Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.60% | — | Suyogs Mcp-server-kubernetesAI | 11/6/2026 | 17/6/2026 | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes… | |
| Aplazada | Baja (2.1) | 0.21% | — | Designcomputer Mysql-mcp-serverAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2.1) | 0.31% | — | Johnhuang316 Code-index-mcpAI | 3/6/2026 | 22/7/2026 | A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argument regex can lead to inefficient regular expression complexity. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Wonderwhy-er DesktopcommandermcpAI | 3/6/2026 | 22/7/2026 | A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is possible to… | |
| Aplazada | Baja (2.1) | 0.22% | — | Wonderwhy-er DesktopcommandermcpAI | 3/6/2026 | 22/7/2026 | A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is… | |
| Aplazada | Baja (2) | 0.18% | — | Ahujasid Blender-mcpAI | 2/6/2026 | 22/7/2026 | A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_blender_code of the file /src/blender_mcp/server.py. This manipulation of the argument code causes code injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Baja (2.1) | 0.23% | — | Ahujasid Blender-mcpAI | 2/6/2026 | 22/7/2026 | A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element is the function requests.get of the file src/blender_mcp/server.py of the component ZIP File Handler. The manipulation of the argument zip_file_url results in server-side request forgery. The attack… | |
| Aplazada | Baja (2.1) | 0.25% | — | Ahujasid Blender-mcpAI | 2/6/2026 | 22/7/2026 | A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file src/blender_mcp/server.py. The manipulation of the argument input_image_url leads to injection. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.30% | — | Horizon921 McpilotAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/route.ts of the component MCP API Call Endpoint. The manipulation of the argument serverBaseUrl results in server-side request forgery. The attack can be launched… | |
| Aplazada | Baja (2.1) | 1.1% | — | Hiraishikentaro Wezterm MCPAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/write_to_specific_pane. The manipulation of the argument request.params.arguments.pane_id leads to os command injection. The attack can be… | |
| Aplazada | Baja (2.1) | 0.29% | — | Ishayoyo Excel-mcpAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file/write_file. Executing a manipulation of the argument filePath/outputPath can lead to path traversal. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.28% | — | J3k0 MCP Google WorkspaceAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack… | |
| Aplazada | Baja (2.1) | 0.27% | — | Hekmon8 Jenkins-server-mcpAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the component get_build_status/get_build_log/trigger_build. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has… | |
| Aplazada | Baja (2.1) | 0.21% | — | Indrasishbanerjee Aem-mcp-serverAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAssetMetadata of the file src/mcp-server.ts of the component Axios Request Flow. Executing a manipulation of the argument assetPath can lead to server-side request forgery.… | |
| Aplazada | Baja (2) | 0.27% | — | Lharries Whatsapp-mcpAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (6.5) | 0.28% | — | Springaicommunity MCP Security | 29/5/2026 | 21/7/2026 | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted URLs for… | |
| Analizada | Alta (8.1) | 0.41% | — | N8n-mcp | 29/5/2026 | 21/7/2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that the target n8n instance is selected per-request from x-n8n-url / x-n8n-key headers. Requests that omitted those headers —… | |
| Analizada | Media (6.5) | 0.46% | — | N8n-mcp | 29/5/2026 | 21/7/2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry backend. Values placed in… | |
| Aplazada | Alta (7.8) | 0.21% | — | Roslyn Codelens MCP ServerAI | 29/5/2026 | 21/7/2026 | Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solution without any allowlist, signature check, or user confirmation;… | |
| Aplazada | Crítica (9.2) | 0.62% | — | Gitlab MCP ServerAI | 26/5/2026 | 24/7/2026 | GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response. The structural defect is that the SSE server stands up a stateful, mutation-capable RPC endpoint… | |
| Aplazada | Baja (2.1) | 0.40% | — | C-rick Jimeng-mcpAI | 25/5/2026 | 23/7/2026 | A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.40% | — | Dazeb Cline-mcp-memory-bankAI | 25/5/2026 | 23/7/2026 | A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The affected element is the function handleInitializeMemoryBank of the file src/index.ts. The manipulation of the argument projectPath results in path traversal. The attack may be performed from remote.… | |
| Aplazada | Baja (2.1) | 0.52% | — | Debugmcp Mcp-debuggerAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted… | |
| Aplazada | Crítica (9.8) | 0.86% | — | MCP Calculate ServerAISympyAI | 15/5/2026 | 17/6/2026 | MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1. | |
| Analizada | Baja (2.1) | 0.27% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and server-side GitHub OIDC flow is bound only to a global audience string, not to the specific registry instance being targeted. On the client side, the publisher always appends… |