CVE-2025-67703
- EPSS 0.19%
- Veröffentlicht 31.12.2025 22:13:12
- Zuletzt bearbeitet 06.01.2026 19:15:11
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context o...
- EPSS 0.5%
- Veröffentlicht 22.10.2025 14:26:22
- Zuletzt bearbeitet 31.10.2025 18:51:22
A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Ser...
CVE-2024-5888
- EPSS 0.25%
- Veröffentlicht 03.03.2025 20:15:43
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51966
- EPSS 0.55%
- Veröffentlicht 03.03.2025 20:15:43
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended direct...
CVE-2024-51963
- EPSS 0.25%
- Veröffentlicht 03.03.2025 20:15:43
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code ...
CVE-2024-51962
- EPSS 0.47%
- Veröffentlicht 03.03.2025 20:15:43
- Zuletzt bearbeitet 13.02.2026 19:41:49
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploita...
CVE-2024-51961
- EPSS 0.43%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remo...
CVE-2024-51956
- EPSS 0.25%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:20
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51957
- EPSS 0.25%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51958
- EPSS 0.56%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended direct...