Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.59% | — | Eiceblue Spire-pdf-mcp-serverAI | 28/4/2026 | 24/7/2026 | A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulation of the argument filepath can lead to path traversal. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.59% | — | Eiceblue Spire-doc-mcp-serverAI | 28/4/2026 | 24/7/2026 | A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. The… | |
| Aplazada | Media (5.5) | 0.61% | — | Williamcloudqi Matlab-mcp-serverAI | 28/4/2026 | 17/6/2026 | A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can lead to path… | |
| Aplazada | Media (5.5) | 0.62% | — | Agiflow Scaffold-mcpAI | 28/4/2026 | 17/6/2026 | A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold-mcp/src/server/index.ts of the component write-to-file Tool. The manipulation of the argument file_path results in path traversal. The attack may be launched remotely.… | |
| Aplazada | Media (5.5) | 0.51% | — | Tencentcloud Cloudbase-mcpAI | 28/4/2026 | 24/7/2026 | A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery. It is possible to launch the attack… | |
| Aplazada | Media (5.5) | 2.1% | — | Jackwrichards FastlymcpAI | 28/4/2026 | 24/7/2026 | A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts an unknown function of the file fastly-mcp.mjs of the component fastly_cli Tool. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.5) | 0.59% | — | Donchelo Processing Claude MCP BridgeAI | 28/4/2026 | 24/7/2026 | A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. Impacted is an unknown function of the file processing_server.py of the component create_sketch Tool. This manipulation of the argument sketch_name causes path traversal. Remote exploitation of the… | |
| Aplazada | Media (5.5) | 2.1% | — | Egtai GMX VMD MCPAI | 28/4/2026 | 24/7/2026 | A security flaw has been discovered in egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_tool of the file mcp_server.py of the component VMD Launch Handler. The manipulation of the argument structure_file/trajectory_file results in command injection. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.59% | — | Ef10007 Mlops MCPAI | 28/4/2026 | 24/7/2026 | A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file Tool. The manipulation of the argument filename/destination results in path traversal. The attack may be performed from remote. The exploit is now public and may be used.… | |
| Aplazada | Media (5.5) | 0.59% | — | Edvardlindelof Notes-mcpAI | 28/4/2026 | 24/7/2026 | A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The manipulation of the argument root_dir/path leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (5.5) | 2.1% | — | Dvladimirov MCPAI | 28/4/2026 | 24/7/2026 | A weakness has been identified in dvladimirov MCP up to 0.1.0. The impacted element is the function GitSearchRequest of the file mcp_server.py of the component Git Search API. Executing a manipulation of the argument repo_url/pattern can lead to command injection. The attack can be executed remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.43% | — | Dubydu Sqlite-mcpAI | 28/4/2026 | 24/7/2026 | A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. Performing a manipulation of the argument output_filename results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the… | |
| Aplazada | Media (5.5) | 0.59% | — | Duartium Papers-mcp-serverAI | 28/4/2026 | 24/7/2026 | A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the function search_papers of the file src/main.py. Such manipulation of the argument topic leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be… | |
| Aplazada | Media (5.5) | 0.61% | — | Douinc Mkdocs-mcp-pluginAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_documents of the file server.py. Performing a manipulation of the argument docs_dir/file_path results in path traversal. The attack is possible to be carried out remotely. The exploit has been made public… | |
| Aplazada | Media (5.5) | 0.47% | — | Dmitryglhf Mcp-url-downloaderAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the function _validate_url_safe of the file src/mcp_url_downloader/server.py. Such manipulation of the argument url leads to server-side request forgery. The attack can be executed… | |
| Aplazada | Media (5.5) | 2.1% | — | Disler Aider-mcp-serverAI | 27/4/2026 | 17/6/2026 | A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py of the component aider_ai_code. This manipulation of the argument relative_editable_files causes command injection.… | |
| Aplazada | Media (5.5) | 0.59% | — | Dexhunter Kaggle-mcpAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server.py. The manipulation of the argument competition_id leads to path traversal. The attack is possible to be carried out… | |
| Aplazada | Media (5.5) | 0.47% | — | Joecastrom Mcp-chat-studioAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remote exploitation of the… | |
| Aplazada | Media (5.5) | 0.51% | — | Alejandroarciniegas Mcp-data-visAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-side request… | |
| Analizada | Media (5.5) | 0.53% | — | Shadowclonelabs Glutamate MCP Servers | 27/4/2026 | 17/6/2026 | A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request… | |
| Aplazada | Media (5.5) | 2.1% | — | Choieastsea Simple Openstack MCPAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function exec_openstack of the file server.py. The manipulation results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 2.1% | — | Toowiredd Chatgpt-mcp-serverAI | 26/4/2026 | 17/6/2026 | A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Aplazada | Media (5.5) | 2.6% | — | Agentdeskai Browser-tools-mcpAI | 26/4/2026 | 2/10/2026 | A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used.… | |
| Aplazada | Alta (7.1) | 1.2% | — | Tufantunc Ssh-mcpAI | 26/4/2026 | 17/6/2026 | A security vulnerability has been detected in tufantunc ssh-mcp up to 1.5.0. The affected element is the function shell.write of the file src/index.ts. Such manipulation of the argument Description leads to command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be… | |
| Aplazada | Baja (1.9) | 0.15% | — | Tufantunc Ssh-mcpAI | 26/4/2026 | 17/6/2026 | A weakness has been identified in tufantunc ssh-mcp up to 1.5.0. Impacted is an unknown function of the file src/index.ts of the component Command Line Handler. This manipulation causes insufficiently protected credentials. The attack is restricted to local execution. The exploit has been made available to the public… |