Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
430 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.60% | — | Apache-airflow-providers-amazon | 10/8/2026 | 16/9/2026 | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve… | |
| Pendiente de análisis | Alta (8.6) | 0.52% | — | Amazon Strands Agents ToolsAI | 6/8/2026 | 12/8/2026 | Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace… | |
| Analizada | Media (5.7) | 0.16% | — | Amazon Documentdb MCP Server | 5/8/2026 | 10/8/2026 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To… | |
| Analizada | Media (6.3) | 0.18% | — | Amazon AWS Transform MCP Server | 5/8/2026 | 10/8/2026 | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should… | |
| Analizada | Alta (8.5) | 0.23% | — | Amazon Kiro CLI | 4/8/2026 | 18/8/2026 | An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory. To… | |
| Analizada | Alta (8.5) | 0.22% | — | Amazon Kiro IDE | 4/8/2026 | 18/8/2026 | An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this… | |
| Pendiente de análisis | Alta (8.6) | 0.51% | — | Amazon BedrockAI | 4/8/2026 | 6/8/2026 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required. | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Amazon Strands Agents ToolsAI | 3/8/2026 | 4/8/2026 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue,… | |
| Pendiente de análisis | Alta (7.1) | 0.42% | — | Awslabs Amazon MQ MCP ServerAIAmazon MQAI | 3/8/2026 | 4/8/2026 | Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted… | |
| Pendiente de análisis | Media (6.9) | 0.29% | — | Amazon AWS CLIAIAmazon AWS CLI V2AI | 3/8/2026 | 4/8/2026 | Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint. To remediate this issue,… | |
| Pendiente de análisis | Media (6.2) | 0.51% | — | Amazon OPS WheelAI | 31/7/2026 | 4/8/2026 | Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this… | |
| Analizada | Media (6.4) | 0.99% | — | Amazon Amplify Codegen UI | 30/7/2026 | 10/8/2026 | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to… | |
| Analizada | Alta (8.7) | 0.43% | — | Amazon Aws-smithy-json | 30/7/2026 | 10/8/2026 | Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP… | |
| Aplazada | Media (5.4) | 0.21% | — | Koollab LMSAIAmazon S3AIAmazon SQSAI | 29/7/2026 | 30/7/2026 | A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception. | |
| Aplazada | Alta (7.1) | 0.45% | — | Pulumi HulumiAIAmazon AWSAI | 24/7/2026 | 30/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the… | |
| Pendiente de análisis | Alta (8.4) | 0.73% | — | Amazon Bedrock Agent CoreAI | 23/7/2026 | 24/7/2026 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to… | |
| Pendiente de análisis | Alta (8.7) | 0.75% | — | Amazon Aws-smithy-http-serverAI | 23/7/2026 | 12/8/2026 | Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets… | |
| Pendiente de análisis | Alta (7.3) | 0.23% | — | Amazon API MCP ServerAI | 23/7/2026 | 23/7/2026 | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup,… | |
| Pendiente de análisis | Media (6.9) | 0.53% | — | Amazon S2n-tlsAI | 21/7/2026 | 22/7/2026 | The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second call, s2n_alloc zeroes the existing… | |
| Pendiente de análisis | Alta (8.3) | 0.25% | — | Amazon S2n-tlsAI | 21/7/2026 | 22/7/2026 | Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer content_type of all encrypted TLS 1.3… | |
| Pendiente de análisis | Alta (8.7) | 0.75% | — | Amazon Smithy RSAIAmazon AWS SDK RustAI | 21/7/2026 | 22/7/2026 | Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation… | |
| Pendiente de análisis | Media (6.8) | 0.35% | — | Amazon Healthomics MCP ServerAI | 17/7/2026 | 20/7/2026 | AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a restricted directory in the linting tools… | |
| Pendiente de análisis | Media (6.1) | 0.59% | — | Amazon Aws-athena-query-federationAI | 17/7/2026 | 20/7/2026 | Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. Improper… | |
| Pendiente de análisis | Media (5.7) | 0.38% | — | Amazon Bedrock Agentcore Python SDKAI | 16/7/2026 | 17/7/2026 | AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a… | |
| Aplazada | Crítica (9) | 0.64% | — | DataeaseAIAmazon Redshift DriverAISpringframework Spring FrameworkAI | 15/7/2026 | 16/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so… |