Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
430 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.7) | 0.10% | — | Amazon AWS Encryption SDK FOR PythonAI | 20/4/2026 | 17/6/2026 | Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple… | |
| Analizada | Media (6.9) | 0.75% | — | Amazon EFS CSI Driver | 17/4/2026 | 17/6/2026 | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to… | |
| Pendiente de análisis | Crítica (9.8) | 2.3% | 💥 PoC | Amazon Mcp-serverAI | 11/4/2026 | 17/6/2026 | aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed… | |
| Analizada | Alta (8.7) | 0.21% | — | Amazon Firecracker | 8/4/2026 | 24/7/2026 | An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration… | |
| Analizada | Alta (7.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users… | |
| Analizada | Alta (8.7) | 0.74% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and… | |
| Analizada | Alta (8.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue,… | |
| Analizada | Alta (7.3) | 1.1% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a local user-initiated connection. To remediate this issue,… | |
| Analizada | Alta (8.7) | 0.68% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate this issue, users should… | |
| Analizada | Crítica (9.1) | 0.74% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users… | |
| Analizada | Crítica (9.1) | 0.36% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to… | |
| Analizada | Alta (7.1) | 0.51% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations. To remediate this issue, users should upgrade to version 2.1.0.0. | |
| Analizada | Alta (7.3) | 0.33% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user-initiated… | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Amazon Kiro IDEAI | 2/4/2026 | 24/7/2026 | Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to trust the workspace… | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Amazon C-event-streamAI | 31/3/2026 | 24/7/2026 | Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. To remediate this issue, users should upgrade to… | |
| Pendiente de análisis | Crítica (9.1) | 0.26% | — | Amazon Aws-lcAI | 19/3/2026 | 17/6/2026 | A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0. | |
| Aplazada | Media (6.9) | 0.46% | — | Amazon S3 FOR Craft CMS Project Amazon S3 FOR Craft CMSAICraftcms Craft CMSAI | 18/3/2026 | 17/6/2026 | The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a list of buckets the plugin has access to. The `BucketsController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of… | |
| Pendiente de análisis | Alta (8.5) | 0.20% | — | Amazon Kiro IDEAI | 17/3/2026 | 17/6/2026 | Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory. To remediate this… | |
| Analizada | Media (5.8) | 0.42% | — | Amazon Bedrock Agentcore Starter Toolkit | 16/3/2026 | 17/6/2026 | A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who… | |
| Analizada | Media (6.8) | 0.18% | — | Amazon AWS API MCP Server | 16/3/2026 | 17/6/2026 | Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue,… | |
| Analizada | Media (5.4) | 0.53% | 💥 PoC | Apache-airflow-providers-amazon | 9/3/2026 | 2/7/2026 | In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0… | |
| Analizada | Media (5.3) | 0.37% | 💥 PoC | MariadbAmazon Aurora MysqlAmazon Relational Database Service | 3/3/2026 | 14/7/2026 | In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged. | |
| Modificada | Alta (8.7) | 0.40% | — | Amazon Aws-lc-sysAmazon AWS Libcrypto | 2/3/2026 | 15/7/2026 | Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0. | |
| Analizada | Alta (8.2) | 0.48% | — | Amazon Aws-lc-fips-sysAmazon Aws-lc-sysAmazon AWS Libcrypto | 2/3/2026 | 17/6/2026 | Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not… | |
| Modificada | Alta (8.7) | 0.40% | — | Amazon Aws-lc-sysAmazon AWS Libcrypto | 2/3/2026 | 15/7/2026 | Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC… |