Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-38205 In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may allow a remote, unauthenticate… Portal For Arcgis after 10.9.1 Fix from $1,9502022-12-29 MEDIUM 6.1 CVE-2022-38204 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to cre… Portal For Arcgis Mitigation only Fix from $1,6002022-12-29 MEDIUM 6.1 CVE-2022-38206 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote remote, unauthenticated attacker … Portal For Arcgis after 10.9.1 Fix from $1,6002022-12-29 MEDIUM 6.1 CVE-2022-38207 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker… Portal For Arcgis Mitigation only Fix from $1,6002022-12-29 MEDIUM 6.1 CVE-2022-38208 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a UR… Portal For Arcgis after 11.0 Fix from $1,6002022-12-29 MEDIUM 6.1 CVE-2022-38209 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to crea… Portal For Arcgis after 10.9.1 Fix from $1,6002022-12-29 MEDIUM 6.1 CVE-2022-38210 There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attack… Portal For Arcgis after 10.9.1 Fix from $1,6002022-12-29 HIGH 7.5 CVE-2022-38202 There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated … Arcgis Server after 10.9.1 Fix from $1,9502022-12-28 MEDIUM 6.1 CVE-2022-38201 An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticate… Arcgis Quickcapture after 10.9.1 Fix from $1,6002022-11-15 HIGH 8.1 CVE-2022-38196 Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authent… Arcgis Server after 10.9.1 Fix from $1,9502022-10-25 MEDIUM 6.1 CVE-2022-38195 There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote unauthorized attacker able … Arcgis Server after 10.9.1 Fix from $1,6002022-10-25 MEDIUM 6.1 CVE-2022-38197 Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user int… Arcgis Server after 10.9.1 Fix from $1,6002022-10-25 MEDIUM 6.1 CVE-2022-38198 There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unaut… Arcgis Server after 10.9.1 Fix from $1,6002022-10-25 MEDIUM 6.1 CVE-2022-38199 A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenti… Arcgis Server Mitigation only Fix from $1,6002022-10-25 MEDIUM 6.1 CVE-2022-38200 A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web … Arcgis Server Mitigation only Fix from $1,6002022-10-25 HIGH 7.5 CVE-2022-38184 There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker… Portal For Arcgis after 10.8.1 Fix from $1,9502022-08-16 MEDIUM 5.4 CVE-2022-38189 A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious st… Portal For Arcgis Mitigation only Fix from $1,6002022-08-16 CRITICAL 9.6 CVE-2022-38193 There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass… Portal For Arcgis after 10.8.1 Fix from $2,3002022-08-16 MEDIUM 5.5 CVE-2022-38194 In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information f… Portal For Arcgis Mitigation only Fix from $1,6002022-08-16 MEDIUM 5.4 CVE-2022-38192 A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious st… Portal For Arcgis after 10.8.1 Fix from $1,6002022-08-16 MEDIUM 6.1 CVE-2022-38188 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click o… Portal For Arcgis after 10.8.1 Fix from $1,6002022-08-15 MEDIUM 6.1 CVE-2022-38190 A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass an… Portal For Arcgis after 10.8.1 Fix from $1,6002022-08-15 MEDIUM 5.4 CVE-2022-38191 There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML … Portal For Arcgis after 10.9 Fix from $1,6002022-08-15 HIGH 7.5 CVE-2022-38187 Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthentic… Portal For Arcgis 10.9+ Fix from $1,9502022-08-15 MEDIUM 6.1 CVE-2022-38186 There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user … Portal For Arcgis after 10.8.1 Fix from $1,6002022-08-15 HIGH 7.8 CVE-2021-29117 A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to ach… Arcreader after 10.8.1 Fix from $1,9502022-08-12 MEDIUM 5.5 CVE-2021-29118 An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticate… Arcreader after 10.8.1 Fix from $1,6002022-08-12 MEDIUM 5.5 CVE-2021-29112 An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticate… Arcreader after 10.8.1 Fix from $1,6002022-08-12 MEDIUM 6.1 CVE-2021-29116 A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a… Arcgis Server Mitigation only Fix from $1,6002021-12-07 CRITICAL 9.8 CVE-2021-29114 A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact t… Arcgis Server after 10.9.0 Fix from $2,3002021-12-07