Amazon records
207 published records for vendor amazon.
Researcher profile
- Entered KEV
- 2 · 1%
- Weaponized
- 2 · 1%
- Pre-auth RCE
- 17
- With a fix record
- 44.4%
- Median publish → KEV
- 5 days
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor11
- CWE-295 Improper Certificate Validation9
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')9
- CWE-863 Incorrect Authorization8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
207 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
62This week | CVE-2024-6387Proof of concept | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | High8.1 | — | 99.5% | Jul 1, 2024 |
62This week | CVE-2026-31431Weaponized | crypto: algif_aead - Revert to operating out-of-placelinux · linux kernel · CWE-669 | High7.8 | KEV | 3.4% | Apr 22, 2026 |
41Plan | CVE-2012-4249No exploit | The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute amazon · kindle touch · CWE-94 | Critical10.0 | — | 3.7% | Aug 12, 2012 |
40Plan | CVE-2019-3984No exploit | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitiamazon · blink xt2 sync module firmware · CWE-78 | Critical9.8 | — | 3.8% | Dec 31, 2019 |
40Plan | CVE-2019-3989No exploit | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitiamazon · blink xt2 sync module firmware · CWE-78 | Critical9.8 | — | 3.7% | Dec 11, 2019 |
40Plan | CVE-2022-25809No exploit | Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thesamazon · echo dot firmware | Critical9.8 | — | 3.3% | Feb 24, 2022 |
40Plan | CVE-2019-18960No exploit | Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.amazon · firecracker · CWE-120 | Critical9.8 | — | 3.3% | Dec 11, 2019 |
40Plan | CVE-2020-28472No exploit | This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.amazon · aws sdk for javascipt | Critical9.8 | — | 2.1% | Jan 19, 2021 |
40Plan | CVE-2015-7292No exploit | Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackeramazon · fire os · CWE-119 | Critical9.8 | — | 1.9% | Apr 9, 2017 |
39Monitor | CVE-2024-28056No exploit | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.amazon · aws amplify cli · CWE-276 | Critical9.8 | — | 1.7% | Apr 15, 2024 |
39Monitor | CVE-2019-10777No exploit | In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wiamazon · aws lambda · CWE-78 | Critical9.8 | — | 1.6% | Jan 8, 2020 |
39Monitor | CVE-2021-44833No exploit | The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.amazon · aws opensearch · CWE-276 | Critical9.8 | — | 1.6% | Dec 12, 2021 |
39Monitor | CVE-2021-31572No exploit | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.amazon · freertos · CWE-190 | Critical9.8 | — | 1.4% | Apr 22, 2021 |
39Monitor | CVE-2021-31571No exploit | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.amazon · freertos · CWE-190 | Critical9.8 | — | 1.4% | Apr 22, 2021 |
39Monitor | CVE-2021-32020No exploit | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.amazon · freertos · CWE-119 | Critical9.8 | — | 1.3% | May 3, 2021 |
39Monitor | CVE-2025-20286No exploit | ISE on AWS Static Credentialcisco · identity services engine · CWE-259 | Critical9.8 | — | 1.1% | Jun 4, 2025 |
39Monitor | CVE-2020-36363No exploit | Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entitiamazon · amazon cloudfront · CWE-327 | Critical9.8 | — | 0.7% | Aug 12, 2021 |
39Monitor | CVE-2022-4725No exploit | AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgeryamazon · aws software development kit · CWE-918 | Critical9.8 | — | 0.7% | Dec 27, 2022 |
38Monitor | CVE-2012-4248No exploit | The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow ramazon · kindle touch · CWE-264 | Critical9.3 | — | 3.5% | Aug 12, 2012 |
37Monitor | CVE-2021-30354No exploit | Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in funcamazon · kindle firmware · CWE-680 | High8.6 | — | 8.4% | Sep 1, 2021 |
37Monitor | CVE-2021-38112No exploit | In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote amazon · aws workspaces · CWE-88 | High8.8 | — | 7.5% | Sep 21, 2021 |
