Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 473 respecto a la semana anterior
Críticas / altas1434▲ 199 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.48% | — | MCP Ruby SDKAI | 29/7/2026 | 30/7/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a session owner, allowing an attacker with a stolen session ID to send tools/call requests that execute in the victim's… | |
| Aplazada | Media (5.3) | 0.51% | — | MCP Ruby SDKAI | 29/7/2026 | 30/7/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue… | |
| Aplazada | Media (6.9) | 0.26% | — | MCP Ruby SDKAI | 29/7/2026 | 30/7/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not validate the HTTP Host or Origin request headers, which allows a malicious browser page to use DNS rebinding to reach a locally running MCP… | |
| Analizada | Alta (8.1) | 0.20% | — | Sgbett Bsv-walletSgbett BSV Ruby SDK | 9/4/2026 | 17/6/2026 | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier's signature over the certificate contents. In acquisition_protocol: 'direct', the caller supplies all certificate fields… | |
| Analizada | Alta (7.5) | 0.47% | — | Sgbett BSV Ruby SDK | 9/4/2026 | 17/6/2026 | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection only recognises REJECTED and DOUBLE_SPEND_ATTEMPTED. ARC responses with txStatus values of INVALID, MALFORMED, MINED_IN_STALE_BLOCK, or any ORPHAN-containing extraInfo / txStatus are silently treated… | |
| Analizada | Alta (8.2) | 0.54% | — | Lfprojects MCP Ruby SDK | 27/3/2026 | 17/6/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a valid session ID can completely hijack the victim's Server-Sent Events (SSE)… | |
| Modificada | Media (5) | 1.5% | — | Basespace Ruby SDK Project Basespace Ruby SDK | 29/4/2014 | 17/6/2026 | The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on the command line, which allows remote attackers to obtain sensitive information by listing the processes. |