Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
561 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.32% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 28/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because it interprets the authority differently from the Requests connection layer in the header-based Jira and Confluence URL authentication… | |
| Analizada | Alta (8.3) | 0.53% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 28/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), and affected Confluence attachment call sites omit base_dir, allowing attacker-selected writes within the working directory. This Python… | |
| Analizada | Media (6.5) | 0.37% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 28/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server opens the selected file and uploads it to an Atlassian issue or page,… | |
| Analizada | Alta (8.3) | 0.29% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and used to construct Atlassian fetchers without calling validate_url_for_ssrf. A caller… | |
| Analizada | Alta (7.5) | 0.27% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connection. An unauthenticated caller can use a DNS-rebinding hostname that… | |
| Analizada | Alta (8.5) | 0.32% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 25/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher sessions created through the basic-auth and oauth_pat branches. If an attacker-controlled or compromised configured Atlassian… | |
| Analizada | Alta (8.3) | 0.35% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced server-local file. A permitted MCP caller can upload sensitive host files to an… | |
| Analizada | Alta (7.7) | 0.34% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted… | |
| Analizada | Media (6.5) | 0.30% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 25/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace administrator-configured allowlists, and caller-provided project or space clauses can suppress the configured restriction. A… | |
| Analizada | Alta (8.3) | 0.24% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence search uses an incomplete case-sensitive space check, and Jira board APIs omit… | |
| Analizada | Media (6.1) | 0.11% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. On systems with a permissive umask,… | |
| Analizada | Crítica (10) | 0.29% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator's globally configured Jira or Confluence credentials. A network… | |
| Analizada | Alta (8.8) | 0.32% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatched. A client that knows a hidden tool name can directly invoke excluded read,… | |
| Analizada | Alta (7.5) | 0.30% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 29/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf checks a hostname's resolved addresses, but Requests and urllib3 resolve the hostname again when connecting. A caller can use a short-lived DNS answer that is public during… | |
| Aplazada | Alta (7.1) | 0.32% | — | Google Notebooklm MCPAI | 21/9/2026 | 24/9/2026 | NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-to-vault` endpoint, also exposed through the `batch_to_vault` MCP tool beginning in… | |
| Aplazada | Media (5.7) | 0.23% | — | Ondata Ckan MCP ServerAI | 21/9/2026 | 24/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS. Any caller-supplied `server_url` whose hostname *resolves* to an internal… | |
| Pendiente de análisis | Alta (8.4) | 0.25% | — | Mcp-for-stataAIStataAI | 21/9/2026 | 24/9/2026 | MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool… | |
| Aplazada | Baja (2.1) | 0.37% | — | Cowork Bench Pdf-tools-mcpAI | 20/9/2026 | 21/9/2026 | A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the component pdf-tools-mcp. Performing a manipulation of the argument pdf_file_path… | |
| Aplazada | Baja (2.1) | 0.43% | — | Mcphubx McphubAI | 20/9/2026 | 22/9/2026 | A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template Import Endpoint. The manipulation leads to improper privilege management. Remote exploitation of the attack is… | |
| Aplazada | Baja (2.1) | 0.47% | — | 0215andrewfeng Ace-mcpAI | 20/9/2026 | 21/9/2026 | A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manipulation of the argument projectRootPath/filePath can lead to path traversal. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.61% | — | 03-lovepreetksingh MCPAI | 20/9/2026 | 21/9/2026 | A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content leads to path traversal. The attack can be launched remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.47% | — | 00kisumi00 Mcp-file-analyzerAI | 20/9/2026 | 22/9/2026 | A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_csv_data MCP tool. This manipulation of the argument filename causes path traversal. Remote exploitation of the attack is… | |
| Aplazada | Baja (2.1) | 1.1% | — | 0-gaurav-0 Nexus-mcpAI | 20/9/2026 | 21/9/2026 | A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool. The manipulation of the argument url results in command injection. The attack may be performed… | |
| Aplazada | Crítica (9.4) | 0.51% | — | Obsidian WEB MCPAI | 17/9/2026 | 30/9/2026 | Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without authenticating a client. An unauthenticated remote caller who can… | |
| Aplazada | Alta (8.8) | 0.57% | — | MCP Documentation ServerAI | 17/9/2026 | 30/9/2026 | MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with START_WEB_UI enabled by default and WEB_PORT set to 3080. startWebServer uses… |