Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Portal For Arcgis CRITICAL 9.8
CVE-2026-33519

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly…

Mitigation only
Fix from $2,300 2026-04-21
Portal For Arcgis HIGH 7.2
CVE-2026-33518

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to cre…

Mitigation only
Fix from $1,950 2026-04-21
Arcgis Allsource HIGH 7.3
CVE-2025-1067

There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the …

Mitigation only
Fix from $1,950 2025-02-25
Arcgis Allsource HIGH 7.3
CVE-2025-1068

There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges t…

Mitigation only
Fix from $1,950 2025-02-25
Portal For Arcgis MEDIUM 6.1
CVE-2024-8148

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a …

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis HIGH 7.5
CVE-2024-38040

There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a U…

Mitigation only
Fix from $1,950 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-38037

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a …

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-38038

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 which may allow a remote, unauthenticated attacker to create a crafted…

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 5.4
CVE-2024-38036

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to crea…

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-25691

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unauthenticated attacker to create…

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-25709

There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated a…

Mitigation only
Fix from $1,600 2024-04-04
Portal For Arcgis MEDIUM 6.1
CVE-2023-25831

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to creat…

Mitigation only
Fix from $1,600 2023-05-09
Portal For Arcgis MEDIUM 6.1
CVE-2023-25829

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a …

No fix yet
Fix from $1,600 2023-05-09
Portal For Arcgis MEDIUM 6.1
CVE-2023-25830

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to crea…

Mitigation only
Fix from $1,600 2023-05-09
Portal For Arcgis MEDIUM 6.1
CVE-2022-38204

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to cre…

Mitigation only
Fix from $1,600 2022-12-29
Portal For Arcgis MEDIUM 6.1
CVE-2022-38207

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker…

Mitigation only
Fix from $1,600 2022-12-29
Arcgis Server MEDIUM 6.1
CVE-2022-38199

A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenti…

Mitigation only
Fix from $1,600 2022-10-25
Arcgis Server MEDIUM 6.1
CVE-2022-38200

A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web …

Mitigation only
Fix from $1,600 2022-10-25
Portal For Arcgis MEDIUM 5.4
CVE-2022-38189

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious st…

Mitigation only
Fix from $1,600 2022-08-16
Portal For Arcgis MEDIUM 5.5
CVE-2022-38194

In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information f…

Mitigation only
Fix from $1,600 2022-08-16
Arcgis Server MEDIUM 6.1
CVE-2021-29116

A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a…

Mitigation only
Fix from $1,600 2021-12-07
Arcgis Server MEDIUM 6.1
CVE-2021-29107

A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pa…

Mitigation only
Fix from $1,600 2021-07-10
Arcgis Enterprise MEDIUM 5.4
CVE-2019-16193

In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.

Mitigation only
Fix from $1,600 2019-09-11
Arcgis Server MEDIUM 5.8
CVE-2014-5122

Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…

No fix yet
Fix from $1,600 2014-08-22
Arcgis Server MEDIUM 6.5
CVE-2012-4949

SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a quer…

Mitigation only
Fix from $1,600 2012-11-14
Arcsde HIGH 7.5
CVE-2007-4278

Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2007-08-15
Arcsde HIGH 10.0
CVE-2007-1770EPSS 17%

Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three …

Mitigation only
Fix from $1,950 2007-03-30