Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit the top exposed vulnerabilities to trigger memory corruption, denial of service, or arbitrary code execution, potentially compromising the OpenSearch container and the underlying host. The high severity of exposed CVEs such as CVE-2024-37371 and CVE-2025-49796 outweighs the otherwise trusted provenance. Immediate remediation through package upgrades is required before any deployment consideration.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2024-37371 | CRITICAL9.1 | krb5-libs 1.15.1-55.amzn2.2.5 fixed in 1.15.1-55.amzn2.2.8 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2025-49796 | CRITICAL9.1 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.19 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48734 | HIGH8.8 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2022-40303 | HIGH8.62 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.7 | 22.8% High Exploitation Risk | Directly Exposed |
| CVE-2020-36230 | HIGH8.62 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 12.3% High Exploitation Risk | Directly Exposed |
| CVE-2023-2650 | HIGH8.45 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.7 | 75.1% Actively Exploited | Directly Exposed |
| CVE-2023-37920 | HIGH8.33 | ca-certificates 2021.2.50-72.amzn2.0.4 fixed in 2021.2.50-72.amzn2.0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-14087 | HIGH8.33 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.13 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-6653 | HIGH8.33 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.25 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42581 | HIGH8.33 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42581 | HIGH8.33 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45447 | HIGH8.1 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.21 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-2961 | HIGH8 | glibc 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.1 | 88.3% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2024-2961 | HIGH8 | glibc-common 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.1 | 88.3% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2024-2961 | HIGH8 | glibc-langpack-en 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.1 | 88.3% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2024-2961 | HIGH8 | glibc-minimal-langpack 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.1 | 88.3% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2024-2961 | HIGH8 | libcrypt 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.1 | 88.3% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2022-40304 | HIGH7.8 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.7 | 6.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-58016 | HIGH7.73 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-49794 | HIGH7.73 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.19 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42584 | HIGH7.73 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42584 | HIGH7.73 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-25638 | HIGH7.57 | dnsjava:dnsjava 2.1.7 fixed in 3.6.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-39689 | HIGH7.5 | ca-certificates 2021.2.50-72.amzn2.0.4 fixed in 2023.2.68-1.amzn2.0.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2022-23990 | HIGH7.5 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.3 | 4.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-45490 | HIGH7.5 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.4 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-16429 | HIGH7.5 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.3 | 3.5% Low-Moderate Risk | Directly Exposed |
| CVE-2021-43618 | HIGH7.5 | gmp 1:6.0.0-15.amzn2.0.2 fixed in 1:6.0.0-15.amzn2.0.3 | 3.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-35945 | HIGH7.5 | libnghttp2 1.41.0-1.amzn2 fixed in 1.41.0-1.amzn2.0.1 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-27113 | HIGH7.5 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.16 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-6021 | HIGH7.5 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.18 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-13565 | HIGH7.5 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36223 | HIGH7.5 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36224 | HIGH7.5 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36226 | HIGH7.5 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36229 | HIGH7.5 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-2953 | HIGH7.5 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.6 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28388 | HIGH7.5 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.20 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.20 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.20 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0464 | HIGH7.5 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.7 | 3.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-7254 | HIGH7.5 | com.google.protobuf:protobuf-java 3.21.12 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2024-7254 | HIGH7.5 | com.google.protobuf:protobuf-java 3.21.8 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2024-7254 | HIGH7.5 | com.google.protobuf:protobuf-java 3.21.9 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2024-7254 | HIGH7.5 | com.google.protobuf:protobuf-java 3.7.1 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-3171 | HIGH7.5 | com.google.protobuf:protobuf-java 3.7.1 fixed in 3.21.7, 3.20.3, 3.19.6, 3.16.3 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3635 | HIGH7.5 | com.squareup.okio:okio 2.8.0 fixed in 3.4.0, 1.17.6 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-55163 | HIGH7.5 | io.netty:netty-codec-http2 4.1.79.Final fixed in 4.2.4.Final, 4.1.124.Final | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33871 | HIGH7.5 | io.netty:netty-codec-http2 4.1.79.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-55163 | HIGH7.5 | io.netty:netty-codec-http2 4.1.86.Final fixed in 4.2.4.Final, 4.1.124.Final | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33871 | HIGH7.5 | io.netty:netty-codec-http2 4.1.86.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-1370 | HIGH7.5 | net.minidev:json-smart 2.4.7 fixed in 2.4.9 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-23184 | HIGH7.5 | org.apache.cxf:cxf-core 3.5.5 fixed in 3.5.10, 3.6.5, 4.0.6 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-32007 | HIGH7.5 | org.apache.cxf:cxf-rt-rs-security-jose 3.5.5 fixed in 4.0.5, 3.6.4, 3.5.9 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2022-45688 | HIGH7.5 | org.json:json 20180813 fixed in 20230227 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5072 | HIGH7.5 | org.json:json 20180813 fixed in 20231013 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2022-45688 | HIGH7.5 | org.json:json 20220924 fixed in 20230227 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5072 | HIGH7.5 | org.json:json 20220924 fixed in 20231013 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34455 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.1 fixed in 1.1.10.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-43642 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.1 fixed in 1.1.10.4 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34453 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.1 fixed in 1.1.10.