Amazon

First CVE: Oct 22, 2024Active for: 2 years
127
CVEs Published
More CVEs Published than 73% of tracked CNAs
42.3
Avg CVEs / Year
More Avg CVEs / Year than 82% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Amazon as a CNA, 43.3% affect products that Amazon develops as a vendor.

43.3%
56.7%
Self-reported: 55Third-party: 72

Of all the CVEs published that affect products developed by Amazon, 28.2% are self-published by Amazon as a CNA.

28.2%
71.8%
Self-published: 55Published by other CNAs: 140

Trends Over Time

The number and severity of CVEs published by Amazon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 22, 2024
21 months ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Amazon as a CNA, regardless of affected vendor or product.

127 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via cr
Jun 29, 20269.843NONO
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2
Jun 29, 20269.843NONO
A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.
Jan 29, 20259.843NONO
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a m
Jun 23, 20267.842NONO
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to
May 18, 20269.841NONO
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the s
Jul 1, 20268.838NONO
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace
Jun 23, 20267.837NONO
Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitra
Jun 8, 20269.037NONO
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via c
Jun 2, 20268.837NONO
Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the
Apr 24, 20269.837NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA127 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local27 (21.3%)
Network94 (74.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network6 (4.7%)
Attack Complexity
Low101 (79.5%)
High26 (20.5%)
Unknown0 (0.0%)
User Interaction
None86 (67.7%)
Unknown0 (0.0%)
Required41 (32.3%)
Privileges Required
Low53 (41.7%)
High15 (11.8%)
None59 (46.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (127 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Amazon as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Amazon as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs