Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.59%—Amazon Link Project Amazon Link30/5/202217/6/2026
The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
ModificadaAlta (7.8)0.48%—Insightsoftware Magnitude Simba Amazon Redshift Jdbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code. NOTE: this is different from CVE-2022-29972.
ModificadaAlta (7.8)0.48%—Insightsoftware Magnitude Simba Amazon Athena Jdbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971.
ModificadaAlta (7.8)3.7%—Insightsoftware Magnitude Simba Amazon Redshift Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.
ModificadaAlta (7.8)0.37%—Insightsoftware Magnitude Simba Amazon Athena Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena ODBC Driver 1.1.1 through 1.1.x before 1.1.17 may allow a local user to execute arbitrary code.
ModificadaAlta (7)0.30%—Amazon SSM Agent20/4/202217/6/2026
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.
ModificadaAlta (8.8)0.38%—Amazon Log4jhotpatch19/4/202217/6/2026
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
ModificadaAlta (8.8)0.37%—Amazon Log4jhotpatch19/4/202217/6/2026
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
ModificadaMedia (5)1.5%—Amazon AWS Client VPN14/4/202217/6/2026
An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and…
ModificadaAlta (7)0.53%—Amazon AWS Client VPN14/4/202217/6/2026
An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows parameters outside of the AWS VPN Client allow list to be injected into the configuration file prior to the AWS VPN Client service (running as SYSTEM) processing the…
ModificadaMedia (6.1)0.69%—Amazon Awsui/components-react24/2/202217/6/2026
@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to…
ModificadaCrítica (9.8)3.3%—Amazon Echo DOT Firmware24/2/202217/6/2026
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus…
ModificadaCrítica (9.8)1.6%—Amazon AWS Opensearch12/12/202117/6/2026
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
ModificadaAlta (7.8)2.5%💥 PoCAmazon Sockeye8/12/202117/6/2026
Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, which can be made to execute arbitrary code embedded in config files. An attacker can add malicious…
ModificadaAlta (8.8)0.55%—Amazon Workspaces7/12/202117/6/2026
Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
ModificadaAlta (8.8)0.48%—Amazon Workspaces7/12/202117/6/2026
Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
ModificadaAlta (7.2)0.64%—Amazon WEB Services Aws-c-ioAmazon WEB Services Internet OF Things Device Software Development KIT V223/11/202117/6/2026
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on macOS systems. Additionally, SNI validation is also not enabled when the CA has been “overridden”. TLS handshakes will thus succeed if the peer can be verified…
ModificadaAlta (8.8)0.39%—Amazon WEB Services Aws-c-ioAmazon WEB Services Internet OF Things Device Software Development KIT V223/11/202117/6/2026
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied CA or the system’s default trust-store. Attackers with…
ModificadaAlta (8.8)0.39%—Amazon WEB Services Internet OF Things Device Software Development KIT V223/11/202117/6/2026
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.3) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust…
ModificadaAlta (8.8)0.41%—Amazon WEB Services Aws-c-ioAmazon WEB Services Internet OF Things Device Software Development KIT V223/11/202117/6/2026
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.1) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust…
ModificadaAlta (7.8)0.34%—Amazon Freertos17/11/202117/6/2026
FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ability to execute injected code to achieve further privilege…
ModificadaMedia (6.5)1.3%—Amazon Tough19/10/202117/6/2026
Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize delegated role names when caching a repository, or when loading a repository from the filesystem. When the repository is cached or loaded,…
ModificadaAlta (8.1)1.1%—Amazon Tough19/10/202117/6/2026
Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize target names when caching a repository, or when saving specific targets to an output directory. When targets are cached or saved, files could…
ModificadaAlta (8.8)7.5%—Amazon AWS Workspaces22/9/202117/6/2026
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code execution because of the Chromium Embedded Framework (CEF) --gpu-launcher argument. This is fixed in 3.1.9.
ModificadaAlta (8.6)6.9%—Amazon Kindle Firmware1/9/202117/6/2026
Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privileges to root.