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34454 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.1 fixed in 1.1.10.1 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34455 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.2 fixed in 1.1.10.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-43642 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.2 fixed in 1.1.10.4 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34453 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.2 fixed in 1.1.10.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34454 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.2 fixed in 1.1.10.1 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0767 | HIGH7.48 | nss 3.79.0-4.amzn2 fixed in 3.79.0-4.amzn2.0.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-0767 | HIGH7.48 | nss-sysinit 3.79.0-4.amzn2 fixed in 3.79.0-4.amzn2.0.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-7104 | HIGH7.3 | nss 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.2 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-7104 | HIGH7.3 | nss-sysinit 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.2 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28182 | MEDIUM6.89 | libnghttp2 1.41.0-1.amzn2 fixed in 1.41.0-1.amzn2.0.5 | 84.8% Actively Exploited | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.14.1 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.14.1 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.1.79.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.1.86.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-25210 | MEDIUM6.63 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2020-35457 | MEDIUM6.63 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-32643 | MEDIUM6.63 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.9 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2017-10140 | MEDIUM6.63 | libdb 5.3.21-24.amzn2.0.3 fixed in 5.3.21-24.amzn2.0.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-49043 | MEDIUM6.63 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.15 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-7425 | MEDIUM6.63 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.20 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-13601 | MEDIUM6.54 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.12 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-24928 | MEDIUM6.54 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.16 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-25313 | MEDIUM6.5 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.3 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | krb5-libs 1.15.1-55.amzn2.2.5 fixed in 1.15.1-55.amzn2.2.6 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-28484 | MEDIUM6.5 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.8 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-29469 | MEDIUM6.5 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.8 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37533 | MEDIUM6.5 | commons-net:commons-net 3.6 fixed in 3.9.0 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34462 | MEDIUM6.5 | io.netty:netty-handler 4.1.79.Final fixed in 4.1.94.Final | 2.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34462 | MEDIUM6.5 | io.netty:netty-handler 4.1.86.Final fixed in 4.1.94.Final | 2.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-44483 | MEDIUM6.5 | org.apache.santuario:xmlsec 2.2.3 fixed in 2.3.4, 2.2.6, 3.0.3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29857 | MEDIUM6.5 | org.bouncycastle:bc-fips 1.0.2.3 fixed in 1.0.2.5 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29857 | MEDIUM6.5 | org.bouncycastle:bcprov-jdk15on 1.67 fixed in 1.78 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29857 | MEDIUM6.5 | org.bouncycastle:bcprov-jdk15on 1.70 fixed in 1.78 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-20863 | MEDIUM6.5 | org.springframework:spring-expression 5.3.22 fixed in 6.0.8, 5.3.27, 5.2.24.RELEASE | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2022-23491 | MEDIUM6.38 | ca-certificates 2021.2.50-72.amzn2.0.4 fixed in 2021.2.50-72.amzn2.0.5 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-32636 | MEDIUM6.38 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.9 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-29499 | MEDIUM6.38 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.9 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | krb5-libs 1.15.1-55.amzn2.2.5 fixed in 1.15.1-55.amzn2.2.8 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | libnghttp2 1.41.0-1.amzn2 fixed in 1.41.0-1.amzn2.0.6 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-32414 | MEDIUM6.38 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.17 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-32415 | MEDIUM6.38 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.17 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.17 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-52999 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-core 2.14.1 fixed in 2.15.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-3509 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.7.1 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-3510 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.7.1 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-1428 | MEDIUM6.38 | io.grpc:grpc-protobuf 1.52.1 fixed in 1.53.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec 4.1.79.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59901 | MEDIUM6.38 | io.netty:netty-codec 4.1.79.Final fixed in 4.1.136.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.79.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec 4.1.86.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59901 | MEDIUM6.38 | io.netty:netty-codec 4.1.86.Final fixed in 4.1.136.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.86.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-55831 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55833 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56745 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56746 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59899 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-55831 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55833 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56745 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56746 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59899 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.79.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.79.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.86.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.86.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.79.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.79.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.86.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.86.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42578 | MEDIUM6.38 | io.netty:netty-handler-proxy 4.1.79.Final fixed in 4.1.133.Final, 4.2.13.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42578 | MEDIUM6.38 | io.netty:netty-handler-proxy 4.1.86.Final fixed in 4.1.133.Final, 4.2.13.