Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.97% | — | Bracketspace SpectraAI | 30/5/2026 | 22/7/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation… | |
| Modificada | Baja (3.5) | 0.31% | — | Bracketspace Advanced Cron Manager | 15/5/2025 | 17/6/2026 | The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (4.3) | 0.39% | — | Bracketspace Advanced Cron ManagerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in BracketSpace Advanced Cron Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.9. | |
| Aplazada | Media (5.9) | 0.27% | — | Bracketspace Simple Post NotesAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BracketSpace Simple Post Notes allows Stored XSS.This issue affects Simple Post Notes: from n/a through 1.7.7. | |
| Aplazada | Media (4.3) | 0.20% | — | Bracketspace Simple Post NotesAI | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6. | |
| Aplazada | Media (5.9) | 0.36% | — | Bracketspace Advanced Cron ManagerAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BracketSpace Advanced Cron Manager – debug & control allows Stored XSS.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.2. | |
| Modificada | Media (4.8) | 0.58% | — | Bracketspace Simple Post Notes | 17/7/2022 | 17/6/2026 | The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.3) | 0.65% | — | Bracketspace Advanced Cron Manager | 7/2/2022 | 17/6/2026 | The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example | |
| Modificada | Media (4.8) | 0.93% | — | Bracketspace Notification | 1/11/2021 | 17/6/2026 | The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in… | |
| Modificada | Crítica (9.8) | 6.6% | — | Adobe Brackets | 19/12/2019 | 17/6/2026 | Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 3.8% | — | Adobe Brackets | 16/6/2016 | 17/6/2026 | The extension manager in Adobe Brackets before 1.7 allows attackers to have an unspecified impact via invalid input. | |
| Modificada | Media (6.1) | 1.3% | — | Adobe Brackets | 16/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe Brackets before 1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | COM Hotbrackets | 8/3/2010 | 16/6/2026 | SQL injection vulnerability in the HotBrackets Tournament Brackets (com_hotbrackets) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. |