Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.5) | — | — | Modelcontextprotocol MCP Server FetchAIModelcontextprotocol MCP Server EverythingAI | 2/10/2026 | 2/10/2026 | A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack… | |
| Analizada | Media (4.9) | 0.32% | — | IBM Contextforge | 24/9/2026 | 29/9/2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files… | |
| Aplazada | Alta (7.3) | 0.39% | — | Opentext Vendor Invoice Management FOR SAP SolutionsAI | 24/9/2026 | 24/9/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and… | |
| Aplazada | Media (6.8) | 0.43% | — | Text StylerAI | 22/9/2026 | 22/9/2026 | The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the… | |
| Aplazada | Media (6.4) | 0.42% | — | Contextual Related PostsAI | 22/9/2026 | 22/9/2026 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Block Parameter in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Nginx IgnitionAIGolang X TextAI | 21/9/2026 | 24/9/2026 | nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape… | |
| Aplazada | Alta (7.5) | 0.63% | — | Perl POD TextAI | 19/9/2026 | 22/9/2026 | Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the… | |
| Pendiente de análisis | Alta (7) | 0.13% | — | Sublimetext Sublime TextAI | 18/9/2026 | 22/9/2026 | Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges by abusing the update staging mechanism. Attackers can place a malicious DLL in… | |
| Aplazada | Alta (8.5) | 0.32% | — | Oracle Database ServerAIOracle TextAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Create Index privilege with network access via Oracle Net to compromise Oracle Text. While… | |
| Pendiente de análisis | Media (5.4) | 0.16% | — | IBM Mcp-context-forgeAI | 15/9/2026 | 19/9/2026 | IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content. | |
| Pendiente de análisis | Media (4.3) | 0.40% | — | Plone App.textfieldAI | 15/9/2026 | 30/9/2026 | plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored RichText value when mimeType equals outputMimeType, including values that claim… | |
| Aplazada | Crítica (10) | 1.1% | — | MCP Context ForgeAIContext Forge Python Sandbox ServerAI | 15/9/2026 | 30/9/2026 | MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on… | |
| Aplazada | Alta (7.1) | 0.38% | — | JHB Software Payload ALT Text PluginAIPayload CMSAI | 15/9/2026 | 30/9/2026 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while alt-text/src/endpoints/generateAltText.ts and… | |
| Aplazada | Alta (8.3) | 0.57% | — | Gettext-converterAI | 14/9/2026 | 30/9/2026 | gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number signs, and uses each segment as a dynamic object key without rejecting __proto__,… | |
| Aplazada | Media (6.6) | 0.35% | — | IBM ContextforgeAI | 14/9/2026 | 30/9/2026 | ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls validate_gateway_test_url() in mcpgateway/common/validators.py to resolve and reject… | |
| Analizada | Crítica (9.8) | 0.58% | — | IBM Contextforge | 10/9/2026 | 16/9/2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials. | |
| Aplazada | Media (4.8) | 0.23% | — | Opentext Documentum WebtopAI | 9/9/2026 | 9/9/2026 | Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS | |
| Pendiente de análisis | Media (6.2) | 0.19% | — | Modelcontextprotocol Kotlin SDKAIKotlinx CoroutinesAIScala-sbt IOAI | 9/9/2026 | 14/9/2026 | MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/modelcontextprotocol/kotlin/sdk/shared/ReadBuffer.kt` writes every chunk of bytes received from the stdio transport into… | |
| Aplazada | Alta (8.7) | 1.1% | — | Modelcontextprotocol MCPAI | 7/9/2026 | 8/9/2026 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server… | |
| Analizada | Alta (7.4) | 0.26% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session. | |
| Analizada | Alta (8.8) | 0.33% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters. | |
| Analizada | Crítica (9.6) | 0.37% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding. | |
| Analizada | Alta (7.7) | 0.34% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation. | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Openshift Oauth-serverAIGolang.org X TextAI | 1/9/2026 | 1/9/2026 | A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the… | |
| Aplazada | Media (5.5) | 0.59% | — | Boxpositron With-context-mcpAI | 27/8/2026 | 28/8/2026 | A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used.… |