Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
561 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.48% | — | MCP AtlassianAIAtlassian ConfluenceAIAtlassian JiraAI | 12/8/2026 | 18/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through _upload_attachment_direct() without calling… | |
| Pendiente de análisis | Crítica (9.1) | 0.31% | 💥 PoC | MCP GrafanaAI | 11/8/2026 | 31/8/2026 | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at… | |
| Aplazada | Baja (2.1) | 0.40% | — | Dmitriiweb Article-scraper-mcpAI | 10/8/2026 | 12/8/2026 | A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-side request forgery. The attack may be performed from remote. The exploit is now public and may be… | |
| Aplazada | Media (5.5) | 0.50% | — | Adafap Api-mcpAI | 9/8/2026 | 12/8/2026 | A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to… | |
| Aplazada | Baja (1.9) | 0.15% | — | Phialsbasement Koboldcpp-mcp-serverAI | 9/8/2026 | 12/8/2026 | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It is possible to launch the attack on the… | |
| Aplazada | Baja (1.9) | 0.17% | — | Handwriting-ocr-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performing a manipulation of the argument File results in path traversal. Attacking locally is a… | |
| Aplazada | Baja (1.9) | 0.17% | — | Nikolaibibo Claude-comfyui-mcpAI | 9/8/2026 | 13/8/2026 | A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path traversal. An attack has to be approached locally. The project was informed of the… | |
| Aplazada | Baja (1.9) | 0.17% | — | Bartekke8it56w2 New-mcpAI | 9/8/2026 | 12/8/2026 | A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal. The attack requires local access. The… | |
| Aplazada | Baja (1.9) | 0.15% | — | Ks-gen-ai Jira-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The project was informed of… | |
| Aplazada | Media (4.8) | 0.17% | — | Pv-bhat Gemsuite-mcpAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_analyze. The manipulation of the argument file_path/file_paths results in path traversal. The… | |
| Aplazada | Baja (2.1) | 0.37% | — | Noctedefensor Ludus MCPAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the argument Source leads to server-side request forgery. The attack may be initiated remotely. The… | |
| Aplazada | Baja (1.9) | 0.17% | — | Noctedefensor Ludus MCPAI | 9/8/2026 | 13/8/2026 | A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a manipulation of the argument configPath/outputPath can lead to path traversal. The attack is restricted to local… | |
| Aplazada | Baja (1.9) | 0.17% | — | Ichigo3766 Image-gen-mcpAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal. The attack must be carried out locally. The project was informed of the problem… | |
| Aplazada | Baja (2.1) | 0.40% | — | Anubissbe Projecthub-mcpAI | 9/8/2026 | 13/8/2026 | A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the attack is possible. The project was… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aliyun Alibabacloud-dataworks-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched… | |
| Aplazada | Baja (1.9) | 0.17% | — | Automateyournetwork McpyatsAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried… | |
| Aplazada | Baja (1.9) | 0.16% | — | Adenot Mcp-google-searchAI | 9/8/2026 | 12/8/2026 | A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called… | |
| Aplazada | Media (4.8) | 0.17% | — | Pimzino Spec Workflow MCPAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version… | |
| Aplazada | Baja (1.9) | 1.1% | — | Nighttrek Ollama-mcpAI | 9/8/2026 | 12/8/2026 | A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed locally. This product is using a rolling… | |
| Aplazada | Baja (1.9) | 1.1% | — | Nighttrek Supabase-mcpAI | 9/8/2026 | 12/8/2026 | A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in command injection. The attack needs to be… | |
| Aplazada | Baja (1.9) | 1.1% | — | Nellyw8 Mcp4edaAI | 9/8/2026 | 12/8/2026 | A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project… | |
| Aplazada | Baja (1.9) | 0.17% | — | Bazylhorsey Obsidian-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report… | |
| Aplazada | Baja (1.9) | 0.17% | — | Angrysky56 Advanced-reasoning-mcpAI | 9/8/2026 | 14/8/2026 | A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes path traversal. The attack requires local access. The project was informed of the… | |
| Aplazada | Baja (1.9) | 1.1% | — | Andreahaku Codex MCPAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the argument model results in command injection. The attack requires a local approach.… | |
| Aplazada | Baja (1.9) | 0.17% | — | Aktsmm Skill-ninja-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to… |