VYPR

Arcgis Server

by Esri

CVEs (71)

  • CVE-2025-57870CriOct 22, 2025
    risk 0.65cvss 10.0epss 0.01

    A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful…

  • CVE-2021-29114CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

  • CVE-2020-35712CriDec 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.

  • CVE-2021-29102CriJul 11, 2021
    risk 0.59cvss 9.1epss 0.02

    A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2024-51962HigMar 3, 2025
    risk 0.57cvss 8.7epss 0.00

    A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users…

  • CVE-2024-51954HigMar 3, 2025
    risk 0.55cvss 8.5epss 0.00

    There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS…

  • CVE-2024-51961HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the…

  • CVE-2022-38202HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on ArcGIS Server. This could lead to the…

  • CVE-2021-29101HigMay 5, 2021
    risk 0.49cvss 7.5epss 0.02

    ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.

  • CVE-2021-29095MedMar 25, 2021
    risk 0.44cvss 6.8epss 0.01

    Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.

  • CVE-2021-29094MedMar 25, 2021
    risk 0.44cvss 6.8epss 0.01

    Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.

  • CVE-2021-29093MedMar 25, 2021
    risk 0.44cvss 6.8epss 0.01

    A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.

  • CVE-2022-38196MedOct 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authenticated attacker to overwrite internal ArcGIS Server directory.

  • CVE-2025-67711MedDec 31, 2025
    risk 0.40cvss 6.1epss 0.00

    There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

  • CVE-2025-67710MedDec 31, 2025
    risk 0.40cvss 6.1epss 0.00

    There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

  • CVE-2025-67709MedDec 31, 2025
    risk 0.40cvss 6.1epss 0.00

    There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

  • CVE-2025-67708MedDec 31, 2025
    risk 0.40cvss 6.1epss 0.00

    There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

  • CVE-2025-67705MedDec 31, 2025
    risk 0.40cvss 6.1epss 0.00

    There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

  • CVE-2025-67704MedDec 31, 2025
    risk 0.40cvss 6.1epss 0.00

    There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

  • CVE-2025-67703MedDec 31, 2025
    risk 0.40cvss 6.1epss 0.00

    There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

Page 1 of 4