VYPR

Vendor CVEs

AWS

All CVEs

106 total · sorted by risk
  • CVE-2026-13763CriJun 29, 2026
    risk 0.00cvss 9.8epss 0.00

    Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is…

  • CVE-2026-13762CriJun 29, 2026
    risk 0.00cvss 9.8epss 0.00

    Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. …

  • CVE-2025-14503HigDec 15, 2025
    risk 0.00cvss 7.2epss 0.01

    An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via role assumption. The sample code for the EKS environment provisioning role is configured to trust the account root principal, which…

  • CVE-2024-37293HigJun 11, 2024
    risk 0.00cvss 7.5epss 0.00

    The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined…

  • CVE-2023-36467HigJun 28, 2023
    risk 0.00cvss 8.0epss 0.01

    AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a…

  • CVE-2019-14652MedFeb 13, 2020
    risk 0.00cvss 6.1epss 0.01

    explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.

Page 3 of 3