Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arcgis vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-29109
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.
Esri Portal For Arcgis
5.4
CVSSv3
CVE-2021-29110
Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated malicious user to pass and store malicious strings in the home application.
Esri Portal For Arcgis
NA
CVE-2014-5122
Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, related to login.
Esri Arcgis Server 10.1.1
5.5
CVSSv3
CVE-2022-38194
In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file.
Esri Portal For Arcgis 10.8.1
NA
CVE-2005-1394
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
Esri Arcgis 9.0
Esri Arcinfo Workstation 9.0
1 EDB exploit
NA
CVE-2024-25699
There is a difficult to exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 10.8.1 up to and including 11.2 on Windows and Linux, and ArcGIS Enterprise 11.1 and below on Kubernetes which, under unique circumstances, could potentially...
6.1
CVSSv3
CVE-2023-25841
There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 10.8.1 – 11.0 on Windows and Linux platforms that may allow a remote, unauthenticated malicious user to create crafted content which when clicked could potentially execute arbitrary JavaScr...
Esri Arcgis Server
9.8
CVSSv3
CVE-2020-35712
Esri ArcGIS Server prior to 10.8 is vulnerable to SSRF in some configurations.
Esri Arcgis Server
NA
CVE-2005-1393
Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.
Esri Arcinfo Workstation 9.0
NA
CVE-2024-25693
There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated malicious user to traverse the file system to access files or execute code outside of the intended directory.
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
NEXT »