Known Vulnerabilities for Servers by Modelcontextprotocol
Listed below are 10 of the newest known vulnerabilities associated with "Servers" by "Modelcontextprotocol".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100583 json | OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that a... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-96748 json | PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated ... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-94281 json | An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-93999 json | A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The... | Not Provided | 2026-09-19 | 2026-09-22 |
| CVE-2026-93545 json | An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an a... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-93543 json | An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an atta... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-93542 json | An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used ... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-92680 json | Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Window... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-91970 json | Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggreg... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-90961 json | The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthentic... | Not Provided | 2026-09-14 | 2026-09-14 |