VYPR

Arcgis Server

by Esri

CVEs (71)

  • CVE-2023-25841MedJul 21, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary JavaScript code in…

  • CVE-2022-38200MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web requests can execute arbitrary JavaScript in the context of the victim's browser.

  • CVE-2022-38199MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide…

  • CVE-2022-38198MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unauthenticated attacker to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the…

  • CVE-2022-38197MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user into accessing an attacker controlled website via a crafted query parameter.

  • CVE-2022-38195MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote unauthorized attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2021-29116MedDec 7, 2021
    risk 0.40cvss 6.1epss 0.01

    A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially…

  • CVE-2021-29104MedJul 11, 2021
    risk 0.40cvss 6.1epss 0.01

    A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.

  • CVE-2021-29103MedJul 11, 2021
    risk 0.40cvss 6.1epss 0.01

    A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.

  • CVE-2021-29107MedJul 10, 2021
    risk 0.40cvss 6.1epss 0.01

    A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.

  • CVE-2021-29106MedJul 10, 2021
    risk 0.40cvss 6.1epss 0.01

    A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.

  • CVE-2025-67707MedDec 31, 2025
    risk 0.36cvss 5.6epss 0.00

    ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture enforces controls…

  • CVE-2025-67706MedDec 31, 2025
    risk 0.36cvss 5.6epss 0.00

    ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture enforces controls…

  • CVE-2021-29115MedDec 7, 2021
    risk 0.35cvss 5.3epss 0.02

    An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.

  • CVE-2021-29105MedJul 11, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.

  • CVE-2021-29099MedJun 7, 2021
    risk 0.35cvss 5.3epss 0.01

    A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets). Web Services that use file based data sources (file…

  • CVE-2026-2812MedMay 20, 2026
    risk 0.34cvss 5.3epss 0.00

    ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based…

  • CVE-2023-25848MedAug 25, 2023
    risk 0.34cvss 5.3epss 0.00

    ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single…

  • CVE-2024-51966MedMar 3, 2025
    risk 0.32cvss 4.9epss 0.01

    There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to…

  • CVE-2024-51958MedMar 3, 2025
    risk 0.32cvss 4.9epss 0.01

    There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory.  There is no impact to…