Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.37% | — | Aerostackdev Aerostack-mcpAI | 9/7/2026 | 3/9/2026 | A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such manipulation of the argument media_url leads to server-side request forgery. The attack may be launched… | |
| Aplazada | Baja (2.1) | 0.51% | — | Tumf Mcp-text-editorAI | 9/7/2026 | 9/7/2026 | A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validate_file_path of the file mcp_text_editor/text_editor.py. Such manipulation of the argument file_path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed… | |
| Pendiente de análisis | Alta (8.6) | 0.58% | — | Amazon Mcp-gateway-registryAI | 6/7/2026 | 7/7/2026 | Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position.… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aianytime Awesome-mcp-serverAI | 5/7/2026 | 6/7/2026 | A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown functionality of the file mcp-wiki/src/mcp_wiki/server.py of the component mcp-wiki/wiki-summary. This manipulation of the argument url causes server-side request forgery. The… | |
| Aplazada | Baja (1.1) | 0.14% | — | Zcaceres Markdownify-mcpAI | 5/7/2026 | 6/7/2026 | A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/Markdownify.ts of the component webpage-to-markdown/youtube-to-markdown/bing-search-to-markdown. This manipulation causes insufficiently random values. The attack is restricted to local execution. A… | |
| Aplazada | Media (4.8) | 0.17% | — | Zcaceres Markdownify-mcpAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipulation can lead to symlink following. The attack can only be executed locally. The pull request to fix this issue awaits acceptance. | |
| Aplazada | Crítica (9.4) | 0.65% | — | Fast-mcp-telegramAI | 2/7/2026 | 6/7/2026 | fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the path before checking whether the session… | |
| Aplazada | Alta (8.1) | 0.43% | — | Royal MCPAI | 1/7/2026 | 1/7/2026 | The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content… | |
| Analizada | Crítica (9.3) | 0.53% | — | Google MCP Toolbox FOR Databases | 29/6/2026 | 1/7/2026 | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter… | |
| Aplazada | Media (6) | 0.21% | — | Github MCP ServerAI | 26/6/2026 | 27/6/2026 | GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent requests from different users share this… | |
| Aplazada | Alta (8.1) | 0.35% | — | Royal Plugins Royal MCPAI | 25/6/2026 | 25/6/2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25. | |
| Analizada | Media (6.1) | 0.12% | — | Google Chrome-devtools-mcp | 24/6/2026 | 26/6/2026 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by checking whether path.resolve(filePath) textually falls under one of the configured root paths. path.resolve() does not… | |
| Analizada | Media (6.1) | 0.10% | — | Google Chrome-devtools-mcp | 24/6/2026 | 26/6/2026 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon writes its PID file with fs.writeFileSync() to a deterministic runtime path. On typical macOS environments, and on Linux sessions where… | |
| Analizada | Media (4.3) | 0.28% | — | Jenkins MCP Server | 24/6/2026 | 26/6/2026 | A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access. | |
| Analizada | Alta (8.1) | 0.56% | — | Apache Doris MCP Server | 22/6/2026 | 6/10/2026 | Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if… | |
| Aplazada | Alta (8.1) | 0.49% | — | Doobidoo Mcp-memory-serviceAI | 19/6/2026 | 23/6/2026 | mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and… | |
| Aplazada | Alta (8.8) | 0.56% | — | Line Desktop MCPAI | 19/6/2026 | 23/6/2026 | Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to… | |
| Aplazada | Crítica (10) | 0.93% | — | Mcp-pinotAIApache PinotAI | 18/6/2026 | 23/6/2026 | mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools, including SQL query execution, schema creation, and table-config… | |
| Analizada | Alta (8.6) | 0.14% | — | Google MCP Toolbox FOR Databases | 18/6/2026 | 17/8/2026 | An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol versions (2025-06-18,… | |
| Analizada | Crítica (9.3) | 0.18% | — | Google MCP Toolbox FOR Databases | 18/6/2026 | 17/8/2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, the subsequent… | |
| Analizada | Crítica (9.3) | 0.18% | — | Google MCP Toolbox FOR Databases | 18/6/2026 | 17/8/2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is… | |
| Pendiente de análisis | Alta (8.9) | 0.69% | — | Windows-mcpAI | 17/6/2026 | 23/6/2026 | Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that… | |
| Aplazada | Alta (7.3) | 0.30% | — | Royal MCPAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions. | |
| Aplazada | Alta (8.7) | 0.54% | — | Agenticmail MCPAI | 12/6/2026 | 17/6/2026 | AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initialize a session and… | |
| Aplazada | Media (6.1) | 0.33% | — | Kubernetes KubectlAISuyogs Mcp-server-kubernetesAI | 11/6/2026 | 17/6/2026 | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags directly to kubectl without any allowlist, enabling a privilege escalation attack within Kubernetes environments. An attacker… |