Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 17% | — | Xixianliang Harmonyos MCP Server | 8/2/2026 | 17/6/2026 | A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument text leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Analizada | Media (5.3) | 2.0% | — | Burtthecoder Maigret MCP Server | 8/2/2026 | 17/6/2026 | A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/index.ts of the component search_username. Executing a manipulation of the argument Username can lead to command injection. The attack may be launched remotely. Upgrading to version 1.0.13 is able to… | |
| Aplazada | Alta (7.8) | 0.74% | — | Mcp-server-siri-shortcutsAI | 23/1/2026 | 17/6/2026 | mcp-server-siri-shortcuts shortcutName Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of mcp-server-siri-shortcuts. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Aplazada | Crítica (9.8) | 2.0% | — | Ollama MCP ServerAI | 23/1/2026 | 17/6/2026 | Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ollama MCP Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the… | |
| Aplazada | Crítica (9.8) | 2.2% | — | Framelink Figma MCP ServerAI | 23/1/2026 | 17/6/2026 | Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Framelink Figma MCP Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Media (6.5) | 0.56% | — | Busymac PAL MCP Server | 12/1/2026 | 17/6/2026 | A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that uses exact string matching against a blacklist of system directories. Attackers… | |
| Aplazada | Alta (7.2) | 1.2% | — | Microsoft Playwright MCP ServerAI | 7/1/2026 | 7/10/2026 | Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool… | |
| Analizada | Alta (7.5) | 0.53% | — | Zcaceres Markdownify MCP Server | 10/12/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before. This vulnerability allows an attacker to bypass private IP restrictions through hostname-based bypass and HTTP redirect chains, enabling access to internal network… | |
| Analizada | Alta (7.5) | 0.45% | — | Zcaceres Fetch MCP Server | 9/12/2025 | 17/6/2026 | fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources. | |
| Analizada | Alta (8.8) | 1.5% | — | Suyogs Mcp-server-kubernetes | 3/12/2025 | 17/6/2026 | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes MCP Server. The tool accepts user-provided commands in both array and string formats. When a string format is provided, it… | |
| Aplazada | Media (5.4) | 0.22% | — | Splunk MCP ServerAI | 3/12/2025 | 17/6/2026 | In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command allowlist controls in MCP by embedding SPL commands as sub-searches, leading to unauthorized actions beyond the intended MCP restrictions. | |
| Aplazada | Crítica (9.1) | 5.3% | — | Hexstrike AI MCP ServerAI | 30/11/2025 | 17/6/2026 | By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to… | |
| Analizada | Media (6.5) | 0.35% | — | Baryhuang AWS Resources MCP Server | 18/11/2025 | 17/6/2026 | A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input validation in the execute_query method. The vulnerability stems from the exposure of dangerous Python built-in functions (__import__, getattr, hasattr) in the execution… | |
| Analizada | Media (6.5) | 0.86% | — | MCP Server FOR Data Exploration Project MCP Server FOR Data Exploration | 18/11/2025 | 17/6/2026 | A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_eval() function (src/mcp_server_ds/server.py:108). The function uses Python's exec() to execute user-supplied scripts but fails to restrict the __builtins__ dictionary in the… | |
| Aplazada | Alta (7.8) | 1.3% | — | Evernote MCP ServerAI | 6/11/2025 | 17/6/2026 | evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of evernote-mcp-server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Media (5.4) | 0.37% | — | Apache Doris MCP Server | 5/11/2025 | 17/6/2026 | An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions. Impact: Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications. Recommended… | |
| Aplazada | Crítica (9.8) | 2.8% | — | Win-cli-mcp-serverAI | 29/10/2025 | 17/6/2026 | win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of win-cli-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (5.4) | 0.26% | — | Jenkins MCP Server | 29/10/2025 | 17/6/2026 | Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access. | |
| Aplazada | Alta (8) | 5.8% | — | Framelink Figma MCP ServerAI | 8/10/2025 | 17/6/2026 | Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl command. The vulnerable endpoint fails to properly sanitize user-supplied input,… | |
| Analizada | Crítica (9.8) | 2.5% | — | Srmorete ADB MCP Server | 25/9/2025 | 30/9/2026 | ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has… | |
| Aplazada | Alta (7.4) | 0.22% | — | Neo4j Cypher MCP ServerAINeo4jAI | 11/9/2025 | 17/6/2026 | DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for… | |
| Analizada | Alta (7.5) | 0.32% | — | Litmus MCP Server | 10/9/2025 | 17/6/2026 | An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Akoskm Create-mcp-server-stdioAI | 8/9/2025 | 17/6/2026 | @akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. The MCP Server exposes the… | |
| Aplazada | Alta (8.9) | 1.4% | — | Github Kanban MCP ServerAINodejsAIGithub GHAI | 14/7/2025 | 17/6/2026 | GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version 0.3.0 of the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition… | |
| Aplazada | Alta (7.5) | 2.2% | — | Mcp-server-kubernetes MCP Server KubernetesAI | 8/7/2025 | 17/6/2026 | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.execSync, enabling an attacker to inject… |