Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-21634 Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for a… Ion 1.10.5+ Fix from $1,9502024-01-03 CRITICAL 9.0 CVE-2023-50928 "Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Au… Awslabs Sandbox Accounts For Events 1.1.0+ Fix from $2,3002023-12-22 HIGH 7.8 CVE-2021-27504 Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an intege… Freertos 4.10.03 / 4.40.00+ Fix from $1,9502023-11-21 MEDIUM 5.4 CVE-2023-45807 OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 2021. There is an issue with the… Opensearch 1.3.14.0 / 2.11.0.0+ Fix from $1,6002023-10-16 HIGH 8.8 CVE-2023-36467 AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1… Aws Dataall after 1.5.1 Fix from $1,9502023-06-28 HIGH 8.8 CVE-2023-35165 AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through … Aws Cloud Development Kit 1.202.0 / 2.80.0+ Fix from $1,9502023-06-23 HIGH 7.6 CVE-2023-33248 Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relev… Alexa No fix yet Fix from $1,9502023-05-24 MEDIUM 5.9 CVE-2023-31141 OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue… Opensearch 1.3.10 / 2.7.0+ Fix from $1,6002023-05-08 HIGH 8.8 CVE-2023-1385 Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthoriz… Fire Os 6.2.9.5 / 7.6.3.3+ Fix from $1,9502023-05-03 MEDIUM 6.1 CVE-2023-1384 The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run Th… Fire Os 6.2.9.5 / 7.6.3.3+ Fix from $1,6002023-05-03 MEDIUM 5.5 CVE-2023-30610 aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` impl… Aws Sigv4 Mitigation only Fix from $1,6002023-04-19 MEDIUM 5.3 CVE-2023-25806 OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the au… Opensearch 1.3.9 / 2.6.0+ Fix from $1,6002023-03-02 HIGH 8.8 CVE-2023-23612 OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained from the Identity Provider (Id… Opensearch 1.3.8 / 2.5.0+ Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2023-23613 OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implementation of field-level secur… Opensearch 1.3.8 / 2.5.0+ Fix from $1,6002023-01-26 CRITICAL 9.8 CVE-2022-4725 A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-co… Aws Software Development Kit 2.59.1+ Fix from $2,3002022-12-27 MEDIUM 6.8 CVE-2022-23511 A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instance… Cloudwatch Agent 1.247355+ Fix from $1,6002022-12-12 MEDIUM 6.3 CVE-2022-41918 OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access cont… Opensearch 1.3.7 / 2.4.0+ Fix from $1,6002022-11-15 HIGH 8.7 CVE-2022-41906 OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Cu… Opensearch Notifications 2.2.1.0+ Fix from $1,9502022-11-11 HIGH 8.1 CVE-2022-41828 In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class t… Amazon Web Services Redshift Java Database Connectivity Driver 2.1.0.8+ Fix from $1,9502022-09-29 MEDIUM 6.5 CVE-2022-39230 fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Versions 3.1.1 and 3.1.2 are subject… Fhir Works On Aws Authz Smart 3.1.3+ Fix from $1,6002022-09-23 HIGH 7.5 CVE-2022-35980 OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security… Opensearch Patch available Fix from $1,9502022-08-12 MEDIUM 6.5 CVE-2022-31159 The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` m… Aws Sdk Java after 1.12.260 Fix from $1,6002022-07-15 HIGH 8.8 CVE-2022-31115 opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used inst… Opensearch 2.0.2+ Fix from $1,9502022-06-30 HIGH 7.0 CVE-2022-33915 Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead … Hotpatch 1.3.5+ Fix from $1,9502022-06-17 HIGH 7.0 CVE-2022-29527 Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate p… Amazon Ssm Agent 3.1.1208.0+ Fix from $1,9502022-04-20 HIGH 8.8 CVE-2021-3100 The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to e… Log4jhotpatch 1.1-13+ Fix from $1,9502022-04-19 HIGH 8.8 CVE-2022-0070 Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the … Log4jhotpatch 1.1-16+ Fix from $1,9502022-04-19 HIGH 7.0 CVE-2022-25165 An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows … Aws Client Vpn No fix yet Fix from $1,9502022-04-14 MEDIUM 5.0 CVE-2022-25166 An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file … Aws Client Vpn No fix yet Fix from $1,6002022-04-14 MEDIUM 6.1 CVE-2022-24709 @awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface developme… Awsui\/components React 3.0.367+ Fix from $1,6002022-02-24