Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-13019 Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability a… Portal For Arcgis after 12.1 Fix from $2,3002026-07-07 CRITICAL 9.8 CVE-2026-13020 A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes… Portal For Arcgis after 12.1 Fix from $2,3002026-07-07 CRITICAL 9.8 CVE-2026-9182 Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted fi… Arcgis Server after 12.0 Fix from $2,3002026-07-06 HIGH 7.5 CVE-2026-9181 Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could e… Arcgis Server after 12.0 Fix from $1,9502026-07-06 MEDIUM 5.3 CVE-2026-2812 ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit… Arcgis Server after 12.0 Fix from $1,6002026-05-20 CRITICAL 9.8 CVE-2026-33519 An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly… Portal For Arcgis Mitigation only Fix from $2,3002026-04-21 HIGH 7.2 CVE-2026-33518 An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to cre… Portal For Arcgis Mitigation only Fix from $1,9502026-04-21 MEDIUM 5.0 CVE-2026-1446 There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is l… Arcgis Pro 3.6.1+ Fix from $1,6002026-01-26 MEDIUM 6.1 CVE-2025-67709 There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 6.1 CVE-2025-67710 There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 6.1 CVE-2025-67711 There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 6.1 CVE-2025-67704 There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 6.1 CVE-2025-67705 There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 6.1 CVE-2025-67708 There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 5.6 CVE-2025-67706 ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 5.6 CVE-2025-67707 ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 6.1 CVE-2025-67703 There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote … Arcgis Server after 11.5 Fix from $1,6002025-12-31 CRITICAL 10.0 CVE-2025-57870 A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a… Arcgis Server after 11.5 Fix from $2,3002025-10-22 MEDIUM 6.1 CVE-2025-57878 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis Patch available Fix from $1,6002025-09-29 MEDIUM 6.1 CVE-2025-57879 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis Patch available Fix from $1,6002025-09-29 MEDIUM 6.1 CVE-2025-57872 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis Patch available Fix from $1,6002025-09-29 CRITICAL 9.1 CVE-2025-4967 Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections. Portal For Arcgis after 11.4 Fix from $2,3002025-05-29 CRITICAL 9.8 CVE-2025-2538 A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remo… Portal For Arcgis after 11.4 Fix from $2,3002025-03-20 HIGH 8.7 CVE-2024-51962 A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when… Arcgis Server after 11.3 Fix from $1,9502025-03-03 HIGH 7.5 CVE-2024-51961 There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that c… Arcgis Server after 11.3 Fix from $1,9502025-03-03 HIGH 8.5 CVE-2024-51954 There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allo… Arcgis Server after 11.3 Fix from $1,9502025-03-03 HIGH 7.3 CVE-2025-1067 There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the … Arcgis Allsource Mitigation only Fix from $1,9502025-02-25 HIGH 7.3 CVE-2025-1068 There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges t… Arcgis Allsource Mitigation only Fix from $1,9502025-02-25 MEDIUM 6.1 CVE-2024-8148 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis Mitigation only Fix from $1,6002024-10-04 HIGH 7.5 CVE-2024-38040 There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a U… Portal For Arcgis Mitigation only Fix from $1,9502024-10-04