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-34480 | MEDIUM6.38 | org.apache.logging.log4j:log4j-core 2.17.1 fixed in 2.25.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk15on 1.70 fixed in 1.84 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-66566 | MEDIUM6.38 | org.lz4:lz4-java 1.7.1 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-41249 | MEDIUM6.38 | org.springframework:spring-core 5.3.22 fixed in 6.2.11 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-41848 | MEDIUM6.38 | org.springframework:spring-core 5.3.22 fixed in 7.0.8, 6.2.19 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41851 | MEDIUM6.38 | org.springframework:spring-expression 5.3.22 fixed in 7.0.8, 6.2.19 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 30.0-jre fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 30.1-jre fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 30.1.1-jre fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 31.0.1-jre fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 31.1-android fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-50602 | MEDIUM5.9 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.5 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | krb5-libs 1.15.1-55.amzn2.2.5 fixed in 1.15.1-55.amzn2.2.7 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1 4.10-1.amzn2.0.3 fixed in 4.10-1.amzn2.0.8 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-5535 | MEDIUM5.9 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.13 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-56132 | MEDIUM5.87 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.7 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56407 | MEDIUM5.87 | expat 2.1.0-15.amzn2.0.2 fixed in 2.1.0-15.amzn2.0.8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-35554 | MEDIUM5.78 | org.apache.kafka:kafka-clients 3.0.2 fixed in 3.9.2, 4.0.2, 4.1.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.16 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | krb5-libs 1.15.1-55.amzn2.2.5 fixed in 1.15.1-55.amzn2.2.9 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-45322 | MEDIUM5.52 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.13 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-39615 | MEDIUM5.52 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.11 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2023-5388 | MEDIUM5.52 | nss-softokn 3.79.0-4.amzn2 fixed in 3.90.0-6.amzn2.0.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-5388 | MEDIUM5.52 | nss-softokn-freebl 3.79.0-4.amzn2 fixed in 3.90.0-6.amzn2.0.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59900 | MEDIUM5.52 | io.netty:netty-codec-http2 4.1.79.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59900 | MEDIUM5.52 | io.netty:netty-codec-http2 4.1.86.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | org.lz4:lz4-java 1.7.1 fixed in 1.8.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2023-20861 | MEDIUM5.52 | org.springframework:spring-expression 5.3.22 fixed in 6.0.7, 5.3.26, 5.2.23.RELEASE | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2024-34459 | MEDIUM5.5 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.14 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0727 | MEDIUM5.5 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.12 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22569 | MEDIUM5.5 | com.google.protobuf:protobuf-java 3.7.1 fixed in 3.16.1, 3.18.2, 3.19.2 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-28153 | MEDIUM5.3 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.7 | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | glibc 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | glibc-common 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | glibc-langpack-en 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | glibc-minimal-langpack 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | libcrypt 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12133 | MEDIUM5.3 | libtasn1 4.10-1.amzn2.0.3 fixed in 4.10-1.amzn2.0.7 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0465 | MEDIUM5.3 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.7 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0466 | MEDIUM5.3 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.7 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3446 | MEDIUM5.3 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.9 | 6.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3817 | MEDIUM5.3 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.9 | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5678 | MEDIUM5.3 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.11 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29025 | MEDIUM5.3 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.1.108.Final | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29025 | MEDIUM5.3 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.1.108.Final | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-31141 | MEDIUM5.3 | org.apache.kafka:kafka-clients 3.0.2 fixed in 3.7.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2021-28170 | MEDIUM5.3 | org.glassfish:javax.el 3.0.0 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-27534 | MEDIUM5.28 | curl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27533 | MEDIUM5.28 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27534 | MEDIUM5.28 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-1757 | MEDIUM5.27 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.24 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-1390 | MEDIUM5.18 | libcap 2.54-1.amzn2.0.1 fixed in 2.54-1.amzn2.0.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6766 | MEDIUM5.18 | nss 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6767 | MEDIUM5.18 | nss 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6772 | MEDIUM5.18 | nss 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6766 | MEDIUM5.18 | nss-sysinit 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6767 | MEDIUM5.18 | nss-sysinit 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6772 | MEDIUM5.18 | nss-sysinit 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-2398 | MEDIUM5.17 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.7 | 36.1% High Exploitation Risk | Post-Exploit |
| CVE-2024-2398 | MEDIUM5.17 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.7 | 36.1% High Exploitation Risk | Post-Exploit |
| CVE-2023-24329 | MEDIUM5.17 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.6 | 20.5% High Exploitation Risk | Post-Exploit |
| CVE-2023-24329 | MEDIUM5.17 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.6 | 20.5% High Exploitation Risk | Post-Exploit |
