Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
–

152 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.29%—Modelcontextprotocol MCP Server FetchAIModelcontextprotocol MCP Server EverythingAI2/10/20262/10/2026
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack…
AplazadaAlta (7.6)0.29%—Office Powerpoint MCP ServerAI1/10/20262/10/2026
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or…
Pendiente de análisisMedia (6.9)0.14%—Amazon Security Agent MCP ServerAI1/10/20261/10/2026
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan…
AplazadaBaja (2.1)1.1%—0xshariq Github-mcp-serverAI30/9/20262/10/2026
A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be…
Pendiente de análisisMedia (4.6)0.13%—Zscaler MCP ServerAI28/9/202628/9/2026
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
AplazadaBaja (2.7)0.19%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending…
AplazadaBaja (2.7)0.17%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by…
AplazadaAlta (8.8)0.14%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator…
AplazadaMedia (5.7)0.23%—Ondata Ckan MCP ServerAI21/9/202624/9/2026
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS. Any caller-supplied `server_url` whose hostname *resolves* to an internal…
AplazadaAlta (8.1)0.62%—Labs64 Netlicensing MCP ServerAI17/9/202630/9/2026
NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass…
Pendiente de análisisCrítica (10)0.42%—Mysql MCP ServerAI15/9/202630/9/2026
MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection, while the Starlette routes /, /sse, and…
AplazadaAlta (7.7)0.41%—Contentful MCP ServerAIContentful MCP ToolsAI15/9/202630/9/2026
Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and…
Pendiente de análisisMedia (5.1)0.44%—Amazon Security Agent MCP ServerAI10/9/202610/9/2026
A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is…
AplazadaCrítica (9)1.7%—Amazon Awslabs Postgres-mcp-serverAI9/9/202610/9/2026
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement…
Pendiente de análisisMedia (5.7)0.18%—Amazon Awslabs Mysql-mcp-serverAI9/9/20269/9/2026
Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To…
Pendiente de análisisAlta (7.1)0.34%—Amazon Postgres-mcp-serverAI4/9/20268/9/2026
An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP…
Pendiente de análisisAlta (7.1)0.21%—Amazon Awslabs.dynamodb-mcp-serverAI4/9/20268/9/2026
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model…
AplazadaCrítica (9.3)0.69%—Excel-mcp-serverAI4/9/202623/9/2026
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
AplazadaCrítica (9.2)0.62%—Cli-mcp-serverAI4/9/202624/9/2026
cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation…
AplazadaAlta (8.7)0.48%—Git-mcp-serverAI4/9/202623/9/2026
git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process.
AplazadaAlta (8.7)0.90%—Firecrawl-mcp-serverAI4/9/202623/9/2026
firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read sensitive files like credentials and…
AplazadaMedia (6.9)0.19%—Appium-mcp-serverAI1/9/20268/9/2026
appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths or relative paths with parent directory segments to overwrite arbitrary files with…
AplazadaCrítica (10)0.78%—Ui-tars-desktop Mcp-http-serverAIAgent-infra Mcp-server-commandsAIAgent-infra Mcp-server-filesystemAI27/8/202623/9/2026
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a…
AplazadaBaja (2.3)0.18%—MCP Server DashAI27/8/202624/9/2026
The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mode with the interface restricted to loopback and no transport-security settings, so a name that had been pointed at the loopback address still…
AplazadaAlta (7.6)0.22%—Tiger-gh-mcp-serverAI27/8/202623/9/2026
tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable…