Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2026-19642
An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or …
Aws Software Development Kit
No fix yet
MEDIUM 5.3
CVE-2026-19643
An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user t…
Aws Software Development Kit
No fix yet
MEDIUM 5.5
CVE-2026-18954
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clie…
Documentdb Mcp Server
1.0.12+
HIGH 8.8
CVE-2026-18953
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 m…
Aws Transform Mcp Server
0.1.5+
HIGH 7.8
CVE-2026-18656
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary cod…
Kiro Ide
No fix yet
HIGH 7.8
CVE-2026-18657
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code…
Kiro Cli
No fix yet
HIGH 8.8
CVE-2026-18245
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrar…
Amplify Codegen Ui
2.20.6+
HIGH 7.5
CVE-2026-18140
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes fr…
Aws Smithy Json
0.62.7+
HIGH 8.8
CVE-2026-14265
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an a…
Advanced Jdbc Wrapper
4.0.1+
CRITICAL 9.8
CVE-2026-13762
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule bod…
Cloudfront
Mitigation only
CRITICAL 9.8
CVE-2026-13763
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF mana…
Application Load Balancer
Mitigation only
HIGH 8.8
CVE-2026-10591
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to e…
Kiro Ide
0.11+
HIGH 7.8
CVE-2026-9255
Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, includ…
Kiro Cli
1.28.0+
HIGH 7.2
CVE-2026-7461
Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows befor…
Amazon Ecs Container Agent
1.103.0+
HIGH 8.1
CVE-2026-7426
Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an ad…
Freertos Plus Tcp
4.2.6 / 4.4.1+
MEDIUM 6.5
CVE-2026-7425
Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent networ…
Freertos Plus Tcp
4.2.6 / 4.4.1+
HIGH 8.1
CVE-2026-7424
Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the devic…
Freertos Plus Tcp
4.2.6 / 4.4.1+
MEDIUM 6.5
CVE-2026-7422
Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size…
Freertos Plus Tcp
4.2.6 / 4.4.1+
MEDIUM 6.5
CVE-2026-7423
Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a…
Freertos Plus Tcp
4.2.6 / 4.4.1+
MEDIUM 6.5
CVE-2026-6967
Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated u…
Tough
0.15.0 / 0.22.0+
MEDIUM 6.5
CVE-2026-6968
Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write file…
Tough
0.15.0 / 0.22.0+
MEDIUM 6.5
CVE-2026-6966
Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenti…
Tough
0.15.0 / 0.22.0+
MEDIUM 6.5
CVE-2026-6437
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remot…
Efs Csi Driver
3.0.1+
HIGH 7.5
CVE-2026-5747
An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local gu…
Firecracker
after 1.14.3
HIGH 8.8
CVE-2026-5707
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through …
Research And Engineering Studio
2026.03+
HIGH 8.8
CVE-2026-5708
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 202…
Research And Engineering Studio
2026.03+
HIGH 8.8
CVE-2026-5709
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authent…
Research And Engineering Studio
2026.03+
CRITICAL 9.8
CVE-2026-35561
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow …
Athena Odbc
2.1.0.0+
HIGH 7.8
CVE-2026-5485
OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to…
Athena Odbc
2.0.5.1+
HIGH 7.5
CVE-2026-35562
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a de…
Athena Odbc
2.1.0.0+