| CVE-2024-26458 | MEDIUM5.02 | krb5-libs 1.15.1-55.amzn2.2.5 fixed in 1.15.1-55.amzn2.2.7 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | krb5-libs 1.15.1-55.amzn2.2.5 fixed in 1.15.1-55.amzn2.2.9 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-0990 | MEDIUM5.02 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.22 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.17 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.17 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.21 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34477 | MEDIUM5.02 | org.apache.logging.log4j:log4j-core 2.17.1 fixed in 2.25.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-30171 | MEDIUM5.02 | org.bouncycastle:bcprov-jdk15on 1.67 fixed in 1.78 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2024-30171 | MEDIUM5.02 | org.bouncycastle:bcprov-jdk15on 1.70 fixed in 1.78 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-41849 | MEDIUM5.02 | org.springframework:spring-expression 5.3.22 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41850 | MEDIUM5.02 | org.springframework:spring-expression 5.3.22 fixed in 7.0.8, 6.2.19 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-38808 | MEDIUM5.02 | org.springframework:spring-expression 5.3.22 fixed in 5.3.39 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.21 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-59921 | MEDIUM4.84 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59921 | MEDIUM4.84 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2007-4559 | MEDIUM4.69 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.12 | 27.1% High Exploitation Risk | Post-Exploit |
| CVE-2007-4559 | MEDIUM4.69 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.12 | 27.1% High Exploitation Risk | Post-Exploit |
| CVE-2021-38185 | MEDIUM4.68 | cpio 2.11-28.amzn2 fixed in 2.12-11.amzn2 | 4.1% Low-Moderate Risk | Post-Exploit |
| CVE-2020-21047 | MEDIUM4.67 | elfutils-libelf 0.176-2.amzn2 fixed in 0.176-2.amzn2.0.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2021-33294 | MEDIUM4.67 | elfutils-libelf 0.176-2.amzn2 fixed in 0.176-2.amzn2.0.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2021-3800 | MEDIUM4.67 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.5 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-32611 | MEDIUM4.67 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.9 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-32665 | MEDIUM4.67 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.9 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | glibc 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | glibc-common 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | glibc-langpack-en 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | glibc-minimal-langpack 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | libcrypt 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.21 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-47535 | MEDIUM4.67 | io.netty:netty-common 4.1.86.Final fixed in 4.1.115.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-25193 | MEDIUM4.67 | io.netty:netty-common 4.1.86.Final fixed in 4.1.118.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-25710 | MEDIUM4.67 | org.apache.commons:commons-compress 1.21 fixed in 1.26.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-26308 | MEDIUM4.67 | org.apache.commons:commons-compress 1.21 fixed in 1.26.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-45146 | MEDIUM4.67 | org.bouncycastle:bc-fips 1.0.2.3 fixed in 1.0.2.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-33202 | MEDIUM4.67 | org.bouncycastle:bcprov-jdk15on 1.67 fixed in 1.70 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2023-23914 | MEDIUM4.64 | curl 7.87.0-2.amzn2.0.1 fixed in 7.88.0-1.amzn2.0.1 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2023-23914 | MEDIUM4.64 | libcurl 7.87.0-2.amzn2.0.1 fixed in 7.88.0-1.amzn2.0.1 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-7598 | MEDIUM4.64 | libssh2 1.4.3-12.amzn2.2.3 fixed in 1.4.3-12.amzn2.2.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-38545 | MEDIUM4.58 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.4 | 78.5% Actively Exploited | Post-Exploit |
| CVE-2023-38545 | MEDIUM4.58 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.4 | 78.5% Actively Exploited | Post-Exploit |
| CVE-2022-1471 | MEDIUM4.58 | org.yaml:snakeyaml 1.32 fixed in 2.0 | 99.6% Actively Exploited | Post-Exploit |
| CVE-2023-28319 | MEDIUM4.5 | curl 7.87.0-2.amzn2.0.1 fixed in 8.2.1-1.amzn2.0.2 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28319 | MEDIUM4.5 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.2.1-1.amzn2.0.2 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2022-45061 | MEDIUM4.5 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.6 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2024-7592 | MEDIUM4.5 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2022-45061 | MEDIUM4.5 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.6 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2024-7592 | MEDIUM4.5 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9923 | MEDIUM4.5 | tar 2:1.26-35.amzn2 fixed in 2:1.26-35.amzn2.0.2 | 3.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-5344 | MEDIUM4.5 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.2 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-4046 | MEDIUM4.5 | glibc 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | glibc-common 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | glibc-langpack-en 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | glibc-minimal-langpack 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libcrypt 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.21 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.14.1 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.14.1 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-51074 | MEDIUM4.5 | com.jayway.jsonpath:json-path 2.4.0 fixed in 2.9.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59898 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.79.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59898 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.86.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.79.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.79.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.86.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.86.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-8885 | MEDIUM4.5 | org.bouncycastle:bc-fips 1.0.2.3 fixed in 1.0.2.6, 2.0.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk15on 1.70 fixed in 1.79 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-33201 | MEDIUM4.5 | org.bouncycastle:bcprov-jdk15on 1.67 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-34447 | MEDIUM4.5 | org.bouncycastle:bcprov-jdk15on 1.67 fixed in 1.78 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-33201 | MEDIUM4.5 | org.bouncycastle:bcprov-jdk15on 1.70 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-34447 | MEDIUM4.5 | org.bouncycastle:bcprov-jdk15on 1.70 fixed in 1.78 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-38820 | MEDIUM4.5 | org.springframework:spring-context 5.3.22 fixed in 6.1.14 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-41852 | MEDIUM4.5 | org.springframework:spring-expression 5.3.22 fixed in 7.0.8, 6.2.19 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-0767 | MEDIUM4.49 | nss-tools 3.79.0-4.amzn2 fixed in 3.79.0-4.amzn2.0.1 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-47162 | MEDIUM4.49 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-29131 | MEDIUM4.4 | org.apache.commons:commons-configuration2 2.1.1 fixed in 2.10.1 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29133 | MEDIUM4.4 | org.apache.commons:commons-configuration2 2.1.1 fixed in 2.10.