Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 1.1% | — | Bazinga012 MCP Code ExecutorAI | 16/3/2026 | 17/6/2026 | A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function installDependencies of the file src/index.ts. Such manipulation leads to command injection. The attack can only be performed from a local environment. The exploit is publicly available and might be used.… | |
| Aplazada | Baja (1.9) | 1.1% | — | Hypermodel Labs MCP Server Auto CommitAI | 16/3/2026 | 17/6/2026 | A vulnerability was determined in hypermodel-labs mcp-server-auto-commit 1.0.0. Affected by this vulnerability is the function getGitChanges of the file index.ts. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch… | |
| Aplazada | Baja (2.1) | 1.8% | — | Aviashbole Quip-mcp-serverAI | 16/3/2026 | 17/6/2026 | A vulnerability has been found in AvinashBole quip-mcp-server 1.0.0. Affected by this vulnerability is the function setupToolHandlers of the file src/index.ts. Such manipulation leads to command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The… | |
| Aplazada | Baja (1.9) | 1.1% | — | 0xkoda WiremcpAI | 11/3/2026 | 17/6/2026 | A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js of the component Tshark CLI Command Handler. The manipulation results in os command injection. The attack needs to be approached locally. The exploit has been made… | |
| Analizada | Media (4.7) | 0.24% | — | Homeassistant-ai Home Assistant MCP Server | 11/3/2026 | 17/6/2026 | ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth endpoint and convince the server operator to follow a crafted authorization URL could execute JavaScript in the… | |
| Analizada | Media (5.3) | 0.34% | — | Homeassistant-ai Home Assistant MCP Server | 11/3/2026 | 17/6/2026 | ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/api/config with no URL validation. An unauthenticated attacker can submit arbitrary URLs to perform internal network reconnaissance via an… | |
| Analizada | Alta (8) | 1.5% | 💥 PoC | Mcp-atlassian MCP Atlassian | 10/3/2026 | 17/6/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory boundary enforcement. An attacker who can call this tool and supply or… | |
| Analizada | Alta (8.2) | 1.0% | 💥 Exploit | Sooperset MCP Atlassian | 10/3/2026 | 17/6/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated attacker who can reach the mcp-atlassian HTTP endpoint can force the server process to make outbound HTTP requests to an arbitrary attacker-controlled URL by supplying two… | |
| Analizada | Alta (8.8) | 0.89% | 💥 PoC | Microsoft Azure MCP Server | 10/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.3) | 0.24% | — | Lupinlin1 Jimeng WEB MCP Server | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allows an attacker to obtain sensitive information. | |
| Aplazada | Baja (2.1) | 1.9% | — | Ryuzakishinji Biome-mcp-serverAI | 7/3/2026 | 17/6/2026 | A security flaw has been discovered in RyuzakiShinji biome-mcp-server up to 1.0.0. Affected by this issue is some unknown functionality of the file biome-mcp-server.ts. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be… | |
| Analizada | Media (5.3) | 0.43% | — | Doobidoo Mcp-memory-service | 7/3/2026 | 17/6/2026 | mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns detailed system information including OS version, Python version, CPU count, memory totals, disk usage, and the full database filesystem path. When… | |
| Analizada | Media (5.3) | 4.5% | — | Phialsbasement MCP Nmap Server | 3/3/2026 | 17/6/2026 | A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from… | |
| Modificada | Alta (7) | 0.46% | — | Lfprojects MCP GO SDK | 26/2/2026 | 15/7/2026 | The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagged json:"method" would also match "Method", "METHOD", etc. This violated the… | |
| Aplazada | Alta (8.3) | 0.49% | — | Ebay API MCP ServerAI | 21/2/2026 | 17/6/2026 | eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to Environment Variable Injection through the updateEnvFile function. The ebay_set_user_tokens tool allows updating the .env file with new tokens. The updateEnvFile… | |
| Aplazada | Alta (7.5) | 1.4% | — | Salesforce Sf-mcp-serverAI | 11/2/2026 | 17/6/2026 | sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to unsafe use of child_process.exec when constructing Salesforce CLI commands with user-controlled input. Successful exploitation allows attackers to execute arbitrary shell… | |
| Aplazada | Media (5.8) | 0.24% | — | Mcp-run-pythonAI | 9/2/2026 | 17/6/2026 | The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the… | |
| Aplazada | Media (5.8) | 0.23% | — | Pydantic-aiAIPydantic Mcp-run-pythonAIDenoAI | 9/2/2026 | 17/6/2026 | The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix. | |
| Analizada | Baja (2.1) | 3.8% | — | R-huijts Xcode MCP Server | 8/2/2026 | 17/6/2026 | A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the argument args results in command injection. It is possible to launch the attack… | |
| Analizada | Baja (2.1) | 17% | — | Xixianliang Harmonyos MCP Server | 8/2/2026 | 17/6/2026 | A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument text leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Analizada | Media (5.3) | 2.0% | — | Burtthecoder Maigret MCP Server | 8/2/2026 | 17/6/2026 | A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/index.ts of the component search_username. Executing a manipulation of the argument Username can lead to command injection. The attack may be launched remotely. Upgrading to version 1.0.13 is able to… | |
| Analizada | Media (6.6) | 0.58% | — | Smn2gnt MCP Salesforce Connector | 6/2/2026 | 17/6/2026 | MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10. | |
| Aplazada | Baja (2.1) | 0.27% | — | Isaacwasserman MCP Vegalite ServerAI | 6/2/2026 | 17/6/2026 | A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component visualize_data. Such manipulation of the argument vegalite_specification leads to code injection. The attack may be… | |
| Analizada | Alta (7.8) | 1.0% | 💥 PoC | Coding-solo Godot MCP | 4/2/2026 | 17/6/2026 | Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a command injection vulnerability in godot-mcp allows remote code execution. The executeOperation function passed user-controlled input (e.g., projectPath) directly to exec(), which spawns a shell. An… | |
| Modificada | Alta (7.1) | 0.38% | — | Lfprojects MCP Typescript SDK | 4/2/2026 | 15/7/2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport… |