Записи Esri
182 опубликованных записей вендора esri.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 33
- С записью об исправлении
- 1,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')95
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-918 Server-Side Request Forgery (SSRF)7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
182 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2007-1770Proof of concept | Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when usiesri · arcsde · CWE-120 | Критическая10,0 | — | 16,8 % | 29 мар. 2007 г. |
44В плане | CVE-2012-1661Proof of concept | ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assiesri · arcmap · CWE-94 | Критическая9,3 | — | 23,8 % | 12 июл. 2012 г. |
40В плане | CVE-2015-2002Эксплойта нет | The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in aesri · arcgisruntime sdk · CWE-118 | Критическая9,8 | — | 2,3 % | 29 мар. 2018 г. |
40В плане | CVE-2025-57870Эксплойта нет | BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.esri · arcgis server · CWE-89 | Критическая10,0 | — | 0,5 % | 22 окт. 2025 г. |
39Наблюдать | CVE-2020-35712Эксплойта нет | Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.esri · arcgis server · CWE-918 | Критическая9,8 | — | 1,7 % | 25 дек. 2020 г. |
39Наблюдать | CVE-2024-25693Эксплойта нет | Portal for ArcGIS has a directory traversal vulnerability.esri · portal for arcgis · CWE-22 | Критическая9,9 | — | 1,3 % | 4 апр. 2024 г. |
39Наблюдать | CVE-2021-29114Эксплойта нет | SQL injection vulnerability in ArcGIS Serveresri · arcgis server · CWE-89 | Критическая9,8 | — | 1,0 % | 7 дек. 2021 г. |
39Наблюдать | CVE-2026-13019Эксплойта нет | Missing Authenticationesri · portal for arcgis · CWE-640 | Критическая9,8 | — | 0,8 % | 7 июл. 2026 г. |
39Наблюдать | CVE-2026-9182Эксплойта нет | Unvalidated File Upload vulnerability in ArcGIS Server.esri · arcgis server · CWE-434 | Критическая9,8 | — | 0,6 % | 6 июл. 2026 г. |
39Наблюдать | CVE-2025-2538Эксплойта нет | A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allesri · portal for arcgis · CWE-798 | Критическая9,8 | — | 0,6 % | 20 мар. 2025 г. |
39Наблюдать | CVE-2026-33519Эксплойта нет | Incorrect privilege assignment in Portal for ArcGISesri · portal for arcgis · CWE-266 | Критическая9,8 | — | 0,5 % | 21 апр. 2026 г. |
39Наблюдать | CVE-2026-13020Эксплойта нет | Weak Password Recovery Mechanism in Portal for ArcGISesri · portal for arcgis · CWE-640 | Критическая9,8 | — | 0,5 % | 7 июл. 2026 г. |
38Наблюдать | CVE-2022-38193Эксплойта нет | Code injection issue in Portal for ArcGIS (10.7.1 and 10.8.1)esri · portal for arcgis · CWE-95 | Критическая9,6 | — | 0,9 % | 16 авг. 2022 г. |
36Наблюдать | CVE-2021-29102Эксплойта нет | There is a Server-Side Request Forgery (SSRF) vulnerability in Esri ArcGIS Server Manager version 10.8.1 and below.esri · arcgis server · CWE-918 | Критическая9,1 | — | 1,6 % | 10 июл. 2021 г. |
36Наблюдать | CVE-2025-4967Эксплойта нет | Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGISesri · portal for arcgis · CWE-918 | Критическая9,1 | — | 0,6 % | 29 мая 2025 г. |
35Наблюдать | CVE-2021-29108Эксплойта нет | There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below.esri · portal for arcgis · CWE-347 | Высокая8,8 | — | 0,8 % | 1 окт. 2021 г. |
35Наблюдать | CVE-2023-25832Эксплойта нет | BUG-000148346 There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.esri · portal for arcgis · CWE-352 | Высокая8,8 | — | 0,3 % | 9 мая 2023 г. |
34Наблюдать | CVE-2024-25699Эксплойта нет | Portal for ArcGIS has an invalid authentication vulnerabilityesri · portal for arcgis · CWE-287 | Высокая8,5 | — | 0,7 % | 4 апр. 2024 г. |
