Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Amazon

First CVE: Aug 12, 2012Active for: 14 yearsTotal CVEs: 195
63.4
VTI Score
TOP TARGET

Amazon's vulnerability profile spans a moderately broad portfolio that includes embedded operating systems, cloud infrastructure components, and open-source projects such as FreeRTOS, Fire OS, OpenSearch, and the TLS library Tough, reflecting the vendor's footprint across both consumer devices and enterprise cloud services. Vulnerabilities affecting the vendor carry a meaningful share of serious severity outcomes and cluster around command-injection and argument-injection flaws, certificate-validation weaknesses, and information-disclosure conditions that arise in the intersection of embedded firmware, network services, and cryptographic validation logic. The exposure across FreeRTOS and related embedded platforms is particularly relevant to defenders managing IoT and constrained-device deployments, while cloud-infrastructure and open-source disclosures affect a broader audience of AWS users and downstream dependents. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
195
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
1.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Amazon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2012
13 years ago
Most Recent CVE
Jul 23, 2026
2 days ago

Self-Reporting Analysis

Of all the CVEs published by Amazon as a CNA, 43.3% affect products that Amazon develops as a vendor.

43.3%
56.7%
Self-reported: 55 (43.3%)
Third-party: 72 (56.7%)

Of all the CVEs published that affect products developed by Amazon, 28.2% are self-published by Amazon as a CNA.

28.2%
71.8%
Self-published: 55 (28.2%)
Other CNAs: 140 (71.8%)

Products(101 total)

Top CVEs

Signals from CVEs in this vendor scope (195 CVEs).

195 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-31431HIGH
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2024-6387HIGH
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
CVE-2026-13763CRITICAL
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via cr
Jun 29, 20269.843NONO
CVE-2026-13762CRITICAL
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2
Jun 29, 20269.843NONO
CVE-2026-14265HIGH
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the s
Jul 1, 20268.838NONO
CVE-2026-10591HIGH
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via c
Jun 2, 20268.837NONO
CVE-2026-35561CRITICAL
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or
Apr 3, 20269.837NONO
CVE-2026-5707HIGH
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote
Apr 6, 20268.835NONO
CVE-2026-5708HIGH
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticat
Apr 6, 20268.834NONO
View all 195 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products195 CVEs
39%
48%
10%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local41 (21.0%)
Network127 (65.1%)
Unknown9 (4.6%)
Physical2 (1.0%)
Adjacent Network16 (8.2%)
Attack Complexity
Low152 (77.9%)
High34 (17.4%)
Unknown9 (4.6%)
User Interaction
None144 (73.8%)
Unknown9 (4.6%)
Required42 (21.5%)
Privileges Required
Low61 (31.3%)
High14 (7.2%)
None111 (56.9%)
Unknown9 (4.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (195 CVEs).

CISA KEV
2 CVEs
1.0% of CVEs· 99th percentile
Metasploit
1 CVE
0.5% of CVEs· 97th percentile
Nuclei
1 CVE
0.5% of CVEs· 95th percentile
ExploitDB
2 CVEs
1.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Amazon.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Amazon — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Amazon's Products

View all 22 CNAs →

Top CWEs