📦 Arcgis Server

by Esri

🔍 What is Arcgis Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-29114

CRITICAL CVSS 9.8 Dec 7, 2021

A critical SQL injection vulnerability in Esri ArcGIS Server feature services allows remote unauthenticated attackers to execute arbitrary SQL commands. This can lead to data theft, data manipulation,...

CVE-2021-29102

CRITICAL CVSS 9.1 Jul 11, 2021

This SSRF vulnerability in ArcGIS Server Manager allows unauthenticated remote attackers to make arbitrary GET requests from the vulnerable system. This can lead to internal network scanning, data exf...

CVE-2020-35712

CRITICAL CVSS 9.8 Dec 26, 2020

CVE-2020-35712 is a Server-Side Request Forgery (SSRF) vulnerability in Esri ArcGIS Server that allows attackers to make unauthorized requests from the server to internal or external systems. This aff...

CVE-2024-51962

HIGH CVSS 8.7 Mar 3, 2025

A SQL injection vulnerability in ArcGIS Server allows authenticated users with advanced application-specific permissions to execute arbitrary SQL commands through EDIT operations. This affects ArcGIS ...

CVE-2024-51961

HIGH CVSS 7.5 Mar 3, 2025

A local file inclusion vulnerability in ArcGIS Server 11.3 and earlier allows remote unauthenticated attackers to read sensitive configuration files by crafting malicious URLs. This exposes internal s...

CVE-2024-51954

HIGH CVSS 8.5 Mar 3, 2025

An improper access control vulnerability in ArcGIS Server versions 11.3 and below allows authenticated attackers with low privileges to access secure services they shouldn't have permission to view. T...

CVE-2025-67709

MEDIUM CVSS 6.1 Dec 31, 2025

A stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server allows remote unauthenticated attackers to upload malicious files that execute JavaScript in victims' browsers when accessed. Th...

CVE-2025-67710

MEDIUM CVSS 6.1 Dec 31, 2025

A stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server allows remote unauthenticated attackers to upload malicious files that execute JavaScript in victims' browsers when accessed. Th...

CVE-2025-67711

MEDIUM CVSS 6.1 Dec 31, 2025

A stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server allows remote unauthenticated attackers to upload malicious files that execute JavaScript in victims' browsers when accessed. Th...

CVE-2025-67704

MEDIUM CVSS 6.1 Dec 31, 2025

A stored cross-site scripting vulnerability in Esri ArcGIS Server allows remote unauthenticated attackers to upload malicious files that execute in victims' browsers. This affects ArcGIS Server 11.4 a...

CVE-2025-67705

MEDIUM CVSS 6.1 Dec 31, 2025

A stored cross-site scripting vulnerability in Esri ArcGIS Server allows attackers to upload malicious files that execute JavaScript in victims' browsers when accessed. This affects ArcGIS Server 11.4...

CVE-2025-67706

MEDIUM CVSS 5.6 Dec 31, 2025

ArcGIS Server versions 11.5 and earlier on Windows and Linux contain a file upload vulnerability where remote attackers can upload arbitrary files. However, server-side controls prevent execution of u...

CVE-2025-67707

MEDIUM CVSS 5.6 Dec 31, 2025

ArcGIS Server versions 11.5 and earlier on Windows and Linux contain a file upload vulnerability that allows remote attackers to upload arbitrary files. However, server-side controls prevent execution...

CVE-2025-67708

MEDIUM CVSS 6.1 Dec 31, 2025

A stored cross-site scripting vulnerability in Esri ArcGIS Server allows attackers to upload malicious files that execute JavaScript in victims' browsers when accessed. This affects ArcGIS Server 11.4...

CVE-2025-67703

MEDIUM CVSS 6.1 Dec 31, 2025

A stored cross-site scripting vulnerability in Esri ArcGIS Server allows remote unauthenticated attackers to upload malicious files that execute JavaScript in victims' browsers when accessed. This aff...

CVE-2024-51966

MEDIUM CVSS 4.9 Mar 3, 2025

A path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below allows authenticated administrators to access files outside intended directories. This poses a high confidentiality risk as...

CVE-2024-51956

MEDIUM CVSS 4.8 Mar 3, 2025

A stored cross-site scripting vulnerability in ArcGIS Server versions 11.3 and below allows authenticated users with publisher privileges to inject malicious JavaScript links. When victims click these...

CVE-2024-51958

MEDIUM CVSS 4.9 Mar 3, 2025

A path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below allows remote authenticated attackers with admin privileges to access files outside intended directories, potentially expos...

CVE-2024-51960

MEDIUM CVSS 4.8 Mar 3, 2025

A stored cross-site scripting vulnerability in ArcGIS Server versions 11.3 and below allows authenticated attackers with publisher privileges to inject malicious JavaScript into links. When victims cl...

CVE-2024-51950

MEDIUM CVSS 4.8 Mar 3, 2025

A stored cross-site scripting (XSS) vulnerability in ArcGIS Server versions 11.3 and below allows authenticated attackers with publisher privileges to inject malicious JavaScript links. When victims c...

CVE-2024-51952

MEDIUM CVSS 4.8 Mar 3, 2025

A stored cross-site scripting (XSS) vulnerability in ArcGIS Server versions 11.3 and below allows authenticated users with publisher privileges to inject malicious JavaScript into links. When victims ...

CVE-2024-51946

MEDIUM CVSS 4.8 Mar 3, 2025

This stored XSS vulnerability in ArcGIS Server allows authenticated attackers with publisher privileges to inject malicious JavaScript into links. When victims click these crafted links, arbitrary cod...

CVE-2024-51944

MEDIUM CVSS 4.8 Mar 3, 2025

A stored cross-site scripting (XSS) vulnerability in ArcGIS Server versions 11.3 and below allows authenticated attackers with publisher privileges to inject malicious JavaScript into crafted links. W...

CVE-2024-51948

MEDIUM CVSS 4.8 Mar 3, 2025

A stored cross-site scripting vulnerability in ArcGIS Server versions 11.3 and below allows authenticated attackers with publisher privileges to inject malicious JavaScript links. When victims click t...

CVE-2024-10904

MEDIUM CVSS 4.8 Mar 3, 2025

A stored cross-site scripting vulnerability in ArcGIS Server versions 11.3 and below allows authenticated attackers with publisher privileges to inject malicious JavaScript links. When victims click t...