Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.47% | — | Mcp-use InspectorAI | 27/8/2026 | 23/9/2026 | The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or the __mcp_target parameter and proxied to it without inspecting the host, so loopback,… | |
| Aplazada | Alta (8.7) | 0.76% | — | Swe-agent Sweagent InspectorAI | 17/8/2026 | 24/9/2026 | SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The server binds all interfaces (0.0.0.0),… | |
| Analizada | Media (6.1) | 0.34% | — | Hsclabs Mailinspector | 18/5/2026 | 17/6/2026 | HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscated JavaScript syntax. | |
| Analizada | Media (6.1) | 0.41% | — | Hsclabs Mailinspector | 18/5/2026 | 17/6/2026 | HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript syntax. The endpoint reflects unsanitized user input in HTTP responses without adequate output encoding, allowing… | |
| Analizada | Alta (7.5) | 3.0% | — | Hsclabs Mailinspector | 18/5/2026 | 17/6/2026 | HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. A remote attacker can exploit this flaw to access… | |
| Analizada | Alta (7.5) | 1.8% | — | Hsclabs Mailinspector | 18/5/2026 | 17/6/2026 | HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path… | |
| Aplazada | Baja (2.1) | 0.45% | — | Hsclabs MailinspectorAI | 6/3/2026 | 17/6/2026 | A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown functionality of the file /mailinspector/mliUserValidation.php of the component URL Handler. The manipulation of the argument error_description results in cross site scripting. The attack may be performed… | |
| Analizada | Crítica (9.8) | 68% | — | Mcpjam Inspector | 16/1/2026 | 17/6/2026 | MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default… | |
| Aplazada | Alta (8.6) | 0.67% | — | Anthropic MCP InspectorAI | 8/9/2025 | 17/6/2026 | The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with… | |
| Aplazada | Media (4.9) | 0.50% | — | Gioni Plugin InspectorAI | 27/6/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gioni Plugin Inspector plugin-inspector allows Path Traversal.This issue affects Plugin Inspector: from n/a through <= 1.5. | |
| Aplazada | Crítica (9.4) | 44% | — | Anthropic MCP InspectorAI | 13/6/2025 | 17/6/2026 | The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately… | |
| Aplazada | Media (4.3) | 0.42% | — | Bowo Variable InspectorAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Bowo Variable Inspector variable-inspector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Variable Inspector: from n/a through <= 2.6.3. | |
| Aplazada | Alta (7.1) | 0.32% | — | Bowo Variable InspectorAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Inspector variable-inspector allows Reflected XSS.This issue affects Variable Inspector: from n/a through <= 2.6.2. | |
| Aplazada | Media (6.9) | 0.44% | — | Txone Networks Portable InspectorAITxone Networks Portable Inspector PRO EditionAI | 8/1/2025 | 17/6/2026 | Improper Input Validation vulnerability in Management Program in TXOne Networks Portable Inspector and Portable Inspector Pro Edition allows remote attacker to crash management service. The Denial of Service situation can be resolved by restarting the management service. This issue affects Portable Inspector: through… | |
| Modificada | Media (6.5) | 1.2% | — | Trendmicro Deep Discovery Inspector | 22/10/2024 | 17/6/2026 | A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Crítica (9.1) | 0.69% | — | Trendmicro Deep Discovery Inspector | 22/10/2024 | 17/6/2026 | A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute high-privileged code (admin user rights) on the target system in order to exploit this… | |
| Aplazada | Media (6.7) | 0.17% | — | Intel InspectorAI | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Inspector software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.5) | 0.70% | — | Hsclabs Mailinspector | 7/5/2024 | 17/6/2026 | An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0. | |
| Analizada | Crítica (9.8) | 1.0% | — | Hsclabs Mailinspector | 7/5/2024 | 17/6/2026 | An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component. | |
| Analizada | Media (4.3) | 0.93% | — | Hsclabs Mailinspector | 7/5/2024 | 17/6/2026 | SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteList.php component. | |
| Analizada | Media (5.4) | 0.74% | — | Hsclabs Mailinspector | 6/5/2024 | 17/6/2026 | An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on… | |
| Modificada | Media (5.5) | 0.65% | — | Hsclabs Mailinspector | 6/5/2024 | 17/6/2026 | An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to… | |
| Analizada | Alta (8.6) | 6.7% | — | Hsclabs Mailinspector | 6/5/2024 | 17/6/2026 | An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the… | |
| Aplazada | Media (4.7) | 0.21% | — | Openstack IronicAIOpenstack Ironic InspectorAI | 17/4/2024 | 17/6/2026 | Ironic-image is an OpenStack Ironic deployment packaged and configured by Metal3. When the reverse proxy mode is enabled by the `IRONIC_REVERSE_PROXY_SETUP` variable set to `true`, 1) HTTP basic credentials are validated on the HTTPD side in a separate container, not in the Ironic service itself and 2) Ironic listens… | |
| Analizada | Alta (7.8) | 0.16% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access. |