Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.6)8.4%—Amazon Kindle Firmware1/9/202117/6/2026
Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBig2Image::expand() and results in a memory corruption that leads to code execution when parsing a crafted PDF book.
ModificadaCrítica (9.8)0.71%—Amazon Cloudfront12/8/202117/6/2026
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.
ModificadaMedia (4.2)0.28%—Amazon Echo DOT Firmware24/7/202117/6/2026
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a…
ModificadaAlta (7.1)0.89%—Amazon Open Distro6/5/202117/6/2026
An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.
ModificadaCrítica (9.8)1.3%—Amazon Freertos3/5/202117/6/2026
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.
ModificadaCrítica (9.8)1.4%—Amazon Freertos22/4/202117/6/2026
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.
ModificadaCrítica (9.8)1.4%—Amazon Freertos22/4/202117/6/2026
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.
ModificadaCrítica (9.1)1.7%—Bestit Amazon PAY26/2/202117/6/2026
best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor.
ModificadaMedia (5.9)0.52%—Tenable Nessus Amazon Machine Image6/2/202117/6/2026
Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
ModificadaCrítica (9.8)2.1%—Amazon AWS SDK FOR JavasciptAmazon AWS Shared Configuration File Loader19/1/202117/6/2026
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the…
ModificadaAlta (8.1)0.40%—Amazon AWS Encryption SDK16/11/202017/6/2026
A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305) used by the SDKs to encrypt messages, an attacker can craft a unique cyphertext…
ModificadaAlta (7.5)1.7%—Amazon Firecracker16/10/202017/6/2026
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.
ModificadaBaja (2.5)0.23%—Amazon AWS S3 Crypto SDK11/8/202017/6/2026
A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-CTR. Using this in combination with a…
ModificadaMedia (5.6)0.35%—Amazon AWS S3 Crypto SDK11/8/202017/6/2026
A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to the target's S3 bucket and can observe whether or not an…
ModificadaMedia (5.9)1.7%—Amazon Firecracker4/8/202017/6/2026
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network interface, and an availability problem for the microVM network interface on which the issue is…
ModificadaAlta (8.6)1.4%—Amazon Tough9/7/202017/6/2026
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A fix is available in…
ModificadaMedia (4.3)0.65%—Jenkins Amazon EC26/5/202017/6/2026
A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
ModificadaMedia (5.6)0.41%—Jenkins Amazon EC26/5/202017/6/2026
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.
ModificadaMedia (4.3)0.64%—Jenkins Amazon EC26/5/202017/6/2026
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.
ModificadaMedia (5.6)0.69%—Jenkins Amazon EC26/5/202017/6/2026
Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.
ModificadaMedia (4.9)0.34%—Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+205/5/202017/6/2026
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal.
ModificadaMedia (4.9)0.34%—Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+205/5/202017/6/2026
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
ModificadaMedia (4.9)0.72%—Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+205/5/202017/6/2026
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell…
ModificadaAlta (8.8)2.3%—Jenkins Amazon WEB Services Serverless Application Model16/4/202017/6/2026
Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
ModificadaMedia (6.1)1.0%—Amazon AWS Javascript S3 Explorer13/2/202017/6/2026
explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.