Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-21634
Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for a…
Ion
1.10.5+
CRITICAL 9.0
CVE-2023-50928
"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Au…
Awslabs Sandbox Accounts For Events
1.1.0+
HIGH 7.8
CVE-2021-27504
Texas Instruments devices running FREERTOS, malloc returns a valid
pointer to a small buffer on extremely large values, which can trigger
an intege…
Freertos
4.10.03 / 4.40.00+
MEDIUM 5.4
CVE-2023-45807
OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 2021. There is an issue with the…
Opensearch
1.3.14.0 / 2.11.0.0+
HIGH 8.8
CVE-2023-36467
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1…
Aws Dataall
after 1.5.1
HIGH 8.8
CVE-2023-35165
AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through …
Aws Cloud Development Kit
1.202.0 / 2.80.0+
HIGH 7.6
CVE-2023-33248
Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relev…
Alexa
No fix yet
MEDIUM 5.9
CVE-2023-31141
OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue…
Opensearch
1.3.10 / 2.7.0+
HIGH 8.8
CVE-2023-1385
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthoriz…
Fire Os
6.2.9.5 / 7.6.3.3+
MEDIUM 6.1
CVE-2023-1384
The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run
Th…
Fire Os
6.2.9.5 / 7.6.3.3+
MEDIUM 5.5
CVE-2023-30610
aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` impl…
Aws Sigv4
Mitigation only
MEDIUM 5.3
CVE-2023-25806
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the au…
Opensearch
1.3.9 / 2.6.0+
HIGH 8.8
CVE-2023-23612
OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained from the Identity Provider (Id…
Opensearch
1.3.8 / 2.5.0+
MEDIUM 6.5
CVE-2023-23613
OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implementation of field-level secur…
Opensearch
1.3.8 / 2.5.0+
CRITICAL 9.8
CVE-2022-4725
A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-co…
Aws Software Development Kit
2.59.1+
MEDIUM 6.8
CVE-2022-23511
A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instance…
Cloudwatch Agent
1.247355+
MEDIUM 6.3
CVE-2022-41918
OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access cont…
Opensearch
1.3.7 / 2.4.0+
HIGH 8.7
CVE-2022-41906
OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Cu…
Opensearch Notifications
2.2.1.0+
HIGH 8.1
CVE-2022-41828
In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class t…
Amazon Web Services Redshift Java Database Connectivity Driver
2.1.0.8+
MEDIUM 6.5
CVE-2022-39230
fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Versions 3.1.1 and 3.1.2 are subject…
Fhir Works On Aws Authz Smart
3.1.3+
HIGH 7.5
CVE-2022-35980
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security…
Opensearch
Patch available
MEDIUM 6.5
CVE-2022-31159
The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` m…
Aws Sdk Java
after 1.12.260
HIGH 8.8
CVE-2022-31115
opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used inst…
Opensearch
2.0.2+
HIGH 7.0
CVE-2022-33915
Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead …
Hotpatch
1.3.5+
HIGH 7.0
CVE-2022-29527
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate p…
Amazon Ssm Agent
3.1.1208.0+
HIGH 8.8
CVE-2021-3100
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to e…
Log4jhotpatch
1.1-13+
HIGH 8.8
CVE-2022-0070
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the …
Log4jhotpatch
1.1-16+
HIGH 7.0
CVE-2022-25165
An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows …
Aws Client Vpn
No fix yet
MEDIUM 5.0
CVE-2022-25166
An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file …
Aws Client Vpn
No fix yet
MEDIUM 6.1
CVE-2022-24709
@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface developme…
Awsui\/components React
3.0.367+