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-7104 | MEDIUM4.38 | nss-tools 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.2 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.11.0 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.7 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.8.0 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | krb5-libs 1.15.1-55.amzn2.2.5 fixed in 1.15.1-55.amzn2.2.10 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34982 | MEDIUM4.18 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-6100 | MEDIUM4.13 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.19 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-6100 | MEDIUM4.13 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.19 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-0938 | MEDIUM4.08 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2025-0938 | MEDIUM4.08 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-4039 | MEDIUM4.08 | libgcc 7.3.1-15.amzn2 fixed in 7.3.1-17.amzn2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-4039 | MEDIUM4.08 | libstdc++ 7.3.1-15.amzn2 fixed in 7.3.1-17.amzn2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-48795 | MEDIUM4.08 | org.apache.cxf:cxf-core 3.5.5 fixed in 3.5.11, 3.6.6, 4.0.7, 4.1.1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68161 | MEDIUM4.08 | org.apache.logging.log4j:log4j-core 2.17.1 fixed in 2.25.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.17 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | openssl-libs 1:1.0.2k-24.amzn2.0.6 fixed in 1:1.0.2k-24.amzn2.0.15 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2017-10140 | LOW3.98 | libdb-utils 5.3.21-24.amzn2.0.3 fixed in 5.3.21-24.amzn2.0.4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2022-2522 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2022-2571 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-2580 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-2581 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3134 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3234 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3235 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3256 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3296 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3297 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3324 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3352 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3491 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-47024 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-0051 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-0054 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-0288 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-0433 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-0512 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-2610 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1592-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-4733 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-4734 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-4735 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-4738 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-4750 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-4751 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-4752 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-4781 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-52858 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-52860 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-55693 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-55895 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-57456 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-22667 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-1215 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.4 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-1127 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1367-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-5535 | LOW3.98 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.3 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-23916 | LOW3.9 | curl 7.87.0-2.amzn2.0.1 fixed in 7.88.0-1.amzn2.0.1 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46218 | LOW3.9 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.6 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.8 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-23916 | LOW3.9 | libcurl 7.87.0-2.amzn2.0.1 fixed in 7.88.0-1.amzn2.0.1 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46218 | LOW3.9 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.6 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.8 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2020-22218 | LOW3.82 | libssh2 1.4.3-12.amzn2.2.3 fixed in 1.4.3-12.amzn2.2.6 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-58050 | LOW3.82 | libssh2 1.4.3-12.amzn2.2.3 fixed in 1.4.3-12.amzn2.2.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-8194 | LOW3.82 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.14 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-3644 | LOW3.82 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.17 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4224 | LOW3.82 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.17 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-8194 | LOW3.82 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.14 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-3644 | LOW3.82 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.17 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4224 | LOW3.82 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.17 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-41411 | LOW3.72 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.6 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.10 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.12.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.4 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.9 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-6135 | LOW3.65 | nss-softokn 3.79.0-4.amzn2 fixed in 3.90.0-6.amzn2.0.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2023-6135 | LOW3.65 | nss-softokn-freebl 3.79.0-4.amzn2 fixed in 3.90.0-6.amzn2.0.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2023-4156 | LOW3.62 | gawk 4.0.2-4.amzn2.1.2 fixed in 4.0.2-4.amzn2.1.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4786 | LOW3.62 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.19 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-4786 | LOW3.62 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.19 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-6965 | LOW3.61 | sqlite 3.7.17-8.amzn2.1.2 fixed in 3.7.17-8.amzn2.1.3 | 74.4% Actively Exploited | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gnupg2 2.0.22-5.amzn2.0.5 fixed in 2.0.22-5.amzn2.0.6 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-8058 | LOW3.57 | glibc 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-8058 | LOW3.57 | glibc-common 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-8058 | LOW3.57 | glibc-langpack-en 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-8058 | LOW3.57 | glibc-minimal-langpack 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-8058 | LOW3.57 | libcrypt 2.26-62.amzn2 fixed in 2.26-64.amzn2.0.