VYPR

Vendor CVEs

Esri

All CVEs

172 total · sorted by risk
  • CVE-2025-57878MedSep 29, 2025
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2025-57872MedSep 29, 2025
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2024-8148MedOct 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2024-38038MedOct 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2024-38037MedOct 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2024-25691MedOct 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2024-25709MedApr 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, which could potentially…

  • CVE-2024-25706MedApr 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This…

  • CVE-2024-25698MedApr 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript…

  • CVE-2023-25841MedJul 21, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary JavaScript code in…

  • CVE-2023-25831MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2023-25830MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2023-25829MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2022-38210MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.

  • CVE-2022-38209MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38208MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2022-38207MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked which could execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38206MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38204MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38201MedNov 15, 2022
    risk 0.40cvss 6.1epss 0.00

    An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

  • CVE-2022-38200MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web requests can execute arbitrary JavaScript in the context of the victim's browser.

  • CVE-2022-38199MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide…

  • CVE-2022-38198MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unauthenticated attacker to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the…

  • CVE-2022-38197MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user into accessing an attacker controlled website via a crafted query parameter.

  • CVE-2022-38195MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote unauthorized attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38193MedAug 16, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution.

  • CVE-2022-38192MedAug 16, 2022
    risk 0.40cvss 6.1epss 0.01

    A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.

  • CVE-2022-38191MedAug 15, 2022
    risk 0.40cvss 6.1epss 0.01

    There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML into some locations in the home application.

  • CVE-2022-38190MedAug 15, 2022
    risk 0.40cvss 6.1epss 0.01

    A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the…

  • CVE-2022-38188MedAug 15, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2022-38186MedAug 15, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2021-29116MedDec 7, 2021
    risk 0.40cvss 6.1epss 0.01

    A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially…

  • CVE-2021-29109MedOct 1, 2021
    risk 0.40cvss 6.1epss 0.01

    A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.

  • CVE-2021-29104MedJul 11, 2021
    risk 0.40cvss 6.1epss 0.01

    A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.

  • CVE-2021-29103MedJul 11, 2021
    risk 0.40cvss 6.1epss 0.01

    A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.

  • CVE-2021-29107MedJul 10, 2021
    risk 0.40cvss 6.1epss 0.01

    A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.

  • CVE-2021-29106MedJul 10, 2021
    risk 0.40cvss 6.1epss 0.01

    A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.

  • CVE-2025-67707MedDec 31, 2025
    risk 0.36cvss 5.6epss 0.00

    ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture enforces controls…

  • CVE-2025-67706MedDec 31, 2025
    risk 0.36cvss 5.6epss 0.00

    ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture enforces controls…

  • CVE-2021-29118MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.

  • CVE-2021-29112MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.

  • CVE-2024-38039MedOct 4, 2024
    risk 0.35cvss 5.4epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data…

  • CVE-2024-38036MedOct 4, 2024
    risk 0.35cvss 5.4epss 0.01

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

  • CVE-2024-25705MedApr 4, 2024
    risk 0.35cvss 5.4epss 0.00

    There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, could…

  • CVE-2024-25697MedApr 4, 2024
    risk 0.35cvss 5.4epss 0.00

    There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The…

  • CVE-2024-25692MedApr 4, 2024
    risk 0.35cvss 5.4epss 0.00

    There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and…

  • CVE-2023-25836MedJul 21, 2023
    risk 0.35cvss 5.4epss 0.00

    There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The…

  • CVE-2023-25833MedMay 10, 2023
    risk 0.35cvss 5.4epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data…

  • CVE-2023-25834MedMay 9, 2023
    risk 0.35cvss 5.4epss 0.00

    Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.

  • CVE-2022-38189MedAug 16, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.