-Infinity
0

maven/org.geoserver.web:gs-web-appGeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution

Risk 54
Severity
8.2
First published (updated )

maven/org.geoserver.web:gs-web-appGeoServer has an arbitrary file write vulnerability in its Master Password Dump Page

Risk 70
Severity
7.2
First published (updated )

maven/org.geoserver.extension:gs-db2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

Risk 66
Severity
7.2
First published (updated )

MapServer MapServerMapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reachable via WMS `SLD_BODY`

Risk 43
Severity
7.5
First published (updated )

GDAL GDALBuffer Overflow

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OSGeo gdalOSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflow

Risk 24
Severity
1.9
EPSS
0.01%
First published (updated )

OSGeo gdalOSGeo gdal SWapi.c SWSDfldsrch heap-based overflow

Risk 24
Severity
1.9
EPSS
0.02%
First published (updated )

MapServer MapServerMapServer: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in OpenLayers viewer

Risk 38
Severity
6.1
First published (updated )

OSGeo gdalOSGeo gdal GDapi.c GDfieldinfo out-of-bounds

Risk 24
Severity
1.9
EPSS
0.01%
First published (updated )

OSGeo gdalOSGeo gdal GDapi.c GDnentries heap-based overflow

Risk 51
Severity
1.9
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OSGeo gdalOSGeo gdal SWapi.c SWnentries heap-based overflow

Risk 51
Severity
1.9
EPSS
0.02%
First published (updated )

OSGeo gdalOSGeo gdal HDF-EOS Grid File SWapi.c memmove out-of-bounds

Risk 24
Severity
1.9
EPSS
0.02%
First published (updated )

MapServer MapServerMapServer has heap buffer overflow in SLD `Categorize` Threshold parsing

Risk 31
Severity
7.5
EPSS
0.07%
First published (updated )

OSGeo gdalGDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code Execution

Risk 58
Severity
9.4
EPSS
0.06%
First published (updated )

GeoNetwork GeoNetworkGeonetwork 4.2.0 - XML External Entity (XXE)

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/org.geoserver:gs-wmsOSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

Risk 99
Severity
9.8
First published (updated )

OSGeo MapServerMapServer - WFS XML Filter Query SQL injection

Risk 86
Severity
9.8
First published (updated )

OSGeo spatialreference.orgXSS

Risk 38
Severity
6.1
First published (updated )

GeoTools GeoToolsGeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling

Risk 72
Severity
9.9
First published (updated )

maven/org.geoserver.extension:gs-wps-coreGeoServer has an Infinite Loop Vulnerability in Jiffle process

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/org.geoserver:gs-restGeoServer Missing Authorization on REST API Index

Risk 27
Severity
5.3
First published (updated )

maven/org.geoserver.web:gs-web-appGeoServer Coverage REST API Allows Server Side Request Forgery

Risk 39
Severity
5.5
First published (updated )

maven/org.geoserver:gs-gwcGWC Home Page communicate version and revision information

Risk 43
Severity
7.5
First published (updated )

maven/org.geoserver.main:gs-mainGeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)

Risk 61
Severity
9.3
First published (updated )

maven/org.geoserver.web:gs-appGeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost

Risk 54
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

GDAL GDALBuffer Overflow

Risk 32
Severity
5.5
First published (updated )

maven/org.geonetwork-opensource:gn-servicesGeoNetwork vulnerable to search end-point information disclosure in response headers

Risk 27
Severity
5.3
First published (updated )

maven/org.geoserver.web:gs-web-coreWelcome and About GeoServer pages communicate version and revision information

Risk 28
Severity
5.3
First published (updated )

GeoTools GeoToolsRemote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver

Risk 99
Severity
9.8
First published (updated )

maven/org.geoserver.extension:gs-wps-coreWPS Server Side Request Forgery in GeoServer

Risk 87
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203