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-27535 | LOW3.54 | curl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27536 | LOW3.54 | curl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27537 | LOW3.54 | curl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 1.9% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28321 | LOW3.54 | curl 7.87.0-2.amzn2.0.1 fixed in 8.2.1-1.amzn2.0.2 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27535 | LOW3.54 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27536 | LOW3.54 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27537 | LOW3.54 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 1.9% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28321 | LOW3.54 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.2.1-1.amzn2.0.2 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2022-48566 | LOW3.54 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.8 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2022-48566 | LOW3.54 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.8 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2018-16428 | LOW3.53 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.3 | 4.7% Low-Moderate Risk | Post-Exploit |
| CVE-2015-8390 | LOW3.53 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.6 | 4.6% Low-Moderate Risk | Post-Exploit |
| CVE-2015-8394 | LOW3.53 | glib2 2.56.1-9.amzn2.0.2 fixed in 2.56.1-9.amzn2.0.6 | 4.8% Low-Moderate Risk | Post-Exploit |
| CVE-2024-56171 | LOW3.53 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.16 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2015-8390 | LOW3.53 | pcre 8.32-17.amzn2.0.2 fixed in 8.32-17.amzn2.0.3 | 4.6% Low-Moderate Risk | Post-Exploit |
| CVE-2015-8394 | LOW3.53 | pcre 8.32-17.amzn2.0.2 fixed in 8.32-17.amzn2.0.3 | 4.8% Low-Moderate Risk | Post-Exploit |
| CVE-2022-48565 | LOW3.53 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.7 | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2022-48565 | LOW3.53 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.7 | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-45853 | LOW3.53 | zlib 1.2.7-19.amzn2.0.2 fixed in 1.2.7-19.amzn2.0.3 | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-32697 | LOW3.53 | org.xerial:sqlite-jdbc 3.32.3.2 fixed in 3.41.2.2 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-38039 | LOW3.51 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.1 | 62.2% Actively Exploited | Post-Exploit |
| CVE-2023-38039 | LOW3.51 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.1 | 62.2% Actively Exploited | Post-Exploit |
| CVE-2023-44487 | LOW3.51 | libnghttp2 1.41.0-1.amzn2 fixed in 1.41.0-1.amzn2.0.4 | 100.0% Actively Exploited | Post-Exploit |
| CVE-2020-36221 | LOW3.51 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 84.2% Actively Exploited | Post-Exploit |
| CVE-2020-36222 | LOW3.51 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 77.7% Actively Exploited | Post-Exploit |
| CVE-2020-36227 | LOW3.51 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 77.7% Actively Exploited | Post-Exploit |
| CVE-2020-36228 | LOW3.51 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 83.4% Actively Exploited | Post-Exploit |
| CVE-2021-27212 | LOW3.51 | openldap 2.4.44-23.amzn2.0.4 fixed in 2.4.44-25.amzn2.0.5 | 64.1% Actively Exploited | Post-Exploit |
| CVE-2025-14819 | LOW3.47 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-14819 | LOW3.47 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2024-6923 | LOW3.47 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2024-6923 | LOW3.47 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2023-1170 | LOW3.37 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1403-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-1175 | LOW3.37 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1403-1.amzn2.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-23915 | LOW3.31 | curl 7.87.0-2.amzn2.0.1 fixed in 7.88.0-1.amzn2.0.1 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2025-11563 | LOW3.31 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-23915 | LOW3.31 | libcurl 7.87.0-2.amzn2.0.1 fixed in 7.88.0-1.amzn2.0.1 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2025-11563 | LOW3.31 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-58051 | LOW3.31 | libssh2 1.4.3-12.amzn2.2.3 fixed in 1.4.3-12.amzn2.2.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-11972 | LOW3.31 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.21 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11972 | LOW3.31 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.21 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-27538 | LOW3.3 | curl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27538 | LOW3.3 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2022-48303 | LOW3.3 | tar 2:1.26-35.amzn2 fixed in 2:1.26-35.amzn2.0.1 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2019-3859 | LOW3.28 | libssh2 1.4.3-12.amzn2.2.3 fixed in 1.4.3-12.amzn2.2.4 | 6.3% Low-Moderate Risk | Post-Exploit |
| CVE-2019-3860 | LOW3.28 | libssh2 1.4.3-12.amzn2.2.3 fixed in 1.4.3-12.amzn2.2.4 | 5.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2004 | LOW3.18 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.7 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.10 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.5 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2004 | LOW3.18 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.7 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.10 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.5 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27043 | LOW3.18 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.9 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27043 | LOW3.18 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.9 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27533 | LOW3.17 | curl 7.87.0-2.amzn2.0.1 fixed in 8.0.1-1.amzn2.0.1 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2024-0450 | LOW3.16 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-0450 | LOW3.16 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-0989 | LOW3.15 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.23 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6766 | LOW3.11 | nss-tools 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6767 | LOW3.11 | nss-tools 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-6772 | LOW3.11 | nss-tools 3.79.0-4.amzn2 fixed in 3.90.0-2.amzn2.0.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6019 | LOW3.11 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-6019 | LOW3.11 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-10966 | LOW3.01 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-10966 | LOW3.01 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-6075 | LOW2.8 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-6075 | LOW2.8 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2023-4641 | LOW2.8 | shadow-utils 2:4.1.5.1-24.amzn2.0.2 fixed in 2:4.1.5.1-24.amzn2.0.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2021-3236 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2022-2874 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3153 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2022-3278 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2023-2609 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1592-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-1264 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1403-1.amzn2.