Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 3.0% | — | Radare2 MCP Server | 23/4/2026 | 17/6/2026 | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc… | |
| Aplazada | Crítica (9.4) | 0.64% | — | Excel-mcp-serverAI | 21/4/2026 | 17/6/2026 | excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated attacker on the… | |
| Analizada | Media (5.3) | 0.47% | — | Apache Doris MCP Server | 20/4/2026 | 7/10/2026 | Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not… | |
| Pendiente de análisis | Alta (7.2) | 0.28% | — | Splunk MCP ServerAI | 15/4/2026 | 17/6/2026 | In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.<br><br>The vulnerability would require either local access to the log files or… | |
| Analizada | Alta (8.1) | 0.42% | — | Suyogs Mcp-server-kubernetes | 15/4/2026 | 17/6/2026 | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior contain an argument injection vulnerability in the port_forward tool in src/tools/port_forward.ts, where a kubectl command is constructed via string concatenation with user-controlled input and then… | |
| Pendiente de análisis | Crítica (9.8) | 2.3% | 💥 PoC | Amazon Mcp-serverAI | 11/4/2026 | 17/6/2026 | aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed… | |
| Pendiente de análisis | Crítica (9.8) | 2.3% | — | Aws-mcp-serverAI | 11/4/2026 | 17/6/2026 | aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed commands… | |
| Analizada | Alta (8.1) | 0.34% | — | Apollographql Apollo MCP Server | 9/4/2026 | 17/6/2026 | Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on incoming HTTP requests when using StreamableHTTP transport. In configurations where an HTTP-based MCP server is run on localhost without… | |
| Aplazada | Baja (1.9) | 1.1% | — | Awwaiid Mcp-server-taskwarriorAI | 9/4/2026 | 24/7/2026 | A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. The attack must be carried out locally. The exploit has been disclosed publicly and… | |
| Aplazada | Media (5.5) | 2.1% | — | Suvarchal Docker-mcp-serverAI | 7/4/2026 | 24/7/2026 | A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Alta (8.1) | 0.43% | 💥 PoC | Pab1it0 Azure Data Explorer MCP Server | 27/3/2026 | 17/6/2026 | Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP… | |
| Aplazada | Baja (1.9) | 1.4% | — | Sigmade Git-mcp-serverAI | 20/3/2026 | 17/6/2026 | A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function child_process.exec of the file src/gitUtils.ts of the component show_merge_diff/quick_merge_summary/show_file_diff. The manipulation results in os command injection. The… | |
| Analizada | Media (5.7) | 0.30% | — | Ondata Ckan MCP Server | 20/3/2026 | 17/6/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_package_search and sparql_query that accept a base_url parameter, making HTTP requests to arbitrary endpoints without restriction. A CKAN portal client has no legitimate reason to contact cloud metadata… | |
| Aplazada | Crítica (9.8) | 2.1% | — | Kubectl-mcp-serverAI | 16/3/2026 | 17/6/2026 | A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters. | |
| Analizada | Media (6.8) | 0.18% | — | Amazon AWS API MCP Server | 16/3/2026 | 17/6/2026 | Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue,… | |
| Aplazada | Baja (1.9) | 1.1% | — | Hypermodel Labs MCP Server Auto CommitAI | 16/3/2026 | 17/6/2026 | A vulnerability was determined in hypermodel-labs mcp-server-auto-commit 1.0.0. Affected by this vulnerability is the function getGitChanges of the file index.ts. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch… | |
| Aplazada | Baja (2.1) | 1.8% | — | Aviashbole Quip-mcp-serverAI | 16/3/2026 | 17/6/2026 | A vulnerability has been found in AvinashBole quip-mcp-server 1.0.0. Affected by this vulnerability is the function setupToolHandlers of the file src/index.ts. Such manipulation leads to command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (4.7) | 0.24% | — | Homeassistant-ai Home Assistant MCP Server | 11/3/2026 | 17/6/2026 | ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth endpoint and convince the server operator to follow a crafted authorization URL could execute JavaScript in the… | |
| Analizada | Media (5.3) | 0.34% | — | Homeassistant-ai Home Assistant MCP Server | 11/3/2026 | 17/6/2026 | ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/api/config with no URL validation. An unauthenticated attacker can submit arbitrary URLs to perform internal network reconnaissance via an… | |
| Analizada | Alta (8.8) | 0.89% | 💥 PoC | Microsoft Azure MCP Server | 10/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.3) | 0.24% | — | Lupinlin1 Jimeng WEB MCP Server | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allows an attacker to obtain sensitive information. | |
| Aplazada | Baja (2.1) | 1.9% | — | Ryuzakishinji Biome-mcp-serverAI | 7/3/2026 | 17/6/2026 | A security flaw has been discovered in RyuzakiShinji biome-mcp-server up to 1.0.0. Affected by this issue is some unknown functionality of the file biome-mcp-server.ts. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be… | |
| Aplazada | Alta (8.3) | 0.49% | — | Ebay API MCP ServerAI | 21/2/2026 | 17/6/2026 | eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to Environment Variable Injection through the updateEnvFile function. The ebay_set_user_tokens tool allows updating the .env file with new tokens. The updateEnvFile… | |
| Aplazada | Alta (7.5) | 1.4% | — | Salesforce Sf-mcp-serverAI | 11/2/2026 | 17/6/2026 | sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to unsafe use of child_process.exec when constructing Salesforce CLI commands with user-controlled input. Successful exploitation allows attackers to execute arbitrary shell… | |
| Analizada | Baja (2.1) | 3.8% | — | R-huijts Xcode MCP Server | 8/2/2026 | 17/6/2026 | A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the argument args results in command injection. It is possible to launch the attack… |