 4.0.1+ Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-13762 Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule bod… Cloudfront Mitigation only Fix from $2,3002026-06-29 CRITICAL 9.8 CVE-2026-13763 Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF mana… Application Load Balancer Mitigation only Fix from $2,3002026-06-29 HIGH 8.8 CVE-2026-10591 Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to e… Kiro Ide 0.11+ Fix from $1,9502026-06-02 HIGH 7.8 CVE-2026-9255 Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, includ… Kiro Cli 1.28.0+ Fix from $1,9502026-05-22 HIGH 7.2 CVE-2026-7461 Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows befor… Amazon Ecs Container Agent 1.103.0+ Fix from $1,9502026-04-30 HIGH 8.1 CVE-2026-7426 Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an ad… Freertos Plus Tcp 4.2.6 / 4.4.1+ Fix from $1,9502026-04-29 MEDIUM 6.5 CVE-2026-7425 Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent networ… Freertos Plus Tcp 4.2.6 / 4.4.1+ Fix from $1,6002026-04-29 HIGH 8.1 CVE-2026-7424 Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the devic… Freertos Plus Tcp 4.2.6 / 4.4.1+ Fix from $1,9502026-04-29 MEDIUM 6.5 CVE-2026-7422 Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size… Freertos Plus Tcp 4.2.6 / 4.4.1+ Fix from $1,6002026-04-29 MEDIUM 6.5 CVE-2026-7423 Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a… Freertos Plus Tcp 4.2.6 / 4.4.1+ Fix from $1,6002026-04-29 MEDIUM 6.5 CVE-2026-6967 Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated u… Tough 0.15.0 / 0.22.0+ Fix from $1,6002026-04-24 MEDIUM 6.5 CVE-2026-6968 Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write file… Tough 0.15.0 / 0.22.0+ Fix from $1,6002026-04-24 MEDIUM 6.5 CVE-2026-6966 Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenti… Tough 0.15.0 / 0.22.0+ Fix from $1,6002026-04-24 MEDIUM 6.5 CVE-2026-6437 Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remot… Efs Csi Driver 3.0.1+ Fix from $1,6002026-04-17 HIGH 7.5 CVE-2026-5747 An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local gu… Firecracker after 1.14.3 Fix from $1,9502026-04-08 HIGH 8.8 CVE-2026-5707 Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through … Research And Engineering Studio 2026.03+ Fix from $1,9502026-04-06 HIGH 8.8 CVE-2026-5708 Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 202… Research And Engineering Studio 2026.03+ Fix from $1,9502026-04-06 HIGH 8.8 CVE-2026-5709 Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authent… Research And Engineering Studio 2026.03+ Fix from $1,9502026-04-06 CRITICAL 9.8 CVE-2026-35561 Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow … Athena Odbc 2.1.0.0+ Fix from $2,3002026-04-03 HIGH 7.8 CVE-2026-5485 OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to… Athena Odbc 2.0.5.1+ Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-35562 Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a de… Athena Odbc 2.1.0.0+ Fix from $1,9502026-04-03