Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

430 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.4)1.1%—Amazon Jsii-diffAI15/7/202615/7/2026
OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument. To mitigate this issue, users should upgrade to jsii-diff v1.131.0 or later.
Pendiente de análisisMedia (5.8)0.65%—Amazon AWS Load Balancer ControllerAI14/7/202615/7/2026
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. To mitigate this issue, users should…
Pendiente de análisisCrítica (9.2)0.39%—Amazon Healthlake-mcp-serverAI14/7/202615/7/2026
AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a…
AplazadaMedia (6.4)0.35%—Affiliate-toolkit WP Affiliate Plugin With Amazon PluginAI10/7/202614/7/2026
The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
Pendiente de análisisAlta (7.1)0.57%—Amazon Research AND Engineering StudioAI7/7/20268/7/2026
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read…
Pendiente de análisisAlta (8.6)0.58%—Amazon Mcp-gateway-registryAI6/7/20267/7/2026
Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position.…
AnalizadaAlta (7.7)0.73%—Amazon Advanced Jdbc Wrapper1/7/20269/7/2026
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java…
Pendiente de análisisMedia (6.8)0.16%—Amazon AWS CLIAI1/7/20261/7/2026
Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the same host to read credentials written by certain CLI subcommands (aws…
Pendiente de análisisAlta (7)1.2%—Amazon Aws-cdk-libAI1/7/20261/7/2026
OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platforms might allow a actor who controls dependency version strings in a project's package.json file to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters…
AnalizadaAlta (7.9)0.68%—Amazon Application Load Balancer29/6/20261/7/2026
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2…
AnalizadaAlta (7.9)0.63%—Amazon Cloudfront29/6/20261/7/2026
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No…
Pendiente de análisisAlta (8.5)0.19%—Amazon Language ServersAI23/6/202623/6/2026
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users…
Pendiente de análisisAlta (8.5)0.23%—Amazon Language ServersAI23/6/202623/6/2026
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the…
AplazadaCrítica (9.3)0.39%—WorksnapsAIAmazon AWSAIAmazon S3AI18/6/20266/10/2026
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials included AWS access keys, S3 bucket names, and related cloud access information. The originally exposed AWS credentials authenticated as the AWS…
Pendiente de análisisAlta (8.4)0.34%—Amazon Bedrock Agentcore Python SDKAI17/6/202622/6/2026
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users…
Pendiente de análisisAlta (8.7)0.35%—Amazon Aws-c-httpAI12/6/202617/6/2026
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To…
Pendiente de análisisMedia (6.9)0.29%—Amazon S2n-quicAI10/6/202617/6/2026
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate this issue, users should upgrade to v1.8.2.
Pendiente de análisisAlta (7)0.99%💥 PoCAmazon AWS CDK LIBAI10/6/202617/6/2026
OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK…
Pendiente de análisisAlta (8.6)0.30%—Amazon Aurora PostgresqlAIAmazon Advanced GO WrapperAI5/6/202617/6/2026
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when…
Pendiente de análisisAlta (8.6)0.40%—Amazon Advanced Jdbc WrapperAI5/6/202617/6/2026
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when…
Pendiente de análisisAlta (7.2)0.33%—Redhat OpenshiftAIAmazon AWSAI4/6/202622/7/2026
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.
AnalizadaAlta (8.6)0.69%—Amazon Kiro IDE2/6/202622/7/2026
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To…
AplazadaAlta (7.6)0.30%—BudibaseAIMinioAIAmazon S3AI27/5/202617/6/2026
Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content restrictions for authenticated users. The checks for dangerous file extensions are conditionally wrapped inside if (isPublicUser) or if (isPublicUser ||…
AplazadaMedia (6.4)0.32%—WP Iframe GEO Style FOR Amazon AffiliatesAI27/5/202617/6/2026
The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
Pendiente de análisisAlta (7.5)0.65%—Amazon Braket SDKAI22/5/202623/7/2026
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to amazon-braket-sdk version…
Orbitaley — Vulnerabilidades