Esri
Esri Arcgis Server: vulnerabilidades y CVE
Esri Arcgis Server tiene 69 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE69
Últimos 12 meses14
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9182 | Crítica (9.8) | 0.62% | — | 6 jul 2026 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow… |
| CVE-2026-9181 | Alta (7.5) | 1.2% | — | 6 jul 2026 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful… |
| CVE-2026-2813 | Media (4.1) | 0.32% | — | 20 may 2026 | ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the… |
| CVE-2026-2812 | Media (5.3) | 0.38% | — | 20 may 2026 | ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful… |
| CVE-2025-67711 | Media (6.1) | 0.24% | — | 31 dic 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code… |
| CVE-2025-67710 | Media (6.1) | 0.24% | — | 31 dic 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code… |
| CVE-2025-67709 | Media (6.1) | 0.24% | — | 31 dic 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code… |
| CVE-2025-67708 | Media (6.1) | 0.24% | — | 31 dic 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code… |
| CVE-2025-67707 | Media (5.6) | 0.30% | — | 31 dic 2025 | ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload… |
| CVE-2025-67706 | Media (5.6) | 0.35% | — | 31 dic 2025 | ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload… |
| CVE-2025-67705 | Media (6.1) | 0.24% | — | 31 dic 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code… |
| CVE-2025-67704 | Media (6.1) | 0.25% | — | 31 dic 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code… |
| CVE-2025-67703 | Media (6.1) | 0.24% | — | 31 dic 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code… |
| CVE-2025-57870 | Crítica (10) | 0.54% | — | 22 oct 2025 | A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands… |
| CVE-2024-5888 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51966 | Media (4.9) | 0.60% | — | 3 mar 2025 | There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files… |
| CVE-2024-51963 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51962 | Alta (8.7) | 0.51% | — | 3 mar 2025 | A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated,… |
| CVE-2024-51961 | Alta (7.5) | 0.47% | — | 3 mar 2025 | There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by… |
| CVE-2024-51960 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51959 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51958 | Media (4.9) | 0.61% | — | 3 mar 2025 | There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files… |
| CVE-2024-51957 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51956 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51954 | Alta (8.5) | 0.32% | — | 3 mar 2025 | There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure… |
| CVE-2024-51953 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51952 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51951 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51950 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
| CVE-2024-51949 | Media (4.8) | 0.27% | — | 3 mar 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.