Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 331 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | 0.25% | — | Geelen Mcp-remoteAI | 24/9/2026 | 24/9/2026 | An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts | |
| Aplazada | Alta (8.8) | 0.53% | — | Geelen MCP RemoteAI | 24/9/2026 | 25/9/2026 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions | |
| Aplazada | Crítica (9.8) | 0.47% | — | Geelen Mcp-remoteAI | 24/9/2026 | 29/9/2026 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function | |
| Aplazada | Alta (7.5) | 0.47% | — | Geelen Mcp-remoteAI | 24/9/2026 | 24/9/2026 | An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components | |
| Aplazada | Crítica (9.1) | 0.35% | — | Mcp-remoteAI | 24/9/2026 | 25/9/2026 | mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header | |
| Aplazada | Crítica (9.6) | 78% | — | Mcp-remoteAI | 9/7/2025 | 17/6/2026 | mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL |