Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.74% | — | Esri Portal FOR Arcgis | 29/12/2022 | 17/6/2026 | Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from… | |
| Modificada | Media (5.4) | 0.58% | — | Esri Portal FOR Arcgis | 16/8/2022 | 17/6/2026 | A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser. | |
| Modificada | Alta (7.5) | 0.99% | — | Esri Portal FOR Arcgis | 16/8/2022 | 17/6/2026 | There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs. | |
| Modificada | Media (5.5) | 0.13% | — | Esri Portal FOR Arcgis | 16/8/2022 | 17/6/2026 | In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file. | |
| Modificada | Crítica (9.6) | 0.89% | — | Esri Portal FOR Arcgis | 16/8/2022 | 17/6/2026 | There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution. | |
| Modificada | Media (5.4) | 0.55% | — | Esri Portal FOR Arcgis | 16/8/2022 | 17/6/2026 | A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser. | |
| Modificada | Media (5.4) | 0.55% | — | Esri Portal FOR Arcgis | 15/8/2022 | 17/6/2026 | There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML into some locations in the home application. | |
| Modificada | Media (6.1) | 0.62% | — | Esri Portal FOR Arcgis | 15/8/2022 | 17/6/2026 | A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser | |
| Modificada | Media (6.1) | 0.57% | — | Esri Portal FOR Arcgis | 15/8/2022 | 17/6/2026 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser. | |
| Modificada | Alta (7.5) | 0.69% | — | Esri Portal FOR Arcgis | 15/8/2022 | 17/6/2026 | Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthenticated attacker to induce Esri Portal for ArcGIS to read arbitrary URLs. | |
| Modificada | Media (6.1) | 0.57% | — | Esri Portal FOR Arcgis | 15/8/2022 | 17/6/2026 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser. | |
| Modificada | Media (5.4) | 0.66% | — | Esri Portal FOR Arcgis | 1/10/2021 | 17/6/2026 | Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application. | |
| Modificada | Media (6.1) | 0.74% | — | Esri Portal FOR Arcgis | 1/10/2021 | 17/6/2026 | A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser. | |
| Modificada | Alta (8.8) | 0.81% | — | Esri Portal FOR Arcgis | 1/10/2021 | 17/6/2026 | There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching,… |