Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

556 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.17%—Airano MCP BridgeAI2/10/20263/10/2026
Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Airano MCP Bridge: from n/a through 2.11.0.
AplazadaMedia (5.5)0.29%—Modelcontextprotocol MCP Server FetchAIModelcontextprotocol MCP Server EverythingAI2/10/20262/10/2026
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack…
AplazadaAlta (7.6)0.29%—Office Powerpoint MCP ServerAI1/10/20262/10/2026
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or…
Pendiente de análisisMedia (6.9)0.14%—Amazon Security Agent MCP ServerAI1/10/20261/10/2026
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan…
AplazadaAlta (8.8)0.23%—Bytecore MCP Connector FOR AI ToolsAI1/10/20261/10/2026
Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.
AplazadaAlta (8.8)0.38%—Bytecore Stack MCP Connector FOR AI ToolsAI1/10/20263/10/2026
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's…
AplazadaMedia (6.8)0.36%—Webo MCPAI30/9/202630/9/2026
Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.
AplazadaMedia (6.5)0.28%—MCP Content Manager LiteAI30/9/202630/9/2026
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
AplazadaBaja (2.1)1.1%—0xshariq Github-mcp-serverAI30/9/20262/10/2026
A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be…
AplazadaCrítica (9.8)0.43%—Metatool AI MetamcpAI29/9/202629/9/2026
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
AplazadaCrítica (9.1)0.31%—Metatool AI MetamcpAI29/9/202630/9/2026
metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint…
AplazadaMedia (5.9)0.19%—Mark3labs MCP Filesystem ServerAI29/9/202630/9/2026
mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved…
AplazadaAlta (8.6)0.24%—Mcp-chrome-bridgeAI29/9/202630/9/2026
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content…
Pendiente de análisisAlta (8.6)0.37%—Google MCP Toolbox FOR DatabasesAI29/9/202629/9/2026
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks…
AplazadaAlta (8.4)0.70%—Token Optimizer MCPAI28/9/20261/10/2026
Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute…
AplazadaMedia (5.3)0.45%—Token Optimizer MCPAI28/9/202630/9/2026
Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, the dashboard HTTP server in token-optimizer-mcp exposes /api/session-summary and /api/session-events with no authentication middleware — any…
AplazadaAlta (7.1)0.21%—Fast-mcp-telegramAI28/9/20261/10/2026
fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's…
Pendiente de análisisMedia (4.6)0.13%—Zscaler MCP ServerAI28/9/202628/9/2026
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
AplazadaBaja (2.3)0.11%—Utcp-mcpAI27/9/202630/9/2026
utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call template's mcpServers configuration without the ensure_secure_url validation that the HTTP-family plugins apply, so the HTTPS/WSS-or-loopback rule is not enforced. A call template naming a…
AplazadaBaja (2.7)0.19%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending…
AplazadaBaja (2.7)0.17%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by…
AplazadaAlta (8.8)0.14%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator…
Pendiente de análisisBaja (2.7)0.25%—Rapid7 Bulk Export MCPAI25/9/202625/9/2026
Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argument reaching the function via the `check_rapid7_export_status` and…
AplazadaSin puntuar0.25%—Geelen Mcp-remoteAI24/9/202624/9/2026
An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts
AplazadaAlta (8.8)0.53%—Geelen MCP RemoteAI24/9/202625/9/2026
An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions