VYPR

Vendor CVEs

Esri

All CVEs

172 total · sorted by risk
  • CVE-2021-29115MedDec 7, 2021
    risk 0.35cvss 5.3epss 0.02

    An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.

  • CVE-2021-29110MedOct 1, 2021
    risk 0.35cvss 5.4epss 0.01

    Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.

  • CVE-2021-29105MedJul 11, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.

  • CVE-2021-29099MedJun 7, 2021
    risk 0.35cvss 5.3epss 0.01

    A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets). Web Services that use file based data sources (file…

  • CVE-2021-3012MedApr 8, 2021
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in the Document Link of documents in ESRI Enterprise before 10.9 allows remote authenticated users to inject arbitrary JavaScript code via a malicious HTML attribute such as onerror (in the URL field of the Parameters tab).

  • CVE-2019-16193MedSep 11, 2019
    risk 0.35cvss 5.4epss 0.01

    In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.

  • CVE-2026-2812MedMay 20, 2026
    risk 0.34cvss 5.3epss 0.00

    ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based…

  • CVE-2023-25848MedAug 25, 2023
    risk 0.34cvss 5.3epss 0.00

    ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single…

  • CVE-2026-1446MedJan 26, 2026
    risk 0.33cvss 5.0epss 0.00

    There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is limited to local users interacting with the application; no privileged role or elevated permissions are required beyond standard…

  • CVE-2024-51966MedMar 3, 2025
    risk 0.32cvss 4.9epss 0.01

    There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to…

  • CVE-2024-51958MedMar 3, 2025
    risk 0.32cvss 4.9epss 0.01

    There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory.  There is no impact to…

  • CVE-2026-2813MedMay 20, 2026
    risk 0.31cvss 4.7epss 0.00

    ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to an unintended,…

  • CVE-2025-67712MedDec 19, 2025
    risk 0.31cvss 4.7epss 0.00

    There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of…

  • CVE-2025-57877MedSep 29, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

  • CVE-2025-57876MedSep 29, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potentially execute arbitrary JavaScript code in the…

  • CVE-2025-57875MedSep 29, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

  • CVE-2025-57874MedSep 29, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

  • CVE-2025-57873MedSep 29, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

  • CVE-2025-57871MedSep 29, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

  • CVE-2025-55107MedAug 21, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potentially execute…

  • CVE-2025-55106MedAug 21, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potentially execute arbitrary…

  • CVE-2025-55105MedAug 21, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potentially execute arbitrary…

  • CVE-2025-55104MedAug 21, 2025
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists ArcGIS HUB and ArcGIS Enterprise Sites which allows an authenticated user with the ability to create or edit a site to add and store an XSS payload. If this stored XSS payload is triggered by any user attacker supplied…

  • CVE-2025-55103MedAug 21, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potentially execute arbitrary…

  • CVE-2024-5888MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51963MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51960MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51959MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51957MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51956MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51953MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51952MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51951MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51950MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51949MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51948MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51947MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51946MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51945MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51944MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-51942MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-10904MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. …

  • CVE-2024-25707MedOct 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript code in the their own…

  • CVE-2024-25702MedOct 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in the site configuration which when clicked could potentially execute…

  • CVE-2024-25701MedOct 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Experience Builder versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in the Experience Builder Embed widget which when loaded…

  • CVE-2024-25694MedOct 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in the Layer Showcase application configuration which when clicked could…

  • CVE-2024-25708MedApr 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.1 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in…

  • CVE-2024-25700MedApr 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in a web map link which when clicked could potentially…

  • CVE-2024-25696MedApr 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when accessing the page editor an image will render in the victim’s browser. The privileges required to…

  • CVE-2024-25690MedApr 4, 2024
    risk 0.31cvss 4.7epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.