CVE-2026-69230
- EPSS 0.2%
- Veröffentlicht 21.08.2026 21:17:03
- Zuletzt bearbeitet 11.09.2026 17:48:52
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. User...
CVE-2026-69231
- EPSS 0.24%
- Veröffentlicht 21.08.2026 21:17:03
- Zuletzt bearbeitet 11.09.2026 17:06:39
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users work...
CVE-2026-69232
- EPSS 0.24%
- Veröffentlicht 21.08.2026 21:17:03
- Zuletzt bearbeitet 11.09.2026 17:05:31
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users work...
CVE-2026-13019
- EPSS 0.43%
- Veröffentlicht 07.07.2026 16:40:53
- Zuletzt bearbeitet 29.09.2026 20:17:19
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are kno...
CVE-2026-13020
- EPSS 0.27%
- Veröffentlicht 07.07.2026 16:39:16
- Zuletzt bearbeitet 09.07.2026 14:33:14
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mecha...
CVE-2026-33519
- EPSS 0.31%
- Veröffentlicht 21.04.2026 20:38:28
- Zuletzt bearbeitet 18.05.2026 18:19:36
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
CVE-2026-33518
- EPSS 0.3%
- Veröffentlicht 21.04.2026 20:37:52
- Zuletzt bearbeitet 18.05.2026 18:20:05
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
CVE-2025-57879
- EPSS 0.23%
- Veröffentlicht 29.09.2025 19:15:37
- Zuletzt bearbeitet 09.10.2026 09:10:00
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
CVE-2025-57878
- EPSS 0.23%
- Veröffentlicht 29.09.2025 19:15:37
- Zuletzt bearbeitet 09.10.2026 09:10:00
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
CVE-2025-57875
- EPSS 0.21%
- Veröffentlicht 29.09.2025 19:15:36
- Zuletzt bearbeitet 09.10.2026 09:10:00
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the...