VYPR

Vendor CVEs

AWS

All CVEs

119 total · sorted by risk
  • CVE-2025-14759MedDec 17, 2025
    risk 0.27cvss 5.3epss 0.00

    Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's…

  • CVE-2025-8217MedJul 30, 2025
    risk 0.26cvss 4.0epss 0.00

    The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which…

  • CVE-2025-12815MedNov 6, 2025
    risk 0.21cvss 4.3epss 0.00

    An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview…

  • CVE-2025-9039MedAug 14, 2025
    risk 0.21cvss 4.3epss 0.00

    We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accessed off-host by another instance if the instances are in the same security group or if their security groups allow incoming connections that include the port…

  • CVE-2025-1969MedMar 4, 2025
    risk 0.21cvss 4.3epss 0.00

    Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for…

  • CVE-2022-46174MedDec 28, 2022
    risk 0.20cvss 4.2epss 0.01

    efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to…

  • CVE-2026-18481HigJul 31, 2026
    risk 0.00cvss 7.3epss 0.00

    Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a …

  • CVE-2026-16318MedJul 21, 2026
    risk 0.00cvss 5.3epss 0.00

    The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second…

  • CVE-2026-16317MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer…

  • CVE-2026-15415MedJul 17, 2026
    risk 0.00cvss 5.5epss 0.00

    AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a…

  • CVE-2026-15737MedJul 16, 2026
    risk 0.00cvss 5.7epss 0.00

    AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK…

  • CVE-2026-15643HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server…

  • CVE-2026-14904MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.01

    AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey…

  • CVE-2026-13763CriJun 29, 2026
    risk 0.00cvss 9.8epss 0.01

    Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is…

  • CVE-2026-13762CriJun 29, 2026
    risk 0.00cvss 9.8epss 0.01

    Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. …

  • CVE-2025-14503HigDec 15, 2025
    risk 0.00cvss 7.2epss 0.01

    An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via role assumption. The sample code for the EKS environment provisioning role is configured to trust the account root principal, which…

  • CVE-2024-37293HigJun 11, 2024
    risk 0.00cvss 7.5epss 0.00

    The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined…

  • CVE-2023-36467HigJun 28, 2023
    risk 0.00cvss 8.0epss 0.01

    AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a…

  • CVE-2019-14652MedFeb 13, 2020
    risk 0.00cvss 6.1epss 0.01

    explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.

Page 3 of 3