Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Portal For Arcgis CRITICAL 9.8
CVE-2026-13019

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability a…

Fix: after 12.1
Fix from $2,300 2026-07-07
Portal For Arcgis CRITICAL 9.8
CVE-2026-13020

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes…

Fix: after 12.1
Fix from $2,300 2026-07-07
Arcgis Server CRITICAL 9.8
CVE-2026-9182

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted fi…

Fix: after 12.0
Fix from $2,300 2026-07-06
Arcgis Server HIGH 7.5
CVE-2026-9181

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could e…

Fix: after 12.0
Fix from $1,950 2026-07-06
Arcgis Server MEDIUM 5.3
CVE-2026-2812

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit…

Fix: after 12.0
Fix from $1,600 2026-05-20
Portal For Arcgis CRITICAL 9.8
CVE-2026-33519

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly…

Mitigation only
Fix from $2,300 2026-04-21
Portal For Arcgis HIGH 7.2
CVE-2026-33518

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to cre…

Mitigation only
Fix from $1,950 2026-04-21
Arcgis Pro MEDIUM 5.0
CVE-2026-1446

There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is l…

Fix: 3.6.1+
Fix from $1,600 2026-01-26
Arcgis Server MEDIUM 6.1
CVE-2025-67709

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 6.1
CVE-2025-67710

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 6.1
CVE-2025-67711

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 6.1
CVE-2025-67704

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 6.1
CVE-2025-67705

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 6.1
CVE-2025-67708

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 5.6
CVE-2025-67706

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 5.6
CVE-2025-67707

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 6.1
CVE-2025-67703

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server CRITICAL 10.0
CVE-2025-57870

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a…

Fix: after 11.5
Fix from $2,300 2025-10-22
Portal For Arcgis MEDIUM 6.1
CVE-2025-57878

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …

Patch available
Fix from $1,600 2025-09-29
Portal For Arcgis MEDIUM 6.1
CVE-2025-57879

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …

Patch available
Fix from $1,600 2025-09-29
Portal For Arcgis MEDIUM 6.1
CVE-2025-57872

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …

Patch available
Fix from $1,600 2025-09-29
Portal For Arcgis CRITICAL 9.1
CVE-2025-4967

Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.

Fix: after 11.4
Fix from $2,300 2025-05-29
Portal For Arcgis CRITICAL 9.8
CVE-2025-2538

A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remo…

Fix: after 11.4
Fix from $2,300 2025-03-20
Arcgis Server HIGH 8.7
CVE-2024-51962

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when…

Fix: after 11.3
Fix from $1,950 2025-03-03
Arcgis Server HIGH 7.5
CVE-2024-51961

There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that c…

Fix: after 11.3
Fix from $1,950 2025-03-03
Arcgis Server HIGH 8.5
CVE-2024-51954

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allo…

Fix: after 11.3
Fix from $1,950 2025-03-03
Arcgis Allsource HIGH 7.3
CVE-2025-1067

There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the …

Mitigation only
Fix from $1,950 2025-02-25
Arcgis Allsource HIGH 7.3
CVE-2025-1068

There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges t…

Mitigation only
Fix from $1,950 2025-02-25
Portal For Arcgis MEDIUM 6.1
CVE-2024-8148

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a …

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis HIGH 7.5
CVE-2024-38040

There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a U…

Mitigation only
Fix from $1,950 2024-10-04