37Monitor | CVE-2026-77234No exploit | Improper input validation in FreeRTOS-Kernel timer command handlingamazon · freertos · CWE-863 | Critical9.3 | — | 0.2% | Aug 21, 2026 |
36Monitor | CVE-2021-30355No exploit | Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilegeamazon · kindle firmware · CWE-269 | High8.6 | — | 6.9% | Sep 1, 2021 |
36Monitor | CVE-2018-1169No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.amazon · amazon music · CWE-78 | High8.8 | — | 2.5% | Mar 1, 2018 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2024-638762This week
Openssh: regresshion - race condition in ssh allows rce/dos
HighCVSS 8.1Proof of conceptEPSS 100%sonicwall · sma 6200 firmwareJul 1, 2024
- CVE-2026-3143162This week
crypto: algif_aead - Revert to operating out-of-place
HighCVSS 7.8KEVWeaponizedEPSS 3%linux · linux kernelApr 22, 2026
- CVE-2012-424941Plan
The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute
CriticalCVSS 10.0No exploitEPSS 4%amazon · kindle touchAug 12, 2012
- CVE-2019-398440Plan
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti
CriticalCVSS 9.8No exploitEPSS 4%amazon · blink xt2 sync module firmwareDec 31, 2019
- CVE-2019-398940Plan
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti
CriticalCVSS 9.8No exploitEPSS 4%amazon · blink xt2 sync module firmwareDec 11, 2019
- CVE-2022-2580940Plan
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thes
CriticalCVSS 9.8No exploitEPSS 3%amazon · echo dot firmwareFeb 24, 2022
- CVE-2019-1896040Plan
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.
CriticalCVSS 9.8No exploitEPSS 3%amazon · firecrackerDec 11, 2019
- CVE-2020-2847240Plan
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.
CriticalCVSS 9.8No exploitEPSS 2%amazon · aws sdk for javasciptJan 19, 2021
- CVE-2015-729240Plan
Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attacker
CriticalCVSS 9.8No exploitEPSS 2%amazon · fire osApr 9, 2017
- CVE-2024-2805639Monitor
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.
CriticalCVSS 9.8No exploitEPSS 2%amazon · aws amplify cliApr 15, 2024
- CVE-2019-1077739Monitor
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wi
CriticalCVSS 9.8No exploitEPSS 2%amazon · aws lambdaJan 8, 2020
- CVE-2021-4483339Monitor
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
CriticalCVSS 9.8No exploitEPSS 2%amazon · aws opensearchDec 12, 2021
- CVE-2021-3157239Monitor
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.
CriticalCVSS 9.8No exploitEPSS 1%amazon · freertosApr 22, 2021
- CVE-2021-3157139Monitor
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.
CriticalCVSS 9.8No exploitEPSS 1%amazon · freertosApr 22, 2021
- CVE-2021-3202039Monitor
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.
CriticalCVSS 9.8No exploitEPSS 1%amazon · freertosMay 3, 2021
- CVE-2025-2028639Monitor
ISE on AWS Static Credential
CriticalCVSS 9.8No exploitEPSS 1%cisco · identity services engineJun 4, 2025
- CVE-2020-3636339Monitor
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entiti
CriticalCVSS 9.8No exploitEPSS 1%amazon · amazon cloudfrontAug 12, 2021
- CVE-2022-472539Monitor
AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgery
CriticalCVSS 9.8No exploitEPSS 1%amazon · aws software development kitDec 27, 2022
- CVE-2012-424838Monitor
The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow r
CriticalCVSS 9.3No exploitEPSS 3%amazon · kindle touchAug 12, 2012
- CVE-2021-3035437Monitor
Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in func
HighCVSS 8.6No exploitEPSS 8%amazon · kindle firmwareSep 1, 2021
- CVE-2021-3811237Monitor
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote
HighCVSS 8.8No exploitEPSS 7%amazon · aws workspacesSep 21, 2021
- CVE-2026-7723437Monitor
Improper input validation in FreeRTOS-Kernel timer command handling
CriticalCVSS 9.3No exploitEPSS 0%amazon · freertosAug 21, 2026
- CVE-2021-3035536Monitor
Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilege
HighCVSS 8.6No exploitEPSS 7%amazon · kindle firmwareSep 1, 2021
- CVE-2018-116936Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.
HighCVSS 8.8No exploitEPSS 3%amazon · amazon musicMar 1, 2018