Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2026-35560
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-m…
Athena Odbc
2.1.0.0+
HIGH 7.8
CVE-2026-35558
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor t…
Athena Odbc
2.1.0.0+
MEDIUM 6.5
CVE-2026-35559
Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by …
Athena Odbc
2.1.0.0+
HIGH 7.5
CVE-2026-4269
A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during th…
Bedrock Agentcore Starter Toolkit
0.1.13+
MEDIUM 5.5
CVE-2026-4270
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all pla…
Aws Api Mcp Server
1.3.9+
HIGH 7.5
CVE-2026-3338
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objec…
Aws Lc Sys
0.38.0 / 1.69.0+
MEDIUM 5.9
CVE-2026-3337
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via…
Aws Lc Fips Sys
0.13.12 / 0.38.0+
HIGH 7.5
CVE-2026-3336
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing P…
Aws Lc Sys
0.38.0 / 1.69.0+
MEDIUM 6.0
CVE-2026-1386
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host u…
Firecracker
1.13.2+
HIGH 7.8
CVE-2026-0830
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE b…
Kiro Ide
0.6.18+
HIGH 7.2
CVE-2025-14503
An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via ro…
Harmonix
0.4.2+
HIGH 7.5
CVE-2025-9624
A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.
This issue affects all …
Opensearch
3.3.0+
HIGH 7.4
CVE-2025-62371
OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins …
Opensearch Data Prepper
2.12.2+
MEDIUM 5.4
CVE-2025-11616
A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of ce…
Freertos Plus Tcp
4.3.4+
MEDIUM 5.4
CVE-2025-11617
A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with inc…
Freertos Plus Tcp
4.3.4+
MEDIUM 5.5
CVE-2025-2598
When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration proper…
Aws Cloud Development Kit
2.178.2+
HIGH 8.1
CVE-2025-23206
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it thro…
Aws Cloud Development Kit
2.177.0+
HIGH 8.0
CVE-2024-12745
A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_col…
Redshift Connector
Mitigation only
HIGH 8.0
CVE-2024-12746
A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLCol…
Redshift Odbc Driver
Mitigation only
HIGH 8.0
CVE-2024-12744
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColum…
Amazon Web Services Redshift Java Database Connectivity Driver
Mitigation only
MEDIUM 6.9
CVE-2024-55886
OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerabili…
Opensearch Data Prepper
2.10.2+
MEDIUM 6.3
CVE-2024-52311
Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution…
Data.all
2.6.1+
MEDIUM 5.4
CVE-2024-52312
Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations ag…
Data.all
2.6.1+
MEDIUM 6.4
CVE-2024-45037
The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own ap…
Aws Cloud Development Kit
2.148.1+
HIGH 8.1
CVE-2024-38373
FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the …
Freertos Plus Tcp
4.1.1+
HIGH 7.8
CVE-2024-37293
The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization.…
Aws Deployment Framework
4.0.0+
CRITICAL 9.8
CVE-2024-28056
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentica…
Amplify Cli
12.10.1+
HIGH 7.8
CVE-2024-28115
FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local priv…
Freertos
10.6.2+
MEDIUM 5.9
CVE-2024-27350
Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: som…
Fire Os
7.6.6.9 / 8.1.0.3+
MEDIUM 5.3
CVE-2024-23680
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
Aws Encryption Sdk
1.9.0 / 2.2.0+