Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
25.937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.44% | — | Opensignlabs OpensignserverAI | 10/8/2026 | 26/8/2026 | A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The function writes IsDeclined, DeclineReason, and… | |
| Aplazada | Alta (7.5) | 0.65% | — | Opensignlabs OpensignserverAI | 10/8/2026 | 26/8/2026 | An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is… | |
| Aplazada | Alta (7.5) | 0.53% | — | Opensignlabs OpensignserverAI | 10/8/2026 | 26/8/2026 | A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records… | |
| Aplazada | Alta (7.5) | 0.61% | — | Opensignlabs OpensignserverAI | 10/8/2026 | 26/8/2026 | A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing any session… | |
| Aplazada | Media (5.4) | 0.24% | — | Cube-root Directory-serveAI | 10/8/2026 | 3/9/2026 | A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. | |
| Aplazada | Crítica (9.1) | 0.74% | — | Cube Root Directory ServeAI | 10/8/2026 | 28/8/2026 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. | |
| Pendiente de análisis | Media (6.5) | 0.43% | — | 389 Project 389 Directory ServerAI | 10/8/2026 | 14/8/2026 | A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to… | |
| Aplazada | Baja (1.9) | 0.15% | — | Phialsbasement Koboldcpp-mcp-serverAI | 9/8/2026 | 12/8/2026 | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It is possible to launch the attack on the… | |
| Aplazada | Baja (1.9) | 0.17% | — | Handwriting-ocr-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performing a manipulation of the argument File results in path traversal. Attacking locally is a… | |
| Aplazada | Baja (1.9) | 0.15% | — | Ks-gen-ai Jira-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The project was informed of… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aliyun Alibabacloud-dataworks-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched… | |
| Aplazada | Baja (1.9) | 0.17% | — | Bazylhorsey Obsidian-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report… | |
| Aplazada | Baja (1.9) | 0.17% | — | Aktsmm Skill-ninja-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to… | |
| Aplazada | Baja (1.9) | 0.17% | — | Incomestreamsurfer ROO Code Memory Bank MCP ServerAI | 9/8/2026 | 14/8/2026 | A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation… | |
| Aplazada | Baja (1.9) | 0.17% | — | Astralisone Rive-mcp-server-coreAI | 8/8/2026 | 12/8/2026 | A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The… | |
| Aplazada | Alta (8.6) | 0.21% | — | Pathling ServerAI | 7/8/2026 | 9/9/2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `exportUrl` and uses it as the remote FHIR Bulk Export endpoint without constraining it… | |
| Aplazada | Alta (8.7) | 0.41% | — | Pathling ServerAI | 7/8/2026 | 9/9/2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller with only coarse operation authorities to act on attacker-chosen resource families… | |
| Aplazada | Alta (8.7) | 0.41% | — | Pathling ServerAI | 7/8/2026 | 9/9/2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller with only coarse operation authorities to act on attacker-chosen resource families… | |
| Aplazada | Alta (8.7) | 0.54% | — | Pathling ServerAI | 7/8/2026 | 9/9/2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that is not validated against… | |
| Aplazada | Alta (8.7) | 0.62% | — | Pathling ServerAI | 7/8/2026 | 9/9/2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a caller who can obtain any valid async export job ID to supply `file` parameter values containing path traversal sequences.… | |
| Analizada | Media (6.5) | 0.45% | — | Dell Openmanage Server Administrator | 7/8/2026 | 8/8/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Crítica (9.8) | 0.53% | — | Dell Openmanage Server Administrator | 7/8/2026 | 8/8/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Aplazada | Baja (1.9) | 0.17% | — | Lspace-io Lspace-serverAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. Performing a manipulation of the argument filePath results in path… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Oauth ServerAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | |
| Aplazada | Baja (1.9) | 1.2% | — | Kino-kafkaesque Ssh-mcp-serverAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. Performing a manipulation of the argument host/username results in command injection. The attack requires a… |