← All vendors

amazon

29 known vulnerabilities affecting amazon products.

Products

athena_odbc 6 freertos 4 kiro_ide 3 research_and_engineering_studio 3 kiro_cli 2 aws_software_development_kit 2 aws_transform_mcp_server 1 aws-smithy-json 1 diagram-as-code 1 documentdb_mcp_server 1 firecracker 1 aws_amplify_cli 1 advanced_jdbc_wrapper 1 amazon_linux 1 amplify_codegen_ui 1

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-31431 Act now 99.9% 7.8 In the Linux kernel, the following vulnerability has been resolved: crypto: alg…
CVE-2024-28056 High 1.7% 9.8 Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust poli…
CVE-2026-5709 Medium 1.1% 8.8 Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio …
CVE-2026-5707 Medium 1.0% 8.8 Unsanitized input in an OS command in the virtual desktop session name handling …
CVE-2026-5708 Medium 0.8% 8.8 Unsanitized control of user-modifiable attributes in the session creation compon…
CVE-2026-5485 Medium 0.7% 7.8 OS command injection in the browser-based authentication component in Amazon Ath…
CVE-2026-18245 Medium 0.7% 9.0 Improper control of code generation in Amazon @aws-amplify/codegen-ui-react befo…
CVE-2026-10591 Medium 0.7% 8.8 Insufficient access control restrictions in the file write tool in Amazon Kiro I…
CVE-2026-35561 Medium 0.5% 7.4 Insufficient authentication security controls in the browser-based authenticatio…
CVE-2026-18140 Medium 0.4% 7.5 Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runti…
CVE-2026-35562 Medium 0.4% 7.5 Allocation of resources without limits in the parsing components in Amazon Athen…
CVE-2026-35558 Medium 0.3% 7.8 Improper neutralization of special elements in the authentication components in …
CVE-2026-35560 Medium 0.3% 7.4 Improper certificate validation in the identity provider connection components i…
CVE-2026-18953 Medium 0.2% 8.6 Improper limitation of a pathname to a restricted directory in the get_resource …
CVE-2026-5747 Medium 0.2% 7.5 An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 t…
CVE-2026-18657 Medium 0.2% 7.8 An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows…
CVE-2026-18656 Medium 0.2% 7.8 An uncontrolled search path element in Kiro IDE before version 1.0.228 on Window…
CVE-2026-81838 Medium 0.1% 7.1 A relative path traversal issue in the zip extraction functionality in AWS diagr…
CVE-2026-77234 Medium 0.1% 8.8 Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unpriv…
CVE-2026-9255 Medium 0.1% 7.8 Missing input source validation in the tool authorization prompt in Kiro CLI bef…
CVE-2026-77236 Medium 0.1% 7.3 Missing minimum size validation in secure context allocation in FreeRTOS-Kernel …
CVE-2026-77235 Medium 0.1% 7.3 Missing privilege verification in the secure context cleanup handler in FreeRTOS…
CVE-2026-19643 Low 0.3% 5.3 An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1…
CVE-2026-19642 Low 0.3% 5.9 An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before …
CVE-2026-35559 Low 0.3% 6.5 Out-of-bounds write in the query processing components in Amazon Athena ODBC dri…
CVE-2026-18061 Low 0.3% 5.9 Improper restriction of XML external entity references in the RemoteQueryCachePl…
CVE-2026-89332 Low 0.2% 5.5 Inclusion of functionality from an untrusted control sphere in the Kiro Powers f…
CVE-2026-77237 Low 0.1% 6.5 Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel bef…
CVE-2026-18954 Low 0.1% 5.5 Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs Docu…