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-1355 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1403-1.amzn2.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-46246 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2081-1.amzn2.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-24014 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-5441 | LOW2.8 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-2602 | LOW2.8 | libcap 2.54-1.amzn2.0.1 fixed in 2.54-1.amzn2.0.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2021-36084 | LOW2.8 | libsepol 2.5-8.1.amzn2.0.2 fixed in 2.5-10.amzn2.0.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2021-36085 | LOW2.8 | libsepol 2.5-8.1.amzn2.0.2 fixed in 2.5-10.amzn2.0.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2021-36086 | LOW2.8 | libsepol 2.5-8.1.amzn2.0.2 fixed in 2.5-10.amzn2.0.1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2021-36087 | LOW2.8 | libsepol 2.5-8.1.amzn2.0.2 fixed in 2.5-10.amzn2.0.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-8732 | LOW2.8 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.21 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 30.0-jre fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 30.1-jre fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 30.1.1-jre fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 31.0.1-jre fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 31.1-android fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2023-40217 | LOW2.7 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.12 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-12084 | LOW2.7 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.15 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2023-40217 | LOW2.7 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.12 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-12084 | LOW2.7 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.15 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-47167 | LOW2.7 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-0992 | LOW2.46 | libxml2 2.9.1-6.amzn2.5.6 fixed in 2.9.1-6.amzn2.5.22 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-14017 | LOW2.45 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15282 | LOW2.45 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-0672 | LOW2.45 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-15282 | LOW2.45 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-0672 | LOW2.45 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.12 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-48706 | LOW2.4 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-11468 | LOW2.29 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-0865 | LOW2.29 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-11468 | LOW2.29 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-0865 | LOW2.29 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.16 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2024-43802 | LOW2.29 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-29768 | LOW2.24 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-38546 | LOW2.22 | curl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.4 | 6.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28322 | LOW2.22 | curl 7.87.0-2.amzn2.0.1 fixed in 8.2.1-1.amzn2.0.2 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-38546 | LOW2.22 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.3.0-1.amzn2.0.4 | 6.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28322 | LOW2.22 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.2.1-1.amzn2.0.2 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-6069 | LOW2.19 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.13 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-6069 | LOW2.19 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.13 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-48231 | LOW2.19 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2023-48232 | LOW2.19 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2023-48233 | LOW2.19 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2023-48234 | LOW2.19 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2023-48235 | LOW2.19 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2023-48236 | LOW2.19 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2023-48237 | LOW2.19 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-26603 | LOW2.14 | vim-minimal 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-11168 | LOW1.89 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2024-11168 | LOW1.89 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.11 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2020-19909 | LOW1.68 | curl 7.87.0-2.amzn2.0.1 fixed in 8.2.1-1.amzn2.0.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2020-19909 | LOW1.68 | libcurl 7.87.0-2.amzn2.0.1 fixed in 8.2.1-1.amzn2.0.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-13462 | LOW1.68 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.18 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-4519 | LOW1.68 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.18 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-3479 | LOW1.68 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.18 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-13462 | LOW1.68 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.18 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-4519 | LOW1.68 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.18 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-3479 | LOW1.68 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.18 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2023-39804 | LOW1.68 | tar 2:1.26-35.amzn2 fixed in 2:1.26-35.amzn2.0.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-5642 | LOW1.38 | python 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.10 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2024-5642 | LOW1.38 | python-libs 2.7.18-1.amzn2.0.5 fixed in 2.7.18-1.amzn2.0.10 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2015-1197 | LOW1.14 | cpio 2.11-28.amzn2 fixed in 2.12-11.amzn2.0.1 | 2.9% Low-Moderate Risk | Post-Exploit |
| CVE-2026-47162 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-34982 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.5 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.5 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.5 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2022-2522 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2022-2571 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-2580 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-2581 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3134 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3234 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3235 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3256 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3296 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3297 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3324 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3352 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3491 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-47024 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-0051 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-0054 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-0288 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-0433 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-0512 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-2610 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1592-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-4733 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-4734 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-4735 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-4738 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-4750 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-4751 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-4752 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-4781 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-52858 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-52860 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-55693 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-55895 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-57456 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2024-22667 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-1215 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-1127 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1367-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-5535 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.3 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-5344 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.2 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-41411 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-1170 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1403-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-1175 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1403-1.amzn2.0.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2020-19185 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19186 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2020-19187 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19188 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19189 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2020-19190 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.7 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2020-19185 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19186 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2020-19187 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19188 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19189 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2020-19190 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.7 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2020-19185 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19186 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2020-19187 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19188 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2020-19189 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2020-19190 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.7 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2021-3236 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2022-2874 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3153 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-3278 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1314-1.amzn2.0.1 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2023-2609 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1592-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-1264 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1403-1.amzn2.0.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-1355 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1403-1.amzn2.0.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-46246 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2081-1.amzn2.0.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-24014 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-5441 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.1882-1.amzn2.0.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2019-17595 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2019-17595 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2019-17595 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2019-17594 | NONE0 | ncurses 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2019-17594 | NONE0 | ncurses-base 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2019-17594 | NONE0 | ncurses-libs 6.0-8.20170212.amzn2.1.4 fixed in 6.0-8.20170212.amzn2.1.6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-47167 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2023-48706 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-43802 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-29768 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-48231 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2023-48232 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2023-48233 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2023-48234 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2023-48235 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2023-48236 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2023-48237 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2120-1.amzn2.0.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-26603 | NONE0 | vim-data 2:9.0.1160-1.amzn2.0.1 fixed in 2:9.0.2153-1.amzn2.0.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.4 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2023-32803 | NONE0 | ca-certificates 2021.2.50-72.amzn2.0.4 fixed in 2021.2.50-72.amzn2.0.7 | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libblkid 2.30.2-2.amzn2.0.11 fixed in 2.30.2-2.amzn2.0.14 | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libmount 2.30.2-2.amzn2.0.11 fixed in 2.30.2-2.amzn2.0.14 | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libuuid 2.30.2-2.amzn2.0.11 fixed in 2.30.2-2.amzn2.0.14 | — | Not Applicable |
| CVE-2024-37902 | NONE0 | ai.djl:api 0.19.0 fixed in 0.28.0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-0851 | NONE0 | ai.djl:api 0.19.0 fixed in 0.31.1 | 23.3% High Exploitation Risk | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.14.1 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.14.1 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-xpw8-rcwv-8f8p | NONE0 | io.netty:netty-codec-http2 4.1.79.Final fixed in 4.1.100.Final | — | Not Applicable |
| GHSA-xpw8-rcwv-8f8p | NONE0 | io.netty:netty-codec-http2 4.1.86.Final fixed in 4.1.100.Final | — | Not Applicable |
| CVE-2024-23454 | NONE0 | org.apache.hadoop:hadoop-common 3.3.4 fixed in 3.4.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-33558 | NONE0 | org.apache.kafka:kafka-clients 3.0.2 fixed in 3.9.2, 4.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-59949 | NONE0 | org.lz4:lz4-java 1.7.1 No fix yet | — | Not Applicable |
| GHSA-6g3j-p5g6-992f | NONE0 | org.opensearch:opensearch 2.5.0 fixed in 1.3.14, 2.11.1 | — | Not Applicable |
| CVE-2025-22233 | NONE0 | org.springframework:spring-context 5.3.22 fixed in 6.2.7, 6.1.20 | 0.4% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.