Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.22% | — | Tiger-gh-mcp-serverAI | 27/8/2026 | 23/9/2026 | tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Telnyx MCP ServerAI | 27/8/2026 | 24/9/2026 | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not fail when they were absent, so a request… | |
| Aplazada | Crítica (9.1) | 0.73% | — | Nextcloud MCP ServerAI | 25/8/2026 | 9/9/2026 | Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults to None and startup validation does not… | |
| Aplazada | Media (5.7) | 0.38% | — | Ckan MCP ServerAI | 21/8/2026 | 9/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip… | |
| Aplazada | Alta (8.1) | 0.49% | — | Apify MCP ServerAI | 18/8/2026 | 18/9/2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor… | |
| Aplazada | Baja (1.9) | 1.2% | — | Jiantao88 Android-mcp-serverAI | 17/8/2026 | 20/8/2026 | A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_process.exec of the file build/index.js of the component Command Execution. Executing a manipulation of the argument… | |
| Aplazada | Baja (2) | 0.30% | — | Jij-inc Jij-mcp-serverAI | 17/8/2026 | 20/8/2026 | A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made public and could be… | |
| Aplazada | Baja (2.1) | 0.37% | — | Graphlit-mcp-serverAI | 16/8/2026 | 20/8/2026 | A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and… | |
| Aplazada | Media (5.3) | 0.37% | — | Gomarble-ai Facebook-ads-mcp-serverAI | 16/8/2026 | 20/8/2026 | A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659.… | |
| Aplazada | Media (6.5) | 0.19% | — | Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCacheKey to collide and an attacker to prime… | |
| Aplazada | Media (5.3) | 0.38% | — | Ondata Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-host and URL-userinfo… | |
| Aplazada | Baja (3.7) | 0.36% | — | Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response,… | |
| Aplazada | Alta (7.1) | 0.16% | — | Neuro-cortex-memory Cortex MCP ServerAI | 14/8/2026 | 18/9/2026 | The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is… | |
| Aplazada | Baja (1.9) | 0.14% | — | Feedmob Fm-mcp-serversAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be… | |
| Aplazada | Baja (1.9) | 0.15% | — | Phialsbasement Koboldcpp-mcp-serverAI | 9/8/2026 | 12/8/2026 | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It is possible to launch the attack on the… | |
| Aplazada | Baja (1.9) | 0.17% | — | Handwriting-ocr-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performing a manipulation of the argument File results in path traversal. Attacking locally is a… | |
| Aplazada | Baja (1.9) | 0.15% | — | Ks-gen-ai Jira-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The project was informed of… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aliyun Alibabacloud-dataworks-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched… | |
| Aplazada | Baja (1.9) | 0.17% | — | Bazylhorsey Obsidian-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report… | |
| Aplazada | Baja (1.9) | 0.17% | — | Aktsmm Skill-ninja-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to… | |
| Aplazada | Baja (1.9) | 0.17% | — | Incomestreamsurfer ROO Code Memory Bank MCP ServerAI | 9/8/2026 | 14/8/2026 | A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation… | |
| Aplazada | Baja (1.9) | 0.17% | — | Astralisone Rive-mcp-server-coreAI | 8/8/2026 | 12/8/2026 | A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The… | |
| Aplazada | Baja (1.9) | 1.2% | — | Kino-kafkaesque Ssh-mcp-serverAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. Performing a manipulation of the argument host/username results in command injection. The attack requires a… | |
| Analizada | Media (5.7) | 0.16% | — | Amazon Documentdb MCP Server | 5/8/2026 | 10/8/2026 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To… | |
| Analizada | Media (6.3) | 0.18% | — | Amazon AWS Transform MCP Server | 5/8/2026 | 10/8/2026 | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should… |