VYPR

Arcgis Server

by Esri

CVEs (71)

  • CVE-2026-2813MedMay 20, 2026
    risk 0.31cvss 4.7epss 0.00

    ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to an unintended,…

  • CVE-2024-5888MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51963MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51960MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51959MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51957MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51956MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51953MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51952MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51951MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51950MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51949MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51948MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51947MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51946MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51945MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51944MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51942MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-10904MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2021-29113MedDec 7, 2021
    risk 0.31cvss 4.7epss 0.01

    A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.