Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.56% | — | Apache Doris MCP Server | 22/6/2026 | 6/10/2026 | Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if… | |
| Aplazada | Media (6.1) | 0.33% | — | Kubernetes KubectlAISuyogs Mcp-server-kubernetesAI | 11/6/2026 | 17/6/2026 | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags directly to kubectl without any allowlist, enabling a privilege escalation attack within Kubernetes environments. An attacker… | |
| Aplazada | Alta (8.8) | 0.60% | — | Suyogs Mcp-server-kubernetesAI | 11/6/2026 | 17/6/2026 | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes… | |
| Aplazada | Baja (2.1) | 0.21% | — | Designcomputer Mysql-mcp-serverAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2.1) | 0.21% | — | Indrasishbanerjee Aem-mcp-serverAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAssetMetadata of the file src/mcp-server.ts of the component Axios Request Flow. Executing a manipulation of the argument assetPath can lead to server-side request forgery.… | |
| Aplazada | Alta (7.8) | 0.21% | — | Roslyn Codelens MCP ServerAI | 29/5/2026 | 21/7/2026 | Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solution without any allowlist, signature check, or user confirmation;… | |
| Aplazada | Crítica (9.2) | 0.62% | — | Gitlab MCP ServerAI | 26/5/2026 | 24/7/2026 | GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response. The structural defect is that the SSE server stands up a stateful, mutation-capable RPC endpoint… | |
| Aplazada | Crítica (9.8) | 0.58% | — | Open Source Kubectl MCP ServerAI | 12/5/2026 | 17/6/2026 | An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page. | |
| Pendiente de análisis | Alta (8.7) | 0.44% | 💥 PoC | Code Runner MCP ServerAI | 12/5/2026 | 17/6/2026 | A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication on port 3088. An unauthenticated remote attacker can invoke the run-code MCP tool to supply arbitrary source code and execute it via… | |
| Aplazada | Alta (8.7) | 0.38% | — | Oracle MCP Server Helper ToolAI | 5/5/2026 | 17/6/2026 | Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server Helper Tool.… | |
| Aplazada | Baja (2.1) | 0.43% | — | Ravenwits Mcp-server-arangodbAI | 4/5/2026 | 17/6/2026 | A vulnerability has been found in ravenwits mcp-server-arangodb up to 0.4.7. This affects the function arango_backup of the file src/tools.ts of the component MCP Interface. Such manipulation of the argument outputDir leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 1.8% | — | R-huijts Mcp-server-rijksmuseumAI | 2/5/2026 | 17/6/2026 | A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument imageUrl results in os command injection. The attack is possible to be carried out… | |
| Aplazada | Baja (2.1) | 1.8% | — | Artmin96 Yii2-mcp-serverAI | 2/5/2026 | 17/6/2026 | A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be… | |
| Aplazada | Media (5.5) | 2.1% | — | Sunwood AI Labs Command Executor MCP ServerAI | 1/5/2026 | 17/6/2026 | A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.ts of the component MCP Interface. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.32% | — | Timbroddin Astro-mcp-serverAI | 1/5/2026 | 17/6/2026 | A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown function of the file src/index.ts of the component MCP Tool Query Construction. Performing a manipulation of the argument request.params.arguments results in sql injection. The attack may be initiated… | |
| Aplazada | Media (5.5) | 2.2% | — | Vetcoders MCP Server SemgrepAI | 30/4/2026 | 17/6/2026 | A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack… | |
| Aplazada | Media (5.5) | 2.1% | — | Polarvista Xcode-mcp-serverAI | 29/4/2026 | 17/6/2026 | A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection. The attack may be launched remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.62% | — | Geekgod382 Filesystem-mcp-serverAI | 29/4/2026 | 17/6/2026 | A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_tool. Such manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.59% | — | Eiceblue Spire-pdf-mcp-serverAI | 28/4/2026 | 24/7/2026 | A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulation of the argument filepath can lead to path traversal. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.59% | — | Eiceblue Spire-doc-mcp-serverAI | 28/4/2026 | 24/7/2026 | A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. The… | |
| Aplazada | Media (5.5) | 0.61% | — | Williamcloudqi Matlab-mcp-serverAI | 28/4/2026 | 17/6/2026 | A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can lead to path… | |
| Aplazada | Media (5.5) | 0.59% | — | Duartium Papers-mcp-serverAI | 28/4/2026 | 24/7/2026 | A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the function search_papers of the file src/main.py. Such manipulation of the argument topic leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be… | |
| Aplazada | Media (5.5) | 2.1% | — | Disler Aider-mcp-serverAI | 27/4/2026 | 17/6/2026 | A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py of the component aider_ai_code. This manipulation of the argument relative_editable_files causes command injection.… | |
| Analizada | Media (5.5) | 0.53% | — | Shadowclonelabs Glutamate MCP Servers | 27/4/2026 | 17/6/2026 | A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request… | |
| Aplazada | Media (5.5) | 2.1% | — | Toowiredd Chatgpt-mcp-serverAI | 26/4/2026 | 17/6/2026 | A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been made… |