Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

430 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.77%💥 PoCAmazon Serverless Application Model CLIAI31/3/202517/6/2026
When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the container environment allows a user to access privileged files on the host by leveraging the elevated permissions granted to the tool. A user could leverage the…
ModificadaMedia (5.7)0.33%—Amazon Tough27/3/202517/6/2026
During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next update until the cache is cleared. Users should upgrade to tough version 0.20.0 or later and ensure…
ModificadaMedia (5.7)0.33%—Amazon Tough27/3/202517/6/2026
During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new…
ModificadaMedia (5.7)0.33%—Amazon Tough27/3/202517/6/2026
Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later…
ModificadaMedia (5.7)0.33%—Amazon Tough27/3/202517/6/2026
Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by the client. Users should upgrade to tough version 0.20.0 or later and ensure any forked or…
ModificadaMedia (5.7)0.27%💥 PoCAmazon AWS Cloud Development KIT21/3/202517/6/2026
When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should upgrade to version 2.178.2 or later and…
AplazadaMedia (5.9)0.26%—Amazon Sagemaker Python SDKAI20/3/202517/6/2026
A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause…
AnalizadaMedia (6.1)0.31%—Duogeek Simple Amazon Affiliate12/3/202517/6/2026
The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AnalizadaAlta (7.1)0.27%—S3bubble-amazon-web-services-oembed-media-streaming-support11/3/202517/6/2026
The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaMedia (5.3)0.33%—Amazon IAM Identity CenterAIAmazon Temporary Elevated Access ManagementAI4/3/202517/6/2026
Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process
AplazadaAlta (7.1)0.15%—Jensmueller Easy Amazon Product InformationAI13/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in jensmueller Easy Amazon Product Information easy-amazon-product-information allows Stored XSS.This issue affects Easy Amazon Product Information: from n/a through <= 4.0.1.
AplazadaMedia (6.9)0.37%—Amazon AWSAI23/1/202517/6/2026
Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.
ModificadaBaja (1.8)0.33%—Amazon AWS Cloud Development KIT17/1/202517/6/2026
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom resource workflow. However, the current…
AplazadaAlta (7.7)0.46%—Amazon WorkspacesAI15/1/202517/6/2026
An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.
AplazadaAlta (7.7)0.51%—Amazon WorkspacesAIAmazon Appstream 2.0AIAmazon DCV ClientsAI15/1/202517/6/2026
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.
AnalizadaAlta (8.6)0.46%—Amazon Redshift Odbc Driver24/12/202417/6/2026
A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.6.0 or revert to driver version 2.1.4.0.
AnalizadaAlta (8.6)0.53%—Amazon Redshift Connector24/12/202417/6/2026
A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.
ModificadaAlta (8.6)0.59%—Amazon WEB Services Redshift Java Database Connectivity Driver24/12/202417/6/2026
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.
AplazadaAlta (7.1)0.21%—Alok Tiwari Amazon Product PriceAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alok Tiwari Amazon Product Price amazon-product-price allows Stored XSS.This issue affects Amazon Product Price: from n/a through <= 1.1.
AnalizadaMedia (6.9)0.33%—Amazon Opensearch Data Prepper12/12/202417/6/2026
OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in Data Prepper starting inversion 2.1.0 and prior to version 2.10.2 where some custom authentication plugins will not perform…
AplazadaAlta (7.1)0.21%—Ragaskar Amazon Associate FilterAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ragaskar Amazon Associate Filter amazon-associate-filter allows Stored XSS.This issue affects Amazon Associate Filter: from n/a through <= 0.4.
AplazadaMedia (4.3)0.39%—Amazon S3AI14/11/202417/6/2026
An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential…
ModificadaMedia (6.9)0.40%—Amazon Data.all9/11/202417/6/2026
A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to extract user data from data.all application logs in data.all via CloudWatch log scanning for particular operations that interact with customer producer teams data.
ModificadaMedia (5.3)0.31%—Amazon Data.all9/11/202417/6/2026
An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
ModificadaMedia (5.3)0.35%—Amazon Data.all9/11/202417/6/2026
Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.
Orbitaley — Vulnerabilidades