Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.32% | — | IBM Contextforge | 24/9/2026 | 29/9/2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files… | |
| Aplazada | Media (6.4) | 0.42% | — | Contextual Related PostsAI | 22/9/2026 | 22/9/2026 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Block Parameter in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and… | |
| Pendiente de análisis | Media (5.4) | 0.16% | — | IBM Mcp-context-forgeAI | 15/9/2026 | 20/9/2026 | IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content. | |
| Aplazada | Crítica (10) | 1.1% | — | MCP Context ForgeAIContext Forge Python Sandbox ServerAI | 15/9/2026 | 30/9/2026 | MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on… | |
| Aplazada | Media (6.6) | 0.35% | — | IBM ContextforgeAI | 14/9/2026 | 30/9/2026 | ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls validate_gateway_test_url() in mcpgateway/common/validators.py to resolve and reject… | |
| Analizada | Crítica (9.8) | 0.58% | — | IBM Contextforge | 10/9/2026 | 16/9/2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials. | |
| Pendiente de análisis | Media (6.2) | 0.19% | — | Modelcontextprotocol Kotlin SDKAIKotlinx CoroutinesAIScala-sbt IOAI | 9/9/2026 | 14/9/2026 | MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/modelcontextprotocol/kotlin/sdk/shared/ReadBuffer.kt` writes every chunk of bytes received from the stdio transport into… | |
| Aplazada | Alta (8.7) | 1.1% | — | Modelcontextprotocol MCPAI | 7/9/2026 | 8/9/2026 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server… | |
| Analizada | Alta (7.4) | 0.26% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session. | |
| Analizada | Alta (8.8) | 0.33% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters. | |
| Analizada | Crítica (9.6) | 0.37% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding. | |
| Analizada | Alta (7.7) | 0.34% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation. | |
| Aplazada | Media (5.5) | 0.59% | — | Boxpositron With-context-mcpAI | 27/8/2026 | 28/8/2026 | A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used.… | |
| Aplazada | Media (5.5) | 0.69% | — | Mcp-file-context-serverAI | 27/8/2026 | 28/8/2026 | A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to initiate the attack remotely. The exploit is… | |
| Analizada | Crítica (9.1) | 0.75% | — | Splunk Model Context Protocol Server | 19/8/2026 | 24/8/2026 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking… | |
| Aplazada | Media (6.4) | 0.49% | — | ContextAI | 18/8/2026 | 24/9/2026 | Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate… | |
| Aplazada | Media (5.5) | 0.47% | — | Modelcontextprotocol MCP RDF ExplorerAI | 13/8/2026 | 14/8/2026 | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Use-context-selectorAI | 10/8/2026 | 9/9/2026 | use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdbbb4db96006424d674124 that executed remote attacker-controlled code on developer… | |
| Aplazada | Media (5.1) | 3.9% | — | Kirachon Context-engineAI | 8/8/2026 | 12/8/2026 | A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue.… | |
| Aplazada | Media (5.3) | 0.36% | — | Context BlogAI | 11/7/2026 | 13/7/2026 | The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes it possible for unauthenticated attackers to extract the content of password-protected posts. | |
| Pendiente de análisis | Crítica (9.4) | 0.22% | — | Anthropic Model Context ProtocolAI | 13/6/2026 | 23/7/2026 | The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing… | |
| Aplazada | Media (4.3) | 0.20% | — | Widget ContextAI | 22/5/2026 | 23/7/2026 | The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on the save_widget_context_settings function. This makes it possible for unauthenticated attackers to modify widget visibility context… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (5.5) | 2.1% | — | Intina47 Context-syncAI | 26/4/2026 | 17/6/2026 | A security vulnerability has been detected in Intina47 context-sync up to 2.0.0. This affects an unknown part of the file src/git-integration.ts of the component Git Integration. Such manipulation leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (6.4) | 0.26% | — | Contextual Related PostsAI | 18/4/2026 | 17/6/2026 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes' parameter in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… |