Amazon
54 known vulnerabilities
Top Products
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged t
Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to
Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to exec
An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow
An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authentica
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated ac
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated a
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authentic
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 t
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to by
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remot
Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to ex
Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amaz
Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V
Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.
Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent netwo
Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adj
Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass
Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated si
Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0
Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-drive
An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and a
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Stud
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (
OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC drive
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0
Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0
A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote a
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >=
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configur
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verificatio
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine au
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain v
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on L
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge
Frequently Asked Questions
How many CVEs affect Amazon?
Amazon has 54 CVE records in our database, including 3 critical and 29 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Amazon vulnerabilities?
Amazon has 3 critical severity (CVSS 9.0+) and 29 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Amazon vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Amazon products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Amazon Vulnerabilities
CyberStrike scans your infrastructure for Amazon vulnerabilities and provides real-time remediation guidance.
Get Started