Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-35560 Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-m… Athena Odbc 2.1.0.0+ Fix from $1,6002026-04-03 HIGH 7.8 CVE-2026-35558 Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor t… Athena Odbc 2.1.0.0+ Fix from $1,9502026-04-03 MEDIUM 6.5 CVE-2026-35559 Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by … Athena Odbc 2.1.0.0+ Fix from $1,6002026-04-03 HIGH 7.5 CVE-2026-4269 A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during th… Bedrock Agentcore Starter Toolkit 0.1.13+ Fix from $1,9502026-03-16 MEDIUM 5.5 CVE-2026-4270 Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all pla… Aws Api Mcp Server 1.3.9+ Fix from $1,6002026-03-16 HIGH 7.5 CVE-2026-3338 Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objec… Aws Lc Sys 0.38.0 / 1.69.0+ Fix from $1,9502026-03-02 MEDIUM 5.9 CVE-2026-3337 Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via… Aws Lc Fips Sys 0.13.12 / 0.38.0+ Fix from $1,6002026-03-02 HIGH 7.5 CVE-2026-3336 Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing P… Aws Lc Sys 0.38.0 / 1.69.0+ Fix from $1,9502026-03-02 MEDIUM 6.0 CVE-2026-1386 A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host u… Firecracker 1.13.2+ Fix from $1,6002026-01-23 HIGH 7.8 CVE-2026-0830 Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE b… Kiro Ide 0.6.18+ Fix from $1,9502026-01-09 HIGH 7.2 CVE-2025-14503 An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via ro… Harmonix 0.4.2+ Fix from $1,9502025-12-15 HIGH 7.5 CVE-2025-9624 A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all … Opensearch 3.3.0+ Fix from $1,9502025-11-25 HIGH 7.4 CVE-2025-62371 OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins … Opensearch Data Prepper 2.12.2+ Fix from $1,9502025-10-15 MEDIUM 5.4 CVE-2025-11616 A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of ce… Freertos Plus Tcp 4.3.4+ Fix from $1,6002025-10-10 MEDIUM 5.4 CVE-2025-11617 A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with inc… Freertos Plus Tcp 4.3.4+ Fix from $1,6002025-10-10 MEDIUM 5.5 CVE-2025-2598 When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration proper… Aws Cloud Development Kit 2.178.2+ Fix from $1,6002025-03-21 HIGH 8.1 CVE-2025-23206 The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it thro… Aws Cloud Development Kit 2.177.0+ Fix from $1,9502025-01-17 HIGH 8.0 CVE-2024-12745 A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_col… Redshift Connector Mitigation only Fix from $1,9502024-12-24 HIGH 8.0 CVE-2024-12746 A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLCol… Redshift Odbc Driver Mitigation only Fix from $1,9502024-12-24 HIGH 8.0 CVE-2024-12744 A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColum… Amazon Web Services Redshift Java Database Connectivity Driver Mitigation only Fix from $1,9502024-12-24 MEDIUM 6.9 CVE-2024-55886 OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerabili… Opensearch Data Prepper 2.10.2+ Fix from $1,6002024-12-12 MEDIUM 6.3 CVE-2024-52311 Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution… Data.all 2.6.1+ Fix from $1,6002024-11-09 MEDIUM 5.4 CVE-2024-52312 Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations ag… Data.all 2.6.1+ Fix from $1,6002024-11-09 MEDIUM 6.4 CVE-2024-45037 The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own ap… Aws Cloud Development Kit 2.148.1+ Fix from $1,6002024-08-27 HIGH 8.1 CVE-2024-38373 FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the … Freertos Plus Tcp 4.1.1+ Fix from $1,9502024-06-24 HIGH 7.8 CVE-2024-37293 The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization.… Aws Deployment Framework 4.0.0+ Fix from $1,9502024-06-11 CRITICAL 9.8 CVE-2024-28056 Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentica… Amplify Cli 12.10.1+ Fix from $2,3002024-04-15 HIGH 7.8 CVE-2024-28115 FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local priv… Freertos 10.6.2+ Fix from $1,9502024-03-07 MEDIUM 5.9 CVE-2024-27350 Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: som… Fire Os 7.6.6.9 / 8.1.0.3+ Fix from $1,6002024-02-26 MEDIUM 5.3 CVE-2024-23680 AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures. Aws Encryption Sdk 1.9.0 / 2.2.0+ Fix from $1,6002024-01-19