Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.21% | — | Verygoodplugins Whatsapp MCP Server | 20/7/2026 | 18/8/2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute… | |
| Pendiente de análisis | Media (6.8) | 0.35% | — | Amazon Healthomics MCP ServerAI | 17/7/2026 | 20/7/2026 | AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a restricted directory in the linting tools… | |
| Aplazada | Media (6.1) | 0.34% | — | Apify MCP ServerAI | 16/7/2026 | 17/7/2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts validates allowlisted documentation domains with String.startsWith() rather… | |
| Analizada | Media (4.3) | 0.37% | — | Getdbt DBT MCP Server | 16/7/2026 | 21/7/2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent it through dbtlabs_vortex.producer.log_proto without redaction, including… | |
| Analizada | Baja (3.3) | 0.17% | — | Getdbt DBT MCP Server | 16/7/2026 | 21/7/2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when… | |
| Analizada | Media (6.3) | 0.21% | — | Getdbt DBT MCP Server | 16/7/2026 | 21/7/2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the dbt subprocess argument list, allowing an MCP client to inject dbt global flags such as --profiles-dir,… | |
| Analizada | Alta (7.6) | 0.23% | — | Lfprojects MCP Python SDK | 15/7/2026 | 17/7/2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins… | |
| Analizada | Media (5.4) | 0.28% | — | N8n-mcp | 15/7/2026 | 17/7/2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true could allow an authenticated tenant to access default-scope workflow_versions backups instead of being confined to the tenant scope,… | |
| Analizada | Crítica (9.9) | 0.39% | — | N8n-mcp | 15/7/2026 | 18/7/2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant… | |
| Analizada | Alta (7.6) | 0.39% | — | Lfprojects MCP Python SDK | 15/7/2026 | 17/7/2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session… | |
| Analizada | Alta (7.1) | 0.53% | — | Lfprojects MCP Python SDK | 15/7/2026 | 17/7/2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only… | |
| Pendiente de análisis | Alta (8.6) | 0.53% | 💥 PoC | Grafana MCP ServerAI | 15/7/2026 | 15/7/2026 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints. | |
| Aplazada | Baja (1.9) | 0.17% | — | Mastergo Magic MCPAI | 14/7/2026 | 15/7/2026 | A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the file mastergo/component-workflow.md of the component mcp__getComponentGenerator. The manipulation of the argument rootPath leads to path traversal. An attack has to be… | |
| Aplazada | Baja (2.1) | 0.40% | — | Mastergo-design Mastergo-magic-mcpAI | 14/7/2026 | 15/7/2026 | A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from… | |
| Aplazada | Baja (1.9) | 0.17% | — | Mastergo-design Mastergo-magic-mcpAI | 14/7/2026 | 15/7/2026 | A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/get-c2d.ts of the component mcp__C2d. Performing a manipulation of the argument filePath results in path traversal. The attack requires a local approach. The exploit has… | |
| Pendiente de análisis | Crítica (9.2) | 0.39% | — | Amazon Healthlake-mcp-serverAI | 14/7/2026 | 15/7/2026 | AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a… | |
| Analizada | Alta (8.2) | 0.40% | — | Appium-mcp | 13/7/2026 | 26/8/2026 | MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In versions prior to 1.85.10, the createLocatorGeneratorUI function interpolates attacker-controlled element attributes — text, content-desc, resource-id, and locator selector values — directly into an… | |
| Aplazada | Crítica (9.2) | 0.51% | — | Mcp-gitlabAI | 13/7/2026 | 13/7/2026 | mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the… | |
| Aplazada | Baja (1.9) | 0.16% | — | Lamaalrajih Kicad-mcpAI | 13/7/2026 | 13/7/2026 | A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the argument project_path/schematic_path results in protection mechanism failure. Attacking locally is a requirement. The exploit has… | |
| Aplazada | Baja (1.9) | 0.17% | — | Augmnt Augments-mcp-serverAI | 13/7/2026 | 13/7/2026 | A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file src/tools/v4/scan-project-deps.ts of the component scan_project_deps. Executing a manipulation of the argument packageJsonPath can lead to path traversal. The attack can only be executed locally. The… | |
| Aplazada | Baja (1.9) | 0.17% | — | Alioshr Memory-bank-mcpAI | 13/7/2026 | 13/7/2026 | A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of the file list-project-files-validation-factory.ts. Such manipulation of the argument projectName leads to path traversal. Local access is required to approach this attack. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.17% | — | Tugcantopaloglu Godot-mcpAI | 13/7/2026 | 13/7/2026 | A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath results in path traversal. Attacking locally is a requirement. The exploit has been… | |
| Analizada | Crítica (9.3) | 2.4% | 💥 Exploit | Suyogs Mcp-server-kubernetes | 10/7/2026 | 17/7/2026 | MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the… | |
| Aplazada | Media (5.3) | 0.60% | — | Arikusi Deepseek MCP ServerAI | 9/7/2026 | 10/7/2026 | DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@arikusi/deepseek-mcp-server` exposes `POST /mcp` without any authentication: `createMcpExpressApp` is called without an `authProvider` and no middleware guards the route, so… | |
| Aplazada | Alta (8.6) | 0.37% | — | Deepseek MCP ServerAI | 9/7/2026 | 10/7/2026 | DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via… |