Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 331 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaSin puntuar0.25%—Geelen Mcp-remoteAI24/9/202624/9/2026
An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts
AplazadaAlta (8.8)0.53%—Geelen MCP RemoteAI24/9/202625/9/2026
An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions
AplazadaCrítica (9.8)0.47%—Geelen Mcp-remoteAI24/9/202629/9/2026
An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function
AplazadaAlta (7.5)0.47%—Geelen Mcp-remoteAI24/9/202624/9/2026
An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components
AplazadaCrítica (9.1)0.35%—Mcp-remoteAI24/9/202625/9/2026
mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header
AplazadaCrítica (9.6)78%—Mcp-remoteAI9/7/202517/6/2026
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL