Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips… | |
| Analizada | Alta (8) | 0.13% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to… | |
| Analizada | Media (6.6) | 0.24% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted… | |
| Analizada | Media (5.7) | 0.20% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset… | |
| Analizada | Alta (8.1) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active. | |
| Aplazada | Alta (7.5) | 0.78% | — | MCPAI | 29/7/2026 | 30/7/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an unauthenticated remote attacker to exhaust process memory. This issue is… | |
| Aplazada | Alta (8.3) | 0.48% | — | MCP Ruby SDKAI | 29/7/2026 | 30/7/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a session owner, allowing an attacker with a stolen session ID to send tools/call requests that execute in the victim's… | |
| Aplazada | Media (5.3) | 0.51% | — | MCP Ruby SDKAI | 29/7/2026 | 30/7/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue… | |
| Aplazada | Media (6.2) | 0.18% | — | MCPAI | 29/7/2026 | 30/7/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp gem use IO#gets without a byte limit, allowing a peer that sends data without a newline to exhaust process memory. This issue is fixed in… | |
| Aplazada | Media (6.9) | 0.26% | — | MCP Ruby SDKAI | 29/7/2026 | 30/7/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not validate the HTTP Host or Origin request headers, which allows a malicious browser page to use DNS rebinding to reach a locally running MCP… | |
| Aplazada | Alta (8.6) | 0.39% | — | Consul-mcp-serverAI | 29/7/2026 | 30/7/2026 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled… | |
| Aplazada | Crítica (10) | 0.54% | — | Hashicorp Consul-mcp-serverAI | 29/7/2026 | 30/7/2026 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4. | |
| Aplazada | Crítica (10) | 0.46% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in… | |
| Aplazada | Alta (8.9) | 0.36% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed… | |
| Aplazada | Alta (8.6) | 0.39% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This… | |
| Analizada | Alta (7.5) | 0.77% | — | Github MCP Server | 28/7/2026 | 8/8/2026 | GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because… | |
| Aplazada | Media (5.8) | 0.40% | — | Alibabacloud RDS Openapi MCP ServerAI | 28/7/2026 | 28/7/2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default. | |
| Analizada | Media (6) | 0.19% | — | Google MCP Toolbox FOR Databases | 27/7/2026 | 28/9/2026 | A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport… | |
| Aplazada | Media (6) | 0.42% | — | BlendermcpAI | 24/7/2026 | 30/7/2026 | BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can supply malicious paths like… | |
| Aplazada | Alta (7.6) | 0.48% | — | Office Word MCP ServerAI | 23/7/2026 | 23/7/2026 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers can supply absolute paths or ../… | |
| Pendiente de análisis | Alta (7.3) | 0.23% | — | Amazon API MCP ServerAI | 23/7/2026 | 23/7/2026 | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup,… | |
| Aplazada | Crítica (9.8) | 0.71% | 💥 PoC | Mountdev AI MCP ConnectorAI | 23/7/2026 | 23/7/2026 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an… | |
| Aplazada | Alta (8.3) | 0.41% | — | Mcp-webresearchAI | 21/7/2026 | 23/7/2026 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers… | |
| Aplazada | Crítica (9.3) | 0.53% | — | Mcp-for-stataAI | 21/7/2026 | 23/7/2026 | MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata command string without sanitization. The security guard (`GuardValidator`) only scans the do-file content but does not… | |
| Analizada | Alta (8.6) | 0.18% | — | Google MCP Toolbox FOR Databases | 21/7/2026 | 22/9/2026 | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via… |