Where
-Infinity
0

Vendor Risk Score

See how amazon compares to other vendors in security performance

View Risk Score →

Software

Amazon OpenSearch Alerting pluginMissing Authorization in Execute Monitor API in OpenSearch Alerting Plugin

Risk 62
Severity
8.6
First published (updated )

Amazon Strands Agents ToolsInsecure direct object reference in Strands Agents Tools memory tool namespace isolation

Risk 62
Severity
8.6
First published (updated )

Amazon AWS Labs DocumentDB MCP ServerIncorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server

Risk 32
Severity
5.7
First published (updated )

aws-transform-mcp-server/get_resourceImproper limitation of a pathname to a restricted directory in aws-transform-mcp-server

Risk 72
Severity
6.3
First published (updated )

Amazon AWS CLI (EMR SSH helper commands)Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

Risk 39
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

aws-smithy-json aws-smithy-json (runtime crate)Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers

Risk 47
Severity
8.7
First published (updated )

npm/@aws-amplify/codegen-ui-reactIncomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react

Risk 74
Severity
6.4
First published (updated )

Amazon s2n-tlsSilent Drop of TLS 1.3 Encrypted Records in s2n-tls

Risk 52
Severity
8.3
First published (updated )

Amazon smithy-rs (code generation and runtime framework)Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes

Risk 47
Severity
8.7
First published (updated )

Amazon Athena Query Federation (Synapse connector)SQL injection in Amazon Athena Synapse connector

Risk 37
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Amazon AWS Load Balancer ControllerCross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer Controller

Risk 73
Severity
5.8
First published (updated )

Amazon Web Services AWS Advanced JDBC WrapperRCE via Deserialization in AWS Advanced JDBC Wrapper

Risk 79
Severity
7.7
First published (updated )

Amazon Web Services Application Load Balancer (ALB) with AWS WAFHTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF

Risk 86
Severity
7.9
First published (updated )

Amazon CloudFrontHTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF

Risk 86
Severity
7.9
First published (updated )

Amazon AWS Toolkit for Visual Studio CodeArbitrary file write in Language Servers for AWS

Risk 72
Severity
8.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Amazon s2n-quicExcessive memory allocation in s2n-quic

Risk 33
Severity
6.9
First published (updated )

Amazon Kiro IDEKiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths

Risk 77
Severity
8.6
First published (updated )

Kiro CLITool Execution Without Authorization via Piped Stdin in Kiro CLI

Risk 54
Severity
8.4
EPSS
0.12%
First published (updated )

Amazon rabbitmq-awsArbitrary file read in rabbitmq-aws plugin

Risk 32
Severity
8.3
EPSS
0.34%
First published (updated )

Amazon coreMQTTDoS from MQTT v5.0 Deserialization Fault in core MQTT

Risk 33
Severity
8.7
EPSS
0.39%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Amazon Amazon Redshift JDBC DriverRemote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver

Risk 55
Severity
9.2
EPSS
0.03%
First published (updated )

The RegisterAttackers are cashing in on fresh 'CopyFail' Linux flaw

First published (updated )

BleepingComputerCISA says ‘Copy Fail’ flaw now exploited to root Linux systems

First published (updated )

Amazon Amazon ECS AgentOS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials

Risk 49
Severity
7.5
EPSS
0.04%
First published (updated )

BleepingComputerNew Linux ‘Copy Fail’ flaw gives hackers root on major distros

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Amazon Freertos-plus-tcpOut-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plus-TCP

Risk 43
Severity
6.1
EPSS
0.02%
First published (updated )

Amazon Freertos-plus-tcpOut-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP

Risk 27
Severity
6
EPSS
0.02%
First published (updated )

Amazon Freertos-plus-tcpInteger Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP

Risk 43
Severity
7.2
EPSS
0.02%
First published (updated )

Amazon Freertos-plus-tcpInteger Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP

Risk 27
Severity
6
EPSS
0.02%
First published (updated )

Amazon Freertos-plus-tcpMAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing

Risk 29
Severity
7.1
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203