Skip to main content

Vendor/product archive

esri / arcgis_server CVEs

Beta · best-effort

69 CVEs tagged to esri / arcgis_server6 Critical, 5 High, 54 Medium, 4 Low, 0 Unrated.

CVE-2024-5888

Published Mar 3, 2025

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51966

Published Mar 3, 2025

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51963

Published Mar 3, 2025

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51962

Published Mar 3, 2025

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authent…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51961

Published Mar 3, 2025

There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sens…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51960

Published Mar 3, 2025

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51959

Published Mar 3, 2025

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51958

Published Mar 3, 2025

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51957

Published Mar 3, 2025

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51956

Published Mar 3, 2025

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 69 CVEsPage 1 of 3