Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
117 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.75% | — | Altumcode 66uptimeAIAltumcode 66uptime Ping ServersAI | 29/9/2026 | 29/9/2026 | An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php | |
| Aplazada | Baja (2) | 0.33% | — | Stilleshan ServerstatusAI | 13/9/2026 | 14/9/2026 | A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public… | |
| Pendiente de análisis | Alta (7.1) | 0.16% | — | Cisco UCS ServersAICisco UCS AppliancesAI | 8/9/2026 | 11/9/2026 | A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected… | |
| Aplazada | Baja (1.9) | 0.14% | — | Feedmob Fm-mcp-serversAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be… | |
| Pendiente de análisis | Alta (8.5) | 0.19% | — | Amazon Language ServersAI | 23/6/2026 | 23/6/2026 | Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users… | |
| Pendiente de análisis | Alta (8.5) | 0.23% | — | Amazon Language ServersAI | 23/6/2026 | 23/6/2026 | Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the… | |
| Analizada | Media (5.5) | 0.53% | — | Shadowclonelabs Glutamate MCP Servers | 27/4/2026 | 17/6/2026 | A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request… | |
| Pendiente de análisis | Alta (7.3) | 0.12% | — | Dell Storage Manager Replay Manager FOR Microsoft ServersAI | 16/4/2026 | 17/6/2026 | Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft ARC Enabled Servers Azure Connected Machine Agent | 10/3/2026 | 17/6/2026 | Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.4) | 0.45% | — | Lfprojects Model Context Protocol Servers | 26/2/2026 | 17/6/2026 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the git_add tool did not validate that file paths provided in the files argument were within the repository boundaries. Because the tool used GitPython's… | |
| Analizada | Media (6.3) | 7.2% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 17/6/2026 | In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., `--output=/path/to/file` for `git_diff`) would be interpreted as command-line options rather than git refs, enabling… | |
| Analizada | Media (6.4) | 7.0% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 30/9/2026 | In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other… | |
| Analizada | Media (6.5) | 8.1% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 30/9/2026 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required… | |
| Aplazada | Crítica (9.3) | 0.44% | — | NEC Clusterpro X FOR LinuxAINEC Expresscluster X FOR LinuxAINEC Clusterpro X Singleserversafe FOR LinuxAINEC Expresscluster X Singleserversafe FOR LinuxAI | 7/11/2025 | 17/6/2026 | CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network… | |
| Aplazada | Alta (7.3) | 0.76% | — | Anthropic Model Context Protocol ServersAI | 2/7/2025 | 17/6/2026 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve. | |
| Aplazada | Alta (8.8) | 0.46% | — | Cisco Integrated Management ControllerAICisco UCS B-series ServersAICisco UCS C-series ServersAICisco UCS S-series ServersAI+1 | 4/6/2025 | 17/6/2026 | A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient… | |
| Aplazada | Crítica (9.1) | 30% | — | Distinct Intranet ServersAI | 21/6/2024 | 16/6/2026 | Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands. | |
| Modificada | Alta (8.8) | 0.74% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (8.8) | 0.63% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (8.8) | 0.63% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (8.8) | 0.74% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (8.8) | 0.63% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (7) | 0.39% | — | Microsoft Azure Arc-enabled Servers | 8/8/2023 | 10/8/2026 | Azure Arc-Enabled Servers Elevation of Privilege Vulnerability | |
| Modificada | Crítica (9.8) | 1.3% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 8/11/2022 | 17/6/2026 | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on… | |
| Modificada | Crítica (9.8) | 1.2% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 8/11/2022 | 17/6/2026 | Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite… |