Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-33519 An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly… Portal For Arcgis Mitigation only Fix from $2,3002026-04-21 HIGH 7.2 CVE-2026-33518 An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to cre… Portal For Arcgis Mitigation only Fix from $1,9502026-04-21 HIGH 7.3 CVE-2025-1067 There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the … Arcgis Allsource Mitigation only Fix from $1,9502025-02-25 HIGH 7.3 CVE-2025-1068 There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges t… Arcgis Allsource Mitigation only Fix from $1,9502025-02-25 MEDIUM 6.1 CVE-2024-8148 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis Mitigation only Fix from $1,6002024-10-04 HIGH 7.5 CVE-2024-38040 There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a U… Portal For Arcgis Mitigation only Fix from $1,9502024-10-04 MEDIUM 6.1 CVE-2024-38037 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis Mitigation only Fix from $1,6002024-10-04 MEDIUM 6.1 CVE-2024-38038 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 which may allow a remote, unauthenticated attacker to create a crafted… Portal For Arcgis Mitigation only Fix from $1,6002024-10-04 MEDIUM 5.4 CVE-2024-38036 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to crea… Portal For Arcgis Mitigation only Fix from $1,6002024-10-04 MEDIUM 6.1 CVE-2024-25691 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unauthenticated attacker to create… Portal For Arcgis Mitigation only Fix from $1,6002024-10-04 MEDIUM 6.1 CVE-2024-25709 There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated a… Portal For Arcgis Mitigation only Fix from $1,6002024-04-04 MEDIUM 6.1 CVE-2023-25831 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to creat… Portal For Arcgis Mitigation only Fix from $1,6002023-05-09 MEDIUM 6.1 CVE-2023-25829 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis No fix yet Fix from $1,6002023-05-09 MEDIUM 6.1 CVE-2023-25830 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to crea… Portal For Arcgis Mitigation only Fix from $1,6002023-05-09 MEDIUM 6.1 CVE-2022-38204 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to cre… Portal For Arcgis Mitigation only Fix from $1,6002022-12-29 MEDIUM 6.1 CVE-2022-38207 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker… Portal For Arcgis Mitigation only Fix from $1,6002022-12-29 MEDIUM 6.1 CVE-2022-38199 A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenti… Arcgis Server Mitigation only Fix from $1,6002022-10-25 MEDIUM 6.1 CVE-2022-38200 A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web … Arcgis Server Mitigation only Fix from $1,6002022-10-25 MEDIUM 5.4 CVE-2022-38189 A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious st… Portal For Arcgis Mitigation only Fix from $1,6002022-08-16 MEDIUM 5.5 CVE-2022-38194 In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information f… Portal For Arcgis Mitigation only Fix from $1,6002022-08-16 MEDIUM 6.1 CVE-2021-29116 A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a… Arcgis Server Mitigation only Fix from $1,6002021-12-07 MEDIUM 6.1 CVE-2021-29107 A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pa… Arcgis Server Mitigation only Fix from $1,6002021-07-10 MEDIUM 5.4 CVE-2019-16193 In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature. Arcgis Enterprise Mitigation only Fix from $1,6002019-09-11 MEDIUM 5.8 CVE-2014-5122 Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at… Arcgis Server No fix yet Fix from $1,6002014-08-22 MEDIUM 6.5 CVE-2012-4949 SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a quer… Arcgis Server Mitigation only Fix from $1,6002012-11-14 HIGH 7.5 CVE-2007-4278 Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attackers to cause a denial of servi… Arcsde Mitigation only Fix from $1,9502007-08-15 HIGH 10.0 CVE-2007-1770EPSS 17% Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three … Arcsde Mitigation only Fix from $1,9502007-03-30