Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 3.2% | — | Divyanshu-hash Gitpilot-mcpAI | 25/4/2026 | 17/6/2026 | A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of the file main.py. Such manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.3) | 3.0% | — | Radare2 MCP Server | 23/4/2026 | 17/6/2026 | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc… | |
| Aplazada | Crítica (9.4) | 0.64% | — | Excel-mcp-serverAI | 21/4/2026 | 17/6/2026 | excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated attacker on the… | |
| Analizada | Media (5.3) | 0.47% | — | Apache Doris MCP Server | 20/4/2026 | 7/10/2026 | Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not… | |
| Aplazada | Baja (2.3) | 0.39% | — | Mcp-neo4j-cypherAINeo4jAINeo4j ApocAI | 17/4/2026 | 17/6/2026 | mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using APOC CALL procedures, potentially allowing unauthorized write operations or server-side request forgery. This issue is fixed in version 0.6.0. | |
| Aplazada | Alta (8.7) | 0.57% | — | Mcp-frameworkAI | 16/4/2026 | 17/6/2026 | mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in the HTTP transport concatenates request body chunks into a string with no size limit. Although a maxMessageSize configuration value exists, it is never enforced in… | |
| Pendiente de análisis | Alta (7.2) | 0.28% | — | Splunk MCP ServerAI | 15/4/2026 | 17/6/2026 | In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.<br><br>The vulnerability would require either local access to the log files or… | |
| Analizada | Alta (8.1) | 0.42% | — | Suyogs Mcp-server-kubernetes | 15/4/2026 | 17/6/2026 | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior contain an argument injection vulnerability in the port_forward tool in src/tools/port_forward.ts, where a kubectl command is constructed via string concatenation with user-controlled input and then… | |
| Analizada | Media (5.3) | 0.35% | — | Mcphubx Mcphub | 14/4/2026 | 3/9/2026 | MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges. | |
| Analizada | Alta (7.1) | 0.54% | — | Apache Skywalking MCP | 13/4/2026 | 17/6/2026 | Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | |
| Pendiente de análisis | Crítica (9.8) | 2.3% | 💥 PoC | Amazon Mcp-serverAI | 11/4/2026 | 17/6/2026 | aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed… | |
| Pendiente de análisis | Crítica (9.8) | 2.3% | — | Aws-mcp-serverAI | 11/4/2026 | 17/6/2026 | aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed commands… | |
| Analizada | Alta (8.1) | 0.34% | — | Apollographql Apollo MCP Server | 9/4/2026 | 17/6/2026 | Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on incoming HTTP requests when using StreamableHTTP transport. In configurations where an HTTP-based MCP server is run on localhost without… | |
| Analizada | Alta (8.5) | 0.43% | — | N8n-mcp | 9/4/2026 | 17/6/2026 | n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and operations. Prior to 2.47.4, an authenticated Server-Side Request Forgery in n8n-mcp allows a caller holding a valid AUTH_TOKEN to cause the server to issue HTTP requests to… | |
| Aplazada | Baja (1.9) | 1.1% | — | Awwaiid Mcp-server-taskwarriorAI | 9/4/2026 | 24/7/2026 | A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. The attack must be carried out locally. The exploit has been disclosed publicly and… | |
| Aplazada | Media (5.5) | 0.50% | — | Atototo Api-lab-mcpAI | 9/4/2026 | 24/7/2026 | A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery. The attack is… | |
| Analizada | Alta (7.5) | 0.42% | — | Agentfront @frontmcp/adaptersAgentfront @frontmcp/sdkAgentfront FrontmcpFrontmcp Mcp-from-openapi | 8/4/2026 | 24/7/2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification… | |
| Aplazada | Media (5.5) | 2.1% | — | Idachev Mcp-javadcAI | 8/4/2026 | 24/7/2026 | A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. Such manipulation of the argument jarFilePath leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project… | |
| Analizada | Crítica (9.8) | 1.1% | — | Statamcp Stata-mcp | 8/4/2026 | 25/7/2026 | A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution. | |
| Analizada | Alta (7.6) | 0.20% | — | Lfprojects MCP Java SDK | 7/4/2026 | 24/7/2026 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent.… | |
| Aplazada | Media (5.5) | 2.1% | — | Suvarchal Docker-mcp-serverAI | 7/4/2026 | 24/7/2026 | A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Alta (8.8) | 0.45% | — | Mobilenexthq Mobile MCP | 6/4/2026 | 24/7/2026 | Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and… | |
| Aplazada | Baja (1.9) | 1.4% | — | Chrischinchilla Vale-mcpAI | 6/4/2026 | 24/7/2026 | A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. The exploit has been… | |
| Aplazada | Baja (1.9) | 1.4% | — | Braffolk Mcp-summarization-functionsAI | 6/4/2026 | 24/7/2026 | A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lead to os command injection. The attack requires local access. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.45% | — | Imprvhub Mcp-browser-agentAI | 6/4/2026 | 24/7/2026 | A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src/handlers.ts of the component URL Parameter Handler. The manipulation of the argument request.params.name/request.params.arguments leads to server-side request forgery.… |