Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Portal For Arcgis MEDIUM 6.1
CVE-2024-38037

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a …

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-38038

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 which may allow a remote, unauthenticated attacker to create a crafted…

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 5.4
CVE-2024-38039

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create …

Fix: after 11.0
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 5.4
CVE-2024-38036

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to crea…

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-25691

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unauthenticated attacker to create…

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-25709

There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated a…

Mitigation only
Fix from $1,600 2024-04-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-25706

There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL wh…

Fix: after 11.0
Fix from $1,600 2024-04-04
Portal For Arcgis MEDIUM 5.4
CVE-2024-25705

There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that al…

Fix: after 11.1
Fix from $1,600 2024-04-04
Portal For Arcgis HIGH 8.5
CVE-2024-25699

There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows a…

Fix: after 11.2
Fix from $1,950 2024-04-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-25698

There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that al…

Fix: after 11.1
Fix from $1,600 2024-04-04
Portal For Arcgis MEDIUM 5.4
CVE-2024-25697

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to crea…

Fix: after 11.1
Fix from $1,600 2024-04-04
Portal For Arcgis CRITICAL 9.9
CVE-2024-25693

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse…

Fix: after 11.2
Fix from $2,300 2024-04-04
Portal For Arcgis HIGH 7.2
CVE-2024-25695

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to prov…

Fix: after 11.2
Fix from $1,950 2024-04-04
Portal For Arcgis MEDIUM 5.4
CVE-2024-25692

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthen…

Fix: after 11.1
Fix from $1,600 2024-04-04
Arcgis Server MEDIUM 5.3
CVE-2023-25848

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a craf…

Fix: after 11.0
Fix from $1,600 2023-08-25
Arcgis Server MEDIUM 6.1
CVE-2023-25841

There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms that may allow a re…

Fix: 11.1+
Fix from $1,600 2023-07-21
Portal For Arcgis HIGH 8.4
CVE-2023-25837

There is a Cross‑Site Scripting (XSS) vulnerability in Esri ArcGIS Enterprise Sites versions 10.9 and below that may allow a remote, authenticated at…

Fix: after 10.9
Fix from $1,950 2023-07-21
Portal For Arcgis MEDIUM 5.4
CVE-2023-25836

There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attac…

Fix: after 10.9
Fix from $1,600 2023-07-21
Portal For Arcgis HIGH 8.4
CVE-2023-25835

There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS Sites versions 11.1 and below that may allow a remote, authentic…

Fix: after 11.1
Fix from $1,950 2023-07-21
Arcgis Insights HIGH 7.5
CVE-2023-25838

There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, authorized attacker to execute…

Patch available
Fix from $1,950 2023-07-19
Arcgis Insights HIGH 7.0
CVE-2023-25839

There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker …

Patch available
Fix from $1,950 2023-07-19
Portal For Arcgis MEDIUM 5.4
CVE-2023-25833

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create …

Fix: after 11.0
Fix from $1,600 2023-05-10
Portal For Arcgis HIGH 8.8
CVE-2023-25832

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authoriz…

Fix: after 11.0
Fix from $1,950 2023-05-09
Portal For Arcgis MEDIUM 6.1
CVE-2023-25831

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to creat…

Mitigation only
Fix from $1,600 2023-05-09
Portal For Arcgis MEDIUM 6.1
CVE-2023-25829

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a …

No fix yet
Fix from $1,600 2023-05-09
Portal For Arcgis MEDIUM 6.1
CVE-2023-25830

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to crea…

Mitigation only
Fix from $1,600 2023-05-09
Portal For Arcgis MEDIUM 5.4
CVE-2023-25834

Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to acces…

Fix: after 10.9.1
Fix from $1,600 2023-05-09
Portal For Arcgis HIGH 7.5
CVE-2022-38211

Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully h…

Fix: after 10.9.1
Fix from $1,950 2022-12-29
Portal For Arcgis HIGH 7.5
CVE-2022-38212

Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully h…

Fix: after 10.8.1
Fix from $1,950 2022-12-29
Portal For Arcgis HIGH 7.5
CVE-2022-38203

Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully h…

Fix: after 10.8.1
Fix from $1,950 2022-12-29