Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Geoserver HIGH 8.2
CVE-2025-58175

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `E…

Fix: 2.26.4 / 2.27.3+
Fix from $1,950 2026-06-18
Geoserver HIGH 7.2
CVE-2025-52465

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists t…

Fix: 2.26.4 / 2.27.3+
Fix from $1,950 2026-06-18
Geoserver HIGH 7.2
CVE-2025-27511

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extens…

Fix: 2.27.0+
Fix from $1,950 2026-06-18
Mapserver HIGH 7.5
CVE-2026-45104

MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psR…

Fix: 8.6.3+
Fix from $1,950 2026-05-27
Gdal HIGH 7.8
CVE-2026-49014

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geom…

Fix: after 3.13.0
Fix from $1,950 2026-05-27
Gdal MEDIUM 5.5
CVE-2026-8212

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWap…

Fix: after 3.12.4
Fix from $1,600 2026-05-09
Gdal MEDIUM 5.5
CVE-2026-8213

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDa…

Fix: after 3.12.4
Fix from $1,600 2026-05-09
Mapserver MEDIUM 6.1
CVE-2026-42030

MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer…

Fix: 8.6.2+
Fix from $1,600 2026-05-08
Gdal HIGH 7.8
CVE-2026-8087

A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Perf…

Fix: after 3.12.4
Fix from $1,950 2026-05-07
Gdal MEDIUM 5.5
CVE-2026-8088

A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi…

Fix: after 3.12.4
Fix from $1,600 2026-05-07
Gdal HIGH 7.8
CVE-2026-8086

A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Su…

Fix: after 3.12.4
Fix from $1,950 2026-05-07
Gdal MEDIUM 5.5
CVE-2026-8084

A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.…

Fix: after 3.12.4
Fix from $1,600 2026-05-07
Mapserver HIGH 7.5
CVE-2026-33721

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in …

Fix: 8.6.1+
Fix from $1,950 2026-03-27
Geonetwork MEDIUM 6.5
CVE-2022-50899

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from t…

Fix: after 4.2.0
Fix from $1,600 2026-01-13
Mapserver CRITICAL 9.8
CVE-2025-59431

MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean…

Mitigation only
Fix from $2,300 2025-09-19
Geoserver HIGH 7.5
CVE-2025-30145

GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either…

Fix: 2.25.7 / 2.26.3+
Fix from $1,950 2025-06-10
Geoserver MEDIUM 5.3
CVE-2025-27505

GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and ac…

Fix: 2.25.6 / 2.26.3+
Fix from $1,600 2025-06-10
Geoserver HIGH 8.2
CVE-2024-29198

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side …

Fix: 2.24.4 / 2.25.2+
Fix from $1,950 2025-06-10
Geoserver HIGH 8.2
CVE-2024-34711

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables …

Fix: 2.25.0+
Fix from $1,950 2025-06-10
Geoserver HIGH 7.5
CVE-2024-38524

GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpSer…

Fix: 2.25.6 / 2.26.2+
Fix from $1,950 2025-06-10
Gdal MEDIUM 5.5
CVE-2025-29480

Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE…

No fix yet
Fix from $1,600 2025-04-07
Geonetwork MEDIUM 5.3
CVE-2024-32037

GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response he…

Fix: 4.2.10 / 4.4.5+
Fix from $1,600 2025-02-11
Geoserver MEDIUM 5.3
CVE-2024-35230

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and…

Fix: 2.25.1+
Fix from $1,600 2024-12-16
Geoserver CRITICAL 9.8
CVE-2023-43795EPSS 68%

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS)…

Fix: 2.22.5 / 2.23.2+
Fix from $2,300 2023-10-25
Geoserver MEDIUM 5.3
CVE-2023-41339

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``s…

Fix: 2.22.5 / 2.23.2+
Fix from $1,600 2023-10-25
Owslib HIGH 7.5
CVE-2023-27476

OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content mo…

Fix: 0.28.1+
Fix from $1,950 2023-03-08
Geoserver CRITICAL 9.8
CVE-2023-25157EPSS 85%

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the O…

Fix: 2.18.7 / 2.19.7+
Fix from $2,300 2023-02-21
Shapelib CRITICAL 9.8
CVE-2022-0699

A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of servi…

Fix: after 1.5.0
Fix from $2,300 2022-10-17
Geonetwork HIGH 7.2
CVE-2021-28398

A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands…

Fix: 3.12.0 / 4.0.4+
Fix from $1,950 2022-09-05
Geoserver HIGH 7.5
CVE-2021-40822EPSS 19%

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

Fix: 2.19.3+
Fix from $1,950 2022-05-02