« Volver al listado

Esri

Esri Arcgis Server: vulnerabilidades y CVE

Esri Arcgis Server tiene 69 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE69
Últimos 12 meses14
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-9182Crítica (9.8)0.62%—6 jul 2026
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow…
CVE-2026-9181Alta (7.5)1.2%—6 jul 2026
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful…
CVE-2026-2813Media (4.1)0.32%—20 may 2026
ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the…
CVE-2026-2812Media (5.3)0.38%—20 may 2026
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful…
CVE-2025-67711Media (6.1)0.24%—31 dic 2025
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code…
CVE-2025-67710Media (6.1)0.24%—31 dic 2025
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code…
CVE-2025-67709Media (6.1)0.24%—31 dic 2025
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code…
CVE-2025-67708Media (6.1)0.24%—31 dic 2025
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code…
CVE-2025-67707Media (5.6)0.30%—31 dic 2025
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload…
CVE-2025-67706Media (5.6)0.35%—31 dic 2025
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload…
CVE-2025-67705Media (6.1)0.24%—31 dic 2025
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code…
CVE-2025-67704Media (6.1)0.25%—31 dic 2025
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code…
CVE-2025-67703Media (6.1)0.24%—31 dic 2025
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code…
CVE-2025-57870Crítica (10)0.54%—22 oct 2025
A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands…
CVE-2024-5888Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51966Media (4.9)0.60%—3 mar 2025
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files…
CVE-2024-51963Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51962Alta (8.7)0.51%—3 mar 2025
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated,…
CVE-2024-51961Alta (7.5)0.47%—3 mar 2025
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by…
CVE-2024-51960Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51959Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51958Media (4.9)0.61%—3 mar 2025
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files…
CVE-2024-51957Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51956Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51954Alta (8.5)0.32%—3 mar 2025
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure…
CVE-2024-51953Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51952Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51951Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51950Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…
CVE-2024-51949Media (4.8)0.27%—3 mar 2025
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System5
  2. T1190 Exploit Public-Facing Application4
  3. T1210 Exploitation of Remote Services2
  4. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Esri