VendorsEsriarcgis_serverall versions
Vulnerabilities

Esri ArcGIS Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2025-57870
BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.
Published 2025-10-22 · Analyzed
10.0EPSS 0.005
CVE-2020-35712
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Published 2020-12-25 · Modified
9.8EPSS 0.017
CVE-2026-9181
Directory Traversal in ArcGIS Server
Published 2026-07-06 · Modified
9.8EPSS 0.012
CVE-2021-29114
SQL injection vulnerability in ArcGIS Server
Published 2021-12-07 · Modified
9.8EPSS 0.010
CVE-2026-9182
Unvalidated File Upload vulnerability in ArcGIS Server.
Published 2026-07-06 · Modified
9.8EPSS 0.006
CVE-2021-29102
There is a Server-Side Request Forgery (SSRF) vulnerability in Esri ArcGIS Server Manager version 10.8.1 and below.
Published 2021-07-11 · Modified
9.1EPSS 0.016
CVE-2024-51962
SQL injection vulnerability in ArcGIS Server
Published 2025-03-03 · Analyzed
8.7EPSS 0.005
CVE-2024-51954
Unauthorized access to secure services in ArcGIS Server
Published 2025-03-03 · Analyzed
8.5EPSS 0.003
CVE-2022-38196
BUG-000150537 - ArcGIS Server has a local file inclusion (LFI) vulnerability
Published 2022-10-25 · Modified
8.1EPSS 0.011
CVE-2013-7232
SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to the map or feature service.
Published 2013-12-30 · Modified
7.5EPSS 0.023
CVE-2022-38202
BUG-000152121 - Directory traversal vulnerability in ArcGIS Server.
Published 2022-12-28 · Modified
7.5EPSS 0.013
CVE-2024-51961
Local file inclusion (LFI) vulnerability in ArcGIS Server
Published 2025-03-03 · Modified
7.5EPSS 0.005
CVE-2021-29094
ArcGIS Server image service and raster analytics security update: buffer overflow
Published 2021-03-25 · Modified
6.8EPSS 0.010
CVE-2021-29093
ArcGIS Server image service and raster analytics security update: use-after-free
Published 2021-03-25 · Modified
6.8EPSS 0.009
CVE-2021-29095
ArcGIS Server image service and raster analytics security update: uninitialized pointer
Published 2021-03-25 · Modified
6.8EPSS 0.009
CVE-2012-4949
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.
Published 2012-11-14 · Modified
6.51 PoCEPSS 0.044
CVE-2021-29107
There is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below.
Published 2021-07-10 · Modified
6.1EPSS 0.009
CVE-2021-29104
There is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below.
Published 2021-07-11 · Modified
6.1EPSS 0.008
CVE-2021-29116
BUG-000142180 Hosted feature services vulnerable to stored XSS
Published 2021-12-07 · Modified
6.1EPSS 0.008
CVE-2021-29103
There is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.
Published 2021-07-11 · Modified
6.1EPSS 0.007
CVE-2021-29106
There is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.
Published 2021-07-10 · Modified
6.1EPSS 0.007
CVE-2023-25841
BUG-000158075 Stored XSS issue in ArcGIS Server
Published 2023-07-21 · Modified
6.1EPSS 0.006
CVE-2022-38198
BUG-000146513 - Reflected XSS vulnerability in ArcGIS Server
Published 2022-10-25 · Modified
6.1EPSS 0.006
CVE-2022-38197
BUG-000148347 Unvalidated redirect issues in ArcGIS Server.
Published 2022-10-25 · Modified
6.1EPSS 0.005
CVE-2022-38195
BUG-000150540 - Reflected XSS vulnerability in ArcGIS Server
Published 2022-10-25 · Modified
6.1EPSS 0.004
CVE-2022-38200
BUG-000142376 - Reflected Cross-Site Scripting (XSS) vulnerability in ArcGIS Server.
Published 2022-10-25 · Modified
6.1EPSS 0.003
CVE-2022-38199
BUG-000144172 - Remote file download issue in ArcGIS Server
Published 2022-10-25 · Modified
6.1EPSS 0.003
CVE-2025-67704
Stored XSS vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67708
Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67711
Reflected XSS vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67709
There is a cross site scripting issue in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67710
Stored XSS vulnerability in ArcGIS Server
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67705
Reflected XSS vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67703
Stored XSS vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2014-5122
Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, related to login.
Published 2014-08-22 · Modified
5.8EPSS 0.021
CVE-2025-67706
Unvalidated File Upload vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
5.6EPSS 0.004
CVE-2025-67707
Unvalidated File Upload vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
5.6EPSS 0.003
CVE-2021-29105
There is a stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below.
Published 2021-07-11 · Modified
5.4EPSS 0.006
CVE-2021-29099
There is a SQL injection vulnerability in ArcGIS Server
Published 2021-06-07 · Modified
5.3EPSS 0.006
CVE-2026-2812
Improper Authentication issue in ArcGIS Server
Published 2026-05-20 · Analyzed
5.3EPSS 0.004
1 / 2Next →