CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Amazon Remove filter Clear all
CVE-2026-104020 HIGH

Uncontrolled recursion in the Ion reader in Amazon Ion Python

CVSS 8.7 EPSS 0.44% Oct 1, 2026
CVE-2026-95985 HIGH

Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

CVSS 8.6 EPSS 0.14% Sep 24, 2026
CVE-2026-94384 MEDIUM

Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda

CVSS 6.4 EPSS 0.32% Sep 22, 2026
CVE-2023-32803 HIGH

ca-certificates: ca-certificates: Failure to remove TrustCor root certificates

CVSS 8.1 EPSS 0.18% Sep 14, 2026
CVE-2026-89332 MEDIUM

Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration

CVSS 6.7 EPSS 0.18% Sep 11, 2026
CVE-2026-18061 MEDIUM

Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin

CVSS 6.0 EPSS 0.27% Sep 11, 2026
CVE-2026-85228 HIGH

Integer overflow in tensor buffer validation in Deep Java Library

CVSS 8.8 EPSS 0.54% Sep 10, 2026
CVE-2026-85787 HIGH

An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server

CVSS 7.1 EPSS 0.34% Sep 4, 2026
CVE-2026-85786 HIGH

Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java

CVSS 8.7 EPSS 0.58% Sep 4, 2026
CVE-2026-85656 HIGH

OS command injection in Amazon log4j-cve-2021-44228-hotpatch

CVSS 8.5 EPSS 1.08% Sep 4, 2026
CVE-2026-85654 HIGH

Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server

CVSS 7.1 EPSS 0.21% Sep 4, 2026
CVE-2026-84851 HIGH

Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6

CVSS 8.7 EPSS 0.61% Sep 2, 2026
CVE-2026-83497 HIGH

Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination

CVSS 8.7 EPSS 0.96% Aug 31, 2026
CVE-2026-81849 HIGH

Path traversal in the aws:downloadContent plugin in amazon-ssm-agent

CVSS 8.7 EPSS 0.90% Aug 28, 2026
CVE-2026-81838 MEDIUM

Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)

CVSS 6.8 EPSS 0.20% Aug 27, 2026
CVE-2026-78379 CRITICAL

Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools

CVSS 9.2 EPSS 0.57% Aug 25, 2026
CVE-2026-77237 HIGH

Missing type validation in xQueueAddToSet in FreeRTOS-Kernel

CVSS 8.2 EPSS 0.18% Aug 21, 2026
CVE-2026-77236 HIGH

Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel

CVSS 8.3 EPSS 0.16% Aug 21, 2026
CVE-2026-77235 HIGH

Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel

CVSS 8.3 EPSS 0.16% Aug 21, 2026
CVE-2026-77234 CRITICAL

Improper input validation in FreeRTOS-Kernel timer command handling

CVSS 9.3 EPSS 0.17% Aug 21, 2026
CVE-2026-19643 MEDIUM

Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms

CVSS 6.0 EPSS 0.56% Aug 12, 2026
CVE-2026-19642 MEDIUM

Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp

CVSS 6.0 EPSS 0.50% Aug 12, 2026
CVE-2026-18954 MEDIUM

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server

CVSS 5.7 EPSS 0.16% Aug 5, 2026
CVE-2026-18953 MEDIUM

Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server

CVSS 6.3 EPSS 0.18% Aug 5, 2026
CVE-2026-18657 HIGH

Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows

CVSS 8.5 EPSS 0.23% Aug 4, 2026

Showing 1 to 25 CVEs · page 1 (more available)