Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.34% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation. | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Openshift Oauth-serverAIGolang.org X TextAI | 1/9/2026 | 6/10/2026 | A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the… | |
| Aplazada | Media (5.5) | 0.59% | — | Boxpositron With-context-mcpAI | 27/8/2026 | 28/8/2026 | A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used.… | |
| Aplazada | Media (5.5) | 0.69% | — | Mcp-file-context-serverAI | 27/8/2026 | 28/8/2026 | A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to initiate the attack remotely. The exploit is… | |
| Pendiente de análisis | Alta (7) | 0.24% | — | Sonicwall NetextenderAI | 25/8/2026 | 28/8/2026 | The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths. | |
| Pendiente de análisis | Alta (8.8) | 0.50% | — | Sonicwall NetextenderAI | 25/8/2026 | 31/8/2026 | A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root. | |
| Aplazada | Alta (8.7) | 0.51% | — | Ech0AIGolang X/textAI | 25/8/2026 | 31/8/2026 | Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request. The header is passed unfiltered to go-i18n's NewLocalizer, which internally calls golang.org/x/text/language.ParseAcceptLanguage. The CVE-2022-32149 mitigation in… | |
| Aplazada | Media (4.2) | 0.12% | — | Litextension Wordpress PluginAI | 21/8/2026 | 26/8/2026 | The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF). | |
| Analizada | Crítica (9.1) | 0.75% | — | Splunk Model Context Protocol Server | 19/8/2026 | 24/8/2026 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking… | |
| Aplazada | Media (6.4) | 0.49% | — | ContextAI | 18/8/2026 | 24/9/2026 | Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate… | |
| Pendiente de análisis | Alta (7.3) | 0.44% | — | Opentext Directory ServicesAI | 17/8/2026 | 1/9/2026 | A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. | |
| Aplazada | Media (5.5) | 0.47% | — | Modelcontextprotocol MCP RDF ExplorerAI | 13/8/2026 | 14/8/2026 | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Form Processor Field HtmlareaAIPerl Html TidyAIPerl Locale MaketextAI | 13/8/2026 | 26/8/2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting… | |
| Aplazada | Crítica (9.1) | 0.63% | — | Html FormhandlerAIPerlAILocale MaketextAI | 13/8/2026 | 8/9/2026 | HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argument to the language handle as the… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Use-context-selectorAI | 10/8/2026 | 9/9/2026 | use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdbbb4db96006424d674124 that executed remote attacker-controlled code on developer… | |
| Aplazada | Media (5.1) | 3.9% | — | Kirachon Context-engineAI | 8/8/2026 | 12/8/2026 | A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue.… | |
| Aplazada | Media (6.5) | 0.33% | — | It-recht-kanzlei Legal Text ConnectorAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. | |
| Aplazada | Media (4.4) | 0.31% | — | Contact Form 7 Dynamic Text ExtensionAI | 5/8/2026 | 12/8/2026 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. This makes it possible… | |
| Aplazada | Baja (1.9) | 0.14% | — | Textplus Text Message AND Call APPAI | 3/8/2026 | 12/8/2026 | A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly… | |
| Aplazada | Media (6.5) | 0.47% | — | Contact Form 7 Dynamic Text ExtensionAI | 22/7/2026 | 29/9/2026 | The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible… | |
| Aplazada | Media (6.9) | 0.43% | — | Huggingface Text-generation-inferenceAI | 16/7/2026 | 16/7/2026 | text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by supplying a crafted image_url value in chat… | |
| Aplazada | Media (5.3) | 0.36% | — | Context BlogAI | 11/7/2026 | 13/7/2026 | The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes it possible for unauthenticated attackers to extract the content of password-protected posts. | |
| Aplazada | Baja (2.1) | 0.51% | — | Tumf Mcp-text-editorAI | 9/7/2026 | 9/7/2026 | A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validate_file_path of the file mcp_text_editor/text_editor.py. Such manipulation of the argument file_path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed… | |
| Pendiente de análisis | Crítica (9.4) | 0.22% | — | Anthropic Model Context ProtocolAI | 13/6/2026 | 23/7/2026 | The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing… | |
| Pendiente de análisis | Media (5.3) | 0.41% | — | Golang Net/textprotoAI | 2/6/2026 | 22/7/2026 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. |