34Наблюдать | CVE-2024-51962Эксплойта нет | SQL injection vulnerability in ArcGIS Serveresri · arcgis server · CWE-89 | Высокая8,7 | — | 0,5 % | 3 мар. 2025 г. |
34Наблюдать | CVE-2024-51954Эксплойта нет | Unauthorized access to secure services in ArcGIS Serverlinux · linux kernel · CWE-284 | Высокая8,5 | — | 0,3 % | 3 мар. 2025 г. |
33Наблюдать | CVE-2023-25837Эксплойта нет | BUG-000133088 - ArcGIS Enterprise site builder is subject to stored XSS.esri · portal for arcgis · CWE-79 | Высокая8,4 | — | 1,0 % | 21 июл. 2023 г. |
33Наблюдать | CVE-2023-25835Эксплойта нет | BUG-000153659 ArcGIS Enterprise Sites has a stored XSS vulnerabilityesri · portal for arcgis · CWE-79 | Высокая8,4 | — | 0,9 % | 20 июл. 2023 г. |
32Наблюдать | CVE-2021-29097Эксплойта нет | ArcGIS general raster security update: buffer overflowesri · arcgis engine · CWE-121 | Высокая7,8 | — | 2,4 % | 25 мар. 2021 г. |
32Наблюдать | CVE-2021-29098Эксплойта нет | ArcGIS general raster security update: uninitialized pointeresri · arcgis engine · CWE-824 | Высокая7,8 | — | 2,0 % | 25 мар. 2021 г. |
32Наблюдать | CVE-2022-38196Эксплойта нет | BUG-000150537 - ArcGIS Server has a local file inclusion (LFI) vulnerabilityesri · arcgis server · CWE-22 | Высокая8,1 | — | 1,1 % | 25 окт. 2022 г. |
- CVE-2007-177045В плане
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when usi
КритическаяCVSS 10,0Proof of conceptEPSS 17 %esri · arcsde29 мар. 2007 г.
- CVE-2012-166144В плане
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assi
КритическаяCVSS 9,3Proof of conceptEPSS 24 %esri · arcmap12 июл. 2012 г.
- CVE-2015-200240В плане
The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %esri · arcgisruntime sdk29 мар. 2018 г.
- CVE-2025-5787040В плане
BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %esri · arcgis server22 окт. 2025 г.
- CVE-2020-3571239Наблюдать
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %esri · arcgis server25 дек. 2020 г.
- CVE-2024-2569339Наблюдать
Portal for ArcGIS has a directory traversal vulnerability.
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %esri · portal for arcgis4 апр. 2024 г.
- CVE-2021-2911439Наблюдать
SQL injection vulnerability in ArcGIS Server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %esri · arcgis server7 дек. 2021 г.
- CVE-2026-1301939Наблюдать
Missing Authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %esri · portal for arcgis7 июл. 2026 г.
- CVE-2026-918239Наблюдать
Unvalidated File Upload vulnerability in ArcGIS Server.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %esri · arcgis server6 июл. 2026 г.
- CVE-2025-253839Наблюдать
A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may all
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %esri · portal for arcgis20 мар. 2025 г.
- CVE-2026-3351939Наблюдать
Incorrect privilege assignment in Portal for ArcGIS
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %esri · portal for arcgis21 апр. 2026 г.
- CVE-2026-1302039Наблюдать
Weak Password Recovery Mechanism in Portal for ArcGIS
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %esri · portal for arcgis7 июл. 2026 г.
- CVE-2022-3819338Наблюдать
Code injection issue in Portal for ArcGIS (10.7.1 and 10.8.1)
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %esri · portal for arcgis16 авг. 2022 г.
- CVE-2021-2910236Наблюдать
There is a Server-Side Request Forgery (SSRF) vulnerability in Esri ArcGIS Server Manager version 10.8.1 and below.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %esri · arcgis server10 июл. 2021 г.
- CVE-2025-496736Наблюдать
Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %esri · