Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.74% | — | Mcp-server-siri-shortcutsAI | 23/1/2026 | 17/6/2026 | mcp-server-siri-shortcuts shortcutName Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of mcp-server-siri-shortcuts. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Aplazada | Alta (8.8) | 1.3% | — | MCP Manager FOR Claude DesktopAI | 23/1/2026 | 17/6/2026 | MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability. This vulnerability allows remote attackers to bypass the sandbox on affected installations of MCP Manager for Claude Desktop. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Crítica (9.8) | 1.9% | — | Github-kanban-mcpAI | 23/1/2026 | 17/6/2026 | github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Aplazada | Crítica (9.8) | 3.5% | — | Gemini-mcp-toolAI | 23/1/2026 | 17/6/2026 | gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of gemini-mcp-tool. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the… | |
| Aplazada | Crítica (9.8) | 2.0% | — | Ollama MCP ServerAI | 23/1/2026 | 17/6/2026 | Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ollama MCP Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the… | |
| Aplazada | Crítica (9.8) | 2.2% | — | Framelink Figma MCP ServerAI | 23/1/2026 | 17/6/2026 | Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Framelink Figma MCP Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Crítica (9.8) | 68% | 💥 Exploit | Mcpjam Inspector | 16/1/2026 | 17/6/2026 | MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default… | |
| Analizada | Media (6.5) | 0.56% | — | Busymac PAL MCP Server | 12/1/2026 | 17/6/2026 | A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that uses exact string matching against a blacklist of system directories. Attackers… | |
| Analizada | Crítica (10) | 2.1% | — | Gongrzhe Terminal-controller-mcp | 7/1/2026 | 17/6/2026 | A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input. | |
| Analizada | Alta (7.5) | 0.62% | — | Sylphx Filesystem MCP | 7/1/2026 | 16/9/2026 | @sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path validation mechanism: the resolvePath… | |
| Analizada | Alta (7.5) | 0.63% | — | Efforthye Fast-filesystem-mcp | 7/1/2026 | 17/6/2026 | fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their actual physical paths. The safePath and isPathAllowed functions use… | |
| Analizada | Media (6.5) | 0.97% | — | Sonirico Mcp-shell | 7/1/2026 | 17/6/2026 | A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string. | |
| Aplazada | Alta (7.2) | 1.2% | — | Microsoft Playwright MCP ServerAI | 7/1/2026 | 7/10/2026 | Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool… | |
| Analizada | Alta (8.7) | 0.44% | — | Lfprojects MCP Typescript SDK | 5/1/2026 | 14/7/2026 | Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can… | |
| Analizada | Alta (7.5) | 0.53% | — | Zcaceres Markdownify MCP Server | 10/12/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before. This vulnerability allows an attacker to bypass private IP restrictions through hostname-based bypass and HTTP redirect chains, enabling access to internal network… | |
| Analizada | Alta (7.5) | 0.45% | — | Zcaceres Fetch MCP Server | 9/12/2025 | 17/6/2026 | fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources. | |
| Analizada | Alta (8.8) | 1.5% | — | Suyogs Mcp-server-kubernetes | 3/12/2025 | 17/6/2026 | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes MCP Server. The tool accepts user-provided commands in both array and string formats. When a string format is provided, it… | |
| Analizada | Alta (7.3) | 0.43% | — | Docker MCP Gateway | 3/12/2025 | 17/6/2026 | MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming transport mode, it is vulnerable to DNS rebinding. An attacker who can get a victim to visit a malicious website or be served a malicious advertisement can perform… | |
| Aplazada | Media (5.4) | 0.22% | — | Splunk MCP ServerAI | 3/12/2025 | 17/6/2026 | In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command allowlist controls in MCP by embedding SPL commands as sub-searches, leading to unauthorized actions beyond the intended MCP restrictions. | |
| Aplazada | Media (6.5) | 0.31% | — | Arcade MCPAI | 2/12/2025 | 17/6/2026 | Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret ("dev") that is never validated or overridden during normal server startup. As a result, any unauthenticated attacker who knows this default key can forge valid JWTs and… | |
| Analizada | Alta (7.6) | 0.51% | — | Lfprojects MCP Python SDK | 2/12/2025 | 17/6/2026 | The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without… | |
| Analizada | Alta (7.6) | 0.51% | — | Lfprojects MCP Typescript SDK | 2/12/2025 | 17/6/2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with… | |
| Analizada | Crítica (9.8) | 2.2% | — | Kapilduraphe MCP Watch | 1/12/2025 | 17/6/2026 | MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical Command Injection vulnerability in the cloneRepo method. The application passes the user-supplied githubUrl argument directly to a system shell via execSync without… | |
| Aplazada | Crítica (9.1) | 5.3% | — | Hexstrike AI MCP ServerAI | 30/11/2025 | 17/6/2026 | By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to… | |
| Analizada | Media (6.5) | 0.35% | — | Baryhuang AWS Resources MCP Server | 18/11/2025 | 17/6/2026 | A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input validation in the execute_query method. The vulnerability stems from the exposure of dangerous Python built-in functions (__import__, getattr, hasattr) in the execution… |