Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
561 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.38% | — | Ckan MCP ServerAI | 21/8/2026 | 9/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip… | |
| Pendiente de análisis | Crítica (9.8) | 1.7% | — | NEO MJSAIAI MCPAI | 20/8/2026 | 3/9/2026 | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution… | |
| Aplazada | Alta (8.1) | 0.49% | — | Apify MCP ServerAI | 18/8/2026 | 18/9/2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor… | |
| Analizada | Crítica (9.8) | 0.69% | — | Apache Skywalking MCP | 18/8/2026 | 2/9/2026 | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | |
| Aplazada | Baja (2.1) | 1.8% | — | Kylecui NetforensicmcpAI | 17/8/2026 | 20/8/2026 | A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argument interface/protocol can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the… | |
| Aplazada | Media (5.3) | 0.37% | — | Jae-jae Fetcher-mcpAI | 17/8/2026 | 20/8/2026 | A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The project was… | |
| Aplazada | Baja (2.1) | 0.37% | — | Kira-pgr PromptshopmcpAI | 17/8/2026 | 20/8/2026 | A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the file server.py of the component Image-Toolkit-MCP-Server. Performing a manipulation of the argument image_url results in server-side request forgery. The attack may be… | |
| Aplazada | Baja (2.1) | 0.37% | — | Jkawamoto MCP Florence2AI | 17/8/2026 | 20/8/2026 | A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init__.py. This manipulation of the argument src causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. It… | |
| Aplazada | Baja (1.9) | 1.2% | — | Jiantao88 Android-mcp-serverAI | 17/8/2026 | 20/8/2026 | A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_process.exec of the file build/index.js of the component Command Execution. Executing a manipulation of the argument… | |
| Aplazada | Baja (2) | 0.30% | — | Jij-inc Jij-mcp-serverAI | 17/8/2026 | 20/8/2026 | A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made public and could be… | |
| Aplazada | Baja (2.1) | 0.39% | — | Iatsiuk Pptr-mcpAI | 16/8/2026 | 20/8/2026 | A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts of the component execute Tool. The manipulation results in code injection. The attack may be launched remotely. The exploit has been released to the public and may be… | |
| Aplazada | Baja (2.1) | 0.37% | — | Graphlit-mcp-serverAI | 16/8/2026 | 20/8/2026 | A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and… | |
| Aplazada | Media (5.3) | 0.37% | — | Gomarble-ai Facebook-ads-mcp-serverAI | 16/8/2026 | 20/8/2026 | A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659.… | |
| Aplazada | Crítica (9.8) | 0.96% | — | Doobidoo Mcp-memory-serviceAI | 14/8/2026 | 16/9/2026 | mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote attacker can upload… | |
| Aplazada | Media (6.5) | 0.19% | — | Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCacheKey to collide and an attacker to prime… | |
| Aplazada | Media (5.3) | 0.38% | — | Ondata Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-host and URL-userinfo… | |
| Aplazada | Baja (3.7) | 0.36% | — | Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response,… | |
| Aplazada | Alta (7.1) | 0.16% | — | Neuro-cortex-memory Cortex MCP ServerAI | 14/8/2026 | 18/9/2026 | The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is… | |
| Aplazada | Baja (1.9) | 0.14% | — | Feedmob Fm-mcp-serversAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be… | |
| Aplazada | Baja (2.1) | 0.37% | — | Eyaushev Swagger-testcase-mcpAI | 14/8/2026 | 18/8/2026 | A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the function loadSource of the file src/utils/swagger-parser.ts of the component fetch_swagger. Performing a manipulation results in server-side request forgery. The attack is… | |
| Aplazada | Media (5.5) | 0.47% | — | Modelcontextprotocol MCP RDF ExplorerAI | 13/8/2026 | 14/8/2026 | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.37% | — | Enzovezzaro Mcp-dominican-layerAI | 13/8/2026 | 14/8/2026 | A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of the file src/index.ts of the component PDF Parsing. Performing a manipulation of the argument pdfUrl results in server-side request forgery. It is possible to initiate the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Enzovezzaro Mcp-dominican-layerAI | 13/8/2026 | 18/8/2026 | A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/index.ts of the component parse-csv tool. This manipulation of the argument csvUrl causes server-side request forgery. The attack is possible to be… | |
| Aplazada | Alta (7.4) | 0.49% | — | Auth-fetch-mcpAI | 13/8/2026 | 18/9/2026 | auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests to private and loopback addresses. However, the `isPrivateV6()` function fails to detect IPv4-mapped IPv6 loopback… | |
| Aplazada | Media (4.3) | 0.28% | — | Jshookmcp JshookAI | 13/8/2026 | 18/9/2026 | @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit authorization object allows private network access.… |