VendorsEsriarcgis_serverany version
Vulnerabilities

Esri ArcGIS Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

58CVEs
CVE-2025-57870
BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.
Published 2025-10-22 · Analyzed
10.0EPSS 0.005
CVE-2020-35712
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Published 2020-12-25 · Modified
9.8EPSS 0.017
CVE-2026-9181
Directory Traversal in ArcGIS Server
Published 2026-07-06 · Modified
9.8EPSS 0.012
CVE-2021-29114
SQL injection vulnerability in ArcGIS Server
Published 2021-12-07 · Modified
9.8EPSS 0.010
CVE-2026-9182
Unvalidated File Upload vulnerability in ArcGIS Server.
Published 2026-07-06 · Modified
9.8EPSS 0.006
CVE-2021-29102
There is a Server-Side Request Forgery (SSRF) vulnerability in Esri ArcGIS Server Manager version 10.8.1 and below.
Published 2021-07-11 · Modified
9.1EPSS 0.016
CVE-2024-51962
SQL injection vulnerability in ArcGIS Server
Published 2025-03-03 · Analyzed
8.7EPSS 0.005
CVE-2024-51954
Unauthorized access to secure services in ArcGIS Server
Published 2025-03-03 · Analyzed
8.5EPSS 0.003
CVE-2022-38196
BUG-000150537 - ArcGIS Server has a local file inclusion (LFI) vulnerability
Published 2022-10-25 · Modified
8.1EPSS 0.011
CVE-2013-7232
SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to the map or feature service.
Published 2013-12-30 · Modified
7.5EPSS 0.023
CVE-2022-38202
BUG-000152121 - Directory traversal vulnerability in ArcGIS Server.
Published 2022-12-28 · Modified
7.5EPSS 0.013
CVE-2024-51961
Local file inclusion (LFI) vulnerability in ArcGIS Server
Published 2025-03-03 · Modified
7.5EPSS 0.005
CVE-2021-29094
ArcGIS Server image service and raster analytics security update: buffer overflow
Published 2021-03-25 · Modified
6.8EPSS 0.010
CVE-2021-29093
ArcGIS Server image service and raster analytics security update: use-after-free
Published 2021-03-25 · Modified
6.8EPSS 0.009
CVE-2021-29095
ArcGIS Server image service and raster analytics security update: uninitialized pointer
Published 2021-03-25 · Modified
6.8EPSS 0.009
CVE-2021-29104
There is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below.
Published 2021-07-11 · Modified
6.1EPSS 0.008
CVE-2021-29103
There is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.
Published 2021-07-11 · Modified
6.1EPSS 0.007
CVE-2021-29106
There is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.
Published 2021-07-10 · Modified
6.1EPSS 0.007
CVE-2023-25841
BUG-000158075 Stored XSS issue in ArcGIS Server
Published 2023-07-21 · Modified
6.1EPSS 0.006
CVE-2022-38198
BUG-000146513 - Reflected XSS vulnerability in ArcGIS Server
Published 2022-10-25 · Modified
6.1EPSS 0.006
CVE-2022-38197
BUG-000148347 Unvalidated redirect issues in ArcGIS Server.
Published 2022-10-25 · Modified
6.1EPSS 0.005
CVE-2022-38195
BUG-000150540 - Reflected XSS vulnerability in ArcGIS Server
Published 2022-10-25 · Modified
6.1EPSS 0.004
CVE-2025-67704
Stored XSS vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67708
Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67711
Reflected XSS vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67709
There is a cross site scripting issue in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67710
Stored XSS vulnerability in ArcGIS Server
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67705
Reflected XSS vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67703
Stored XSS vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
6.1EPSS 0.002
CVE-2025-67706
Unvalidated File Upload vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
5.6EPSS 0.004
CVE-2025-67707
Unvalidated File Upload vulnerability in ArcGIS Server.
Published 2025-12-31 · Analyzed
5.6EPSS 0.003
CVE-2021-29105
There is a stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below.
Published 2021-07-11 · Modified
5.4EPSS 0.006
CVE-2021-29099
There is a SQL injection vulnerability in ArcGIS Server
Published 2021-06-07 · Modified
5.3EPSS 0.006
CVE-2026-2812
Improper Authentication issue in ArcGIS Server
Published 2026-05-20 · Analyzed
5.3EPSS 0.004
CVE-2023-25848
BUG-000158039 - There is an information disclosure issue in ArcGIS Server.
Published 2023-08-25 · Modified
5.3EPSS 0.003
CVE-2024-51958
Directory traversal vulnerability in the admin api for service thumbnails
Published 2025-03-03 · Modified
4.9EPSS 0.006
CVE-2024-51966
Directory traversal vulnerability in ArcGIS Server
Published 2025-03-03 · Modified
4.9EPSS 0.006
CVE-2024-51951
Stored XSS in Server Admin API
Published 2025-03-03 · Modified
4.8EPSS 0.003
CVE-2024-51952
Stored XSS issue in ArcGIS Server
Published 2025-03-03 · Modified
4.8EPSS 0.003
CVE-2024-51953
Stored XSS in ArcGIS Server Rest services
Published 2025-03-03 · Modified
4.8EPSS 0.003
1 / 2Next →