Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
–

74 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.29%—Modelcontextprotocol MCP Server FetchAIModelcontextprotocol MCP Server EverythingAI2/10/20262/10/2026
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack…
AplazadaMedia (4.8)0.13%—OnefetchAI27/9/202630/9/2026
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text,…
AplazadaMedia (6.8)0.24%—Etruel Wpematico RSS Feed FetcherAI27/9/202628/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (4.1)0.18%—Etruel Wpematico RSS Feed FetcherAI27/9/202628/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
AplazadaMedia (4.9)0.19%—Etruel Wpematico RSS Feed FetcherAI27/9/202628/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an…
AplazadaMedia (4.1)0.18%—Etruel Wpematico RSS Feed FetcherAI27/9/202628/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the…
AplazadaMedia (6.8)0.24%—Etruel Wpematico RSS Feed FetcherAI24/9/202624/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any…
AplazadaBaja (2.7)0.22%—Wpecom Wpeomatico RSS Feed FetcherAI24/9/202624/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including…
AplazadaMedia (6.8)0.24%—Wpematico RSS Feed FetcherAI24/9/202624/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Scripting attacks against higher-privileged users who review the campaign.
Pendiente de análisisMedia (5.3)0.82%—FetchmailAI21/9/20261/10/2026
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to…
AplazadaMedia (4.3)0.14%—Fetchdesigns Sign-up SheetsAI20/9/202621/9/2026
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
AplazadaMedia (5.1)0.35%—Cyberchitta Scrapling-fetch-mcpAI28/8/202628/8/2026
A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_page/s_fetch_pattern of the file src/scrapling_fetch_mcp/_fetcher.py. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. Upgrading to version…
AplazadaAlta (8.7)0.35%—Mcp-fetchAI26/8/202624/9/2026
mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed URL, which for a literal such as http://[::1]/ yields the bracketed string, and then tests it with net.isIP. That call returns zero for a bracketed value, so…
AplazadaAlta (8.8)0.69%—Etruel Wpematico RSS Feed FetcherAI22/8/202624/8/2026
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.37%—Jae-jae Fetcher-mcpAI17/8/202620/8/2026
A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The project was…
AplazadaAlta (7.4)0.49%—Auth-fetch-mcpAI13/8/202618/9/2026
auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests to private and loopback addresses. However, the `isPrivateV6()` function fails to detect IPv4-mapped IPv6 loopback…
AplazadaAlta (7.1)0.25%—Etruel Wpematico RSS Feed FetcherAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.
AplazadaMedia (5.5)1.2%—Microsoft Kiota-http-fetchlibraryAI19/6/202623/6/2026
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from cross-origin redirect targets, but the default…
AplazadaAlta (7.2)0.33%—Rent FetchAI18/2/202617/6/2026
The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all versions up to, and including, 0.32.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (6.5)0.19%—Ruhul Amin Content FetcherAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ruhul Amin Content Fetcher content-fetcher allows DOM-Based XSS.This issue affects Content Fetcher: from n/a through <= 1.1.
AplazadaAlta (7.1)0.42%—Fetch FTP ClientAI30/12/202517/6/2026
Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the application.
AnalizadaAlta (7.5)0.45%—Zcaceres Fetch MCP Server9/12/202517/6/2026
fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources.
AplazadaMedia (4.3)0.13%—JK Social Photo Fetcher Facebook Photo FetcherAI9/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in JK Social Photo Fetcher facebook-photo-fetcher allows Cross Site Request Forgery.This issue affects Social Photo Fetcher: from n/a through <= 3.0.4.
AplazadaMedia (5.9)0.22%—Etruel Wpematico RSS Feed FetcherAI9/12/202517/6/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
AplazadaCrítica (9.8)0.53%—Fetchdesigns Sign-up SheetsAI6/11/202517/6/2026
Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.2.