Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Portal For Arcgis HIGH 7.5
CVE-2022-38205

In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may allow a remote, unauthenticate…

Fix: after 10.9.1
Fix from $1,950 2022-12-29
Portal For Arcgis MEDIUM 6.1
CVE-2022-38204

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to cre…

Mitigation only
Fix from $1,600 2022-12-29
Portal For Arcgis MEDIUM 6.1
CVE-2022-38206

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote remote, unauthenticated attacker …

Fix: after 10.9.1
Fix from $1,600 2022-12-29
Portal For Arcgis MEDIUM 6.1
CVE-2022-38207

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker…

Mitigation only
Fix from $1,600 2022-12-29
Portal For Arcgis MEDIUM 6.1
CVE-2022-38208

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a UR…

Fix: after 11.0
Fix from $1,600 2022-12-29
Portal For Arcgis MEDIUM 6.1
CVE-2022-38209

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to crea…

Fix: after 10.9.1
Fix from $1,600 2022-12-29
Portal For Arcgis MEDIUM 6.1
CVE-2022-38210

There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attack…

Fix: after 10.9.1
Fix from $1,600 2022-12-29
Arcgis Server HIGH 7.5
CVE-2022-38202

There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated …

Fix: after 10.9.1
Fix from $1,950 2022-12-28
Arcgis Quickcapture MEDIUM 6.1
CVE-2022-38201

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticate…

Fix: after 10.9.1
Fix from $1,600 2022-11-15
Arcgis Server HIGH 8.1
CVE-2022-38196

Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authent…

Fix: after 10.9.1
Fix from $1,950 2022-10-25
Arcgis Server MEDIUM 6.1
CVE-2022-38195

There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote unauthorized attacker able …

Fix: after 10.9.1
Fix from $1,600 2022-10-25
Arcgis Server MEDIUM 6.1
CVE-2022-38197

Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user int…

Fix: after 10.9.1
Fix from $1,600 2022-10-25
Arcgis Server MEDIUM 6.1
CVE-2022-38198

There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unaut…

Fix: after 10.9.1
Fix from $1,600 2022-10-25
Arcgis Server MEDIUM 6.1
CVE-2022-38199

A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenti…

Mitigation only
Fix from $1,600 2022-10-25
Arcgis Server MEDIUM 6.1
CVE-2022-38200

A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web …

Mitigation only
Fix from $1,600 2022-10-25
Portal For Arcgis HIGH 7.5
CVE-2022-38184

There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker…

Fix: after 10.8.1
Fix from $1,950 2022-08-16
Portal For Arcgis MEDIUM 5.4
CVE-2022-38189

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious st…

Mitigation only
Fix from $1,600 2022-08-16
Portal For Arcgis CRITICAL 9.6
CVE-2022-38193

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass…

Fix: after 10.8.1
Fix from $2,300 2022-08-16
Portal For Arcgis MEDIUM 5.5
CVE-2022-38194

In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information f…

Mitigation only
Fix from $1,600 2022-08-16
Portal For Arcgis MEDIUM 5.4
CVE-2022-38192

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious st…

Fix: after 10.8.1
Fix from $1,600 2022-08-16
Portal For Arcgis MEDIUM 6.1
CVE-2022-38188

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click o…

Fix: after 10.8.1
Fix from $1,600 2022-08-15
Portal For Arcgis MEDIUM 6.1
CVE-2022-38190

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass an…

Fix: after 10.8.1
Fix from $1,600 2022-08-15
Portal For Arcgis MEDIUM 5.4
CVE-2022-38191

There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML …

Fix: after 10.9
Fix from $1,600 2022-08-15
Portal For Arcgis HIGH 7.5
CVE-2022-38187

Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthentic…

Fix: 10.9+
Fix from $1,950 2022-08-15
Portal For Arcgis MEDIUM 6.1
CVE-2022-38186

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user …

Fix: after 10.8.1
Fix from $1,600 2022-08-15
Arcreader HIGH 7.8
CVE-2021-29117

A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to ach…

Fix: after 10.8.1
Fix from $1,950 2022-08-12
Arcreader MEDIUM 5.5
CVE-2021-29118

An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticate…

Fix: after 10.8.1
Fix from $1,600 2022-08-12
Arcreader MEDIUM 5.5
CVE-2021-29112

An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticate…

Fix: after 10.8.1
Fix from $1,600 2022-08-12
Arcgis Server MEDIUM 6.1
CVE-2021-29116

A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a…

Mitigation only
Fix from $1,600 2021-12-07
Arcgis Server CRITICAL 9.8
CVE-2021-29114

A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact t…

Fix: after 10.9.0
Fix from $2,300 2021-12-07