Live MCP vulnerability intelligence

MCP vulnerabilities, separated from security unknowns

A continuously updated evidence index for MCP server vulnerabilities. It connects proven exact-version findings from the MCP vulnerability scanner to the tested population and preserves the much larger unknown state instead of presenting missing evidence as safety.

71,565canonical MCPs indexed
9,298package versions scanned
508current versions with proven findings
63,163current security states unknown
01 / EVIDENCE FUNNEL

How the index reaches a vulnerability verdict

Inventory size, historical scan coverage, current verification, and proven vulnerability evidence answer different questions. The funnel shows the denominator behind every public verdict.

Inventory71,565

deduplicated MCP implementations

Observed8,593

implementations scanned across retained versions

Current clean7,894

completed current-version runs without a proven finding

Current vulnerable508

completed current-version runs with proven evidence

63,163 MCPs are not classified as safe. Their selected current version does not have complete public verification evidence.
02 / LIVE INDEX

Investigate the underlying MCP records

The intelligence report does not manufacture a second list. These views open the canonical catalog records and their retained version evidence.

03 / INTERPRETATION

What the current rate does—and does not—say

6.0% of exact current versions with completed public verification have at least one proven finding. This is an observed rate within the verified population. It must not be projected onto unverified MCPs, and it is not an estimate of ecosystem-wide vulnerability prevalence.

A proven finding establishes repeatable behavior under the retained scanner method and tested environment. Severity, remote reachability, default exposure, vendor ownership, and deployment impact require their own evidence.

Let’s talk about MCP security.

Share your details and our security team will contact you.