Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.59% | — | GeonetworkAI | 15/9/2026 | 30/9/2026 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validation. An anonymous attacker could make the GeoNetwork server send requests to… | |
| Aplazada | Alta (8.6) | 0.47% | — | GeonetworkAI | 3/9/2026 | 9/9/2026 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip`… | |
| Aplazada | Crítica (9.1) | 1.2% | — | GeonetworkAISaxonica SaxonAI | 3/9/2026 | 9/9/2026 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any… | |
| Pendiente de análisis | Media (4.8) | 0.65% | — | GeonetworkAI | 31/7/2026 | 10/9/2026 | GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in… | |
| Analizada | Alta (8.7) | 0.54% | — | Osgeo Geonetwork | 13/1/2026 | 17/6/2026 | Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL… | |
| Analizada | Crítica (9.1) | 42% | — | GeotoolsOsgeo GeonetworkOsgeo Geoserver | 10/6/2025 | 17/6/2026 | GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the… | |
| Analizada | Media (5.3) | 0.38% | — | Osgeo Geonetwork | 11/2/2025 | 17/6/2026 | GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to… | |
| Modificada | Alta (7.2) | 1.4% | — | Osgeo Geonetwork | 5/9/2022 | 17/6/2026 | A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Administrator or Administrator account is required to perform this. This occurs in the runBeforeScript method in… | |
| Modificada | Alta (7.5) | 1.2% | — | Geonetwork Opensource | 26/10/2006 | 16/6/2026 | SQL injection vulnerability in GeoNetwork opensource before 2.0.3 allows remote attackers to execute arbitrary SQL commands, and complete a login, via unspecified vectors. |