VYPR

Arcgis Enterprise

by Esri

CVEs (25)

  • CVE-2022-38205HigDec 29, 2022
    risk 0.56cvss 8.6epss 0.02

    In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may allow a remote, unauthenticated attacker to traverse the file system and lead to the disclosure of sensitive data (not customer-published content).

  • CVE-2024-25699HigApr 4, 2024
    risk 0.55cvss 8.5epss 0.01

    There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows and Linux, and ArcGIS Enterprise versions 11.1 and below on Kubernetes, which under unique circumstances could allow a remote,…

  • CVE-2023-25837HigJul 21, 2023
    risk 0.55cvss 8.4epss 0.01

    There is a Cross‑Site Scripting (XSS) vulnerability in Esri ArcGIS Enterprise Sites versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which, when clicked by a victim, could result in the execution of arbitrary JavaScript code in…

  • CVE-2022-38212HigDec 29, 2022
    risk 0.49cvss 7.5epss 0.01

    Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading…

  • CVE-2022-38211HigDec 29, 2022
    risk 0.49cvss 7.5epss 0.01

    Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading…

  • CVE-2026-69236MedAug 21, 2026
    risk 0.40cvss 6.1epss

    There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise…

  • CVE-2026-69234MedAug 21, 2026
    risk 0.40cvss 6.1epss

    There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.…

  • CVE-2022-38210MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.

  • CVE-2022-38208MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2022-38207MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked which could execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38206MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38204MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2026-69233MedAug 21, 2026
    risk 0.36cvss 5.5epss

    There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS…

  • CVE-2026-69232MedAug 21, 2026
    risk 0.36cvss 5.5epss

    There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise…

  • CVE-2026-69231MedAug 21, 2026
    risk 0.36cvss 5.5epss

    There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise…

  • CVE-2026-69230MedAug 21, 2026
    risk 0.36cvss 5.5epss

    There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS…

  • CVE-2026-69229MedAug 21, 2026
    risk 0.35cvss 5.4epss

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are…

  • CVE-2021-29115MedDec 7, 2021
    risk 0.35cvss 5.3epss 0.02

    An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.

  • CVE-2021-3012MedApr 8, 2021
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in the Document Link of documents in ESRI Enterprise before 10.9 allows remote authenticated users to inject arbitrary JavaScript code via a malicious HTML attribute such as onerror (in the URL field of the Parameters tab).

  • CVE-2019-16193MedSep 11, 2019
    risk 0.35cvss 5.4epss 0.01

    In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.

Page 1 of 2