Skip to main content

Vendor archive

amazon CVEs

Beta · best-effort

188 CVEs tagged to vendor amazon19 Critical, 89 High, 76 Medium, 4 Low, 0 Unrated.

CVE-2026-14265

Published Jul 1, 2026

Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the…

CVSS 7.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-13763

Published Jun 29, 2026

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via c…

CVSS 7.9 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-13762

Published Jun 29, 2026

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/…

CVSS 7.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10591

Published Jun 2, 2026

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via…

CVSS 8.6 · High
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-9255

Published May 22, 2026

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without us…

CVSS 8.4 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-7461

Published Apr 30, 2026

Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-7426

Published Apr 29, 2026

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-7425

Published Apr 29, 2026

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of s…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-7424

Published Apr 29, 2026

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, D…

CVSS 7.2 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-7423

Published Apr 29, 2026

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device cra…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-7422

Published Apr 29, 2026

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Et…

CVSS 7.1 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-6968

Published Apr 24, 2026

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output dire…

CVSS 7.1 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-6967

Published Apr 24, 2026

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing au…

CVSS 7.1 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-6966

Published Apr 24, 2026

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF…

CVSS 7.0 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-6437

Published Apr 17, 2026

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with Per…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-5747

Published Apr 8, 2026

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges…

CVSS 8.7 · High
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2026-5709

Published Apr 6, 2026

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitr…

CVSS 7.7 · High
evidence mentions
4
Buzz score
35.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5708

Published Apr 6, 2026

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authentica…

CVSS 8.7 · High
evidence mentions
4
Buzz score
35.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5707

Published Apr 6, 2026

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remot…

CVSS 8.7 · High
evidence mentions
4
Buzz score
35.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5485

Published Apr 3, 2026

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by usi…

CVSS 7.3 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort
Showing 1-25 of 188 CVEsPage 1 of 8