Product
esri arcgis server
67 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2813
CVE-2026-2812
CVE-2025-67711
CVE-2025-67710
CVE-2025-67709
CVE-2025-67708
CVE-2025-67707
CVE-2025-67706
CVE-2025-67705
CVE-2025-67704
CVE-2025-67703
CVE-2025-57870
CVE-2024-5888
CVE-2024-51966
CVE-2024-51963
CVE-2024-51962
CVE-2024-51961
CVE-2024-51960
CVE-2024-51959
CVE-2024-51958
CVE-2024-51957
CVE-2024-51956
CVE-2024-51954
CVE-2024-51953
CVE-2024-51952
CVE-2024-51951
CVE-2024-51950
CVE-2024-51949
CVE-2024-51948
CVE-2024-51947
CVE-2024-51946
CVE-2024-51945
CVE-2024-51944
CVE-2024-51942
CVE-2024-10904
CVE-2023-25848
CVE-2023-25841
CVE-2023-25840
CVE-2022-38202
CVE-2022-38200
CVE-2022-38199
CVE-2022-38198
CVE-2022-38197
CVE-2022-38196
CVE-2022-38195
CVE-2021-29116
CVE-2021-29114
CVE-2021-29113
CVE-2021-29105
CVE-2021-29104
CVE-2021-29103
CVE-2021-29102
CVE-2021-29107
CVE-2021-29106
CVE-2021-29099
CVE-2021-29095
CVE-2021-29094
CVE-2021-29093
CVE-2020-35712
CVE-2014-9741
CVE-2014-5122
CVE-2014-5121
CVE-2013-7232
CVE-2013-7231
CVE-2013-5222
CVE-2013-5221
CVE-2012-4949
all versions
ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit thi
>= 11.1 and <= 12.0
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated att
<= 11.5
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configuratio
<= 11.5
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configuratio
<= 11.5
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configuratio
<= 11.5
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configuratio
<= 11.5
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauth
<= 11.5
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauth
<= 11.5
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configuratio
<= 11.5
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configuratio
<= 11.5
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configuratio
>= 11.3 and <= 11.5
A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vul
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authen
>= 10.9.1 and <= 11.3
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to
>= 10.9.1 and <= 11.3
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circum
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.9.1 and <= 11.3
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authent
>= 10.8.1 and <= 11.0
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacke
>= 10.8.1 and < 11.1
There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms
>= 10.8.1 and < 11.1
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated
<= 10.9.1
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remot
all versions
A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specif
all versions
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a
<= 10.9.1
There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may al
<= 10.9.1
Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker
<= 10.9.1
Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowin
<= 10.9.1
There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote unauthor
all versions
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature s
<= 10.9.0
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated a
<= 10.9.0
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inje
< 10.9.0
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a re
< 10.9.0
A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthentic
< 10.9.0
A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attacker able to
< 10.9.0
A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthent
all versions
A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthentic
< 10.9.0
A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote attacker ab
<= 10.8.1
A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web re
<= 10.8.1
Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) al
<= 10.8.1
Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows a
<= 10.8.1
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenti
< 10.8
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
<= 10.2.2
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Desktop, ArcGIS for Engine, and ArcGIS for Server 10.2.2 an
all versions
Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject arbitrary we
<= 10.2
SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via u
all versions
Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authen
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1 allow remote authenticated users to inject arbi
all versions
The mobile-upload feature in Esri ArcGIS for Server 10.1 through 10.2 allows remote authenticated users to upload .exe files by le
all versions
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where