Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.50% | — | MapserverAI | 17/9/2026 | 30/9/2026 | MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(),… | |
| Pendiente de análisis | Alta (8.2) | 0.68% | — | MapserverAIPostgresqlAIPostgisAI | 17/9/2026 | 24/9/2026 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml_<item>_type=Integer are configured, but it does… | |
| Analizada | Alta (7.5) | 0.49% | — | Osgeo Mapserver | 27/5/2026 | 17/6/2026 | MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> — it assumes msSLDParseRule added one class. When the rule has no symbolizer (a structurally valid SLD),… | |
| Analizada | Media (6.1) | 0.30% | — | Osgeo Mapserver | 8/5/2026 | 17/6/2026 | MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker to inject arbitrary HTML/JavaScript into the browser of any user who opens a crafted WMS URL. The vulnerability is… | |
| Pendiente de análisis | Alta (8.8) | 0.19% | — | Gatewaygeo MapserverAI | 9/4/2026 | 17/6/2026 | A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted executable. | |
| Pendiente de análisis | Crítica (9.1) | 0.54% | — | Osgeo MapserverAI | 9/4/2026 | 17/6/2026 | A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted executable. | |
| Modificada | Alta (7.5) | 0.82% | — | Osgeo Mapserver | 27/3/2026 | 17/6/2026 | MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold… | |
| Analizada | Alta (8.9) | 0.41% | — | Osgeo Mapserver | 19/9/2025 | 17/6/2026 | MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It seems like expression checking is bypassed by introducing double quote characters in the PropertyName. Allowing to manipulate backend database… | |
| Aplazada | Media (6.9) | 0.31% | — | Pilotgaea Technologies Oview MapserverAI | 15/9/2025 | 17/6/2026 | O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network. | |
| Modificada | Media (5.3) | 1.5% | — | Osgeo MapserverFedoraproject Fedora | 6/5/2021 | 17/6/2026 | MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI). | |
| Modificada | Alta (8.1) | 2.4% | — | Gatewaygeomatics Mapserver | 9/1/2020 | 16/6/2026 | Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Osgeo Mapserver | 29/10/2019 | 16/6/2026 | Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing. | |
| Modificada | Crítica (9.8) | 4.8% | — | Debian LinuxOsgeo Mapserver | 15/3/2017 | 17/6/2026 | Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests. | |
| Modificada | Alta (7.5) | 1.5% | — | Osgeo Mapserver | 8/12/2016 | 17/6/2026 | In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails. | |
| Modificada | Media (6.8) | 2.2% | — | Osgeo MapserverUMN Mapserver | 5/1/2014 | 17/6/2026 | SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter. | |
| Modificada | Media (6.8) | 4.6% | — | Osgeo MapserverUMN Mapserver | 1/8/2011 | 16/6/2026 | Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data. | |
| Modificada | Alta (7.5) | 5.2% | — | Osgeo MapserverUMN Mapserver | 1/8/2011 | 16/6/2026 | Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding. | |
| Modificada | Alta (7.5) | 2.7% | — | Osgeo MapserverUMN Mapserver | 1/8/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support. | |
| Modificada | Alta (10) | 3.8% | — | Osgeo MapserverUMN Mapserver | 2/8/2010 | 16/6/2026 | mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments. | |
| Modificada | Baja (2.1) | 0.32% | — | Osgeo MapserverUMN Mapserver | 2/8/2010 | 16/6/2026 | Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files. | |
| Modificada | Alta (10) | 5.9% | — | Osgeo MapserverUMN Mapserver | 23/10/2009 | 16/6/2026 | Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a… | |
| Modificada | Alta (10) | 2.9% | — | Osgeo MapserverUMN Mapserver | 31/3/2009 | 16/6/2026 | Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and remote attack vectors. | |
| Modificada | Alta (10) | 4.1% | — | Osgeo MapserverUMN Mapserver | 31/3/2009 | 16/6/2026 | mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other impact via a long id parameter in a query action. | |
| Modificada | Alta (7.8) | 3.1% | — | Osgeo MapserverUMN Mapserver | 31/3/2009 | 16/6/2026 | The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists. | |
| Modificada | Media (4.3) | 2.6% | — | Osgeo MapserverUMN Mapserver | 31/3/2009 | 16/6/2026 | mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink. |