Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6) | — | — | Amazon Powertools FOR AWS Lambda PythonAI | 1/10/2026 | 1/10/2026 | A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0. | |
| Recibida | Alta (8.7) | — | — | Amazon ION PythonAI | 1/10/2026 | 1/10/2026 | Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later. | |
| Pendiente de análisis | Media (6.9) | — | — | Amazon Security Agent MCP ServerAI | 1/10/2026 | 1/10/2026 | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan… | |
| Pendiente de análisis | Media (6.9) | — | — | Amazon EFS CSI DriverAI | 1/10/2026 | 1/10/2026 | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap… | |
| Pendiente de análisis | Alta (8.4) | 0.14% | — | Amazon GluontsAI | 29/9/2026 | 30/9/2026 | Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory. To remediate this issue, users should upgrade to… | |
| Pendiente de análisis | Alta (8.7) | 0.65% | — | Amazon PgcollectionAI | 24/9/2026 | 25/9/2026 | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval… | |
| Pendiente de análisis | Alta (8.6) | 0.14% | — | Amazon Kiro IDEAI | 24/9/2026 | 24/9/2026 | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global… | |
| Pendiente de análisis | Alta (8.7) | 1.9% | — | Amazon S2n-quicAI | 22/9/2026 | 23/9/2026 | Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected. To… | |
| Pendiente de análisis | Media (6.4) | 0.25% | — | Amazon-connect-salesforce-lambdaAI | 22/9/2026 | 22/9/2026 | Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that… | |
| Aplazada | Crítica (9.1) | 0.45% | — | MaxkbAIAmazon BedrockAIAmazon AWSAI | 21/9/2026 | 22/9/2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials without safe parsing. An attacker can append a new AWS… | |
| Pendiente de análisis | Crítica (9.2) | 0.38% | — | Amazon IOT Device SDK FOR PythonAI | 17/9/2026 | 18/9/2026 | Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages… | |
| Pendiente de análisis | Alta (8.7) | 0.64% | — | Amazon EKS Network Policy AgentAIAmazon VPC CNIAI | 16/9/2026 | 17/9/2026 | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions.… | |
| Pendiente de análisis | Alta (8.6) | 0.69% | — | TeamAIAmazon IAM Identity CenterAI | 14/9/2026 | 14/9/2026 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated… | |
| Pendiente de análisis | Alta (7.5) | 0.18% | — | Amazon Linux 2AICa-certificatesAI | 14/9/2026 | 22/9/2026 | The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491. | |
| Analizada | Media (6.7) | 0.18% | — | Amazon Kiro IDE | 11/9/2026 | 16/9/2026 | Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file,… | |
| Pendiente de análisis | Alta (8.2) | 0.30% | — | Amazon AWS SDK FOR GO V2AI | 11/9/2026 | 11/9/2026 | An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this… | |
| Analizada | Media (6) | 0.27% | — | Amazon Advanced Jdbc Wrapper | 11/9/2026 | 16/9/2026 | Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached query results, including stored database… | |
| Pendiente de análisis | Alta (8.5) | 0.66% | — | Amazon Systems Manager AgentAI | 10/9/2026 | 10/9/2026 | A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist… | |
| Pendiente de análisis | Alta (8.8) | 0.54% | — | Amazon Deep Java LibraryAI | 10/9/2026 | 10/9/2026 | An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue,… | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Amazon Security Agent MCP ServerAI | 10/9/2026 | 10/9/2026 | A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is… | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Amazon Aws-agents-for-devsecopsAI | 10/9/2026 | 10/9/2026 | A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage… | |
| Aplazada | Crítica (9) | 1.7% | — | Amazon Awslabs Postgres-mcp-serverAI | 9/9/2026 | 10/9/2026 | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement… | |
| Pendiente de análisis | Media (5.7) | 0.18% | — | Amazon Awslabs Mysql-mcp-serverAI | 9/9/2026 | 9/9/2026 | Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To… | |
| Pendiente de análisis | Alta (7.1) | 0.34% | — | Amazon Postgres-mcp-serverAI | 4/9/2026 | 8/9/2026 | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP… | |
| Pendiente de análisis | Alta (8.7) | 0.58% | — | Amazon Ion-javaAI | 4/9/2026 | 8/9/2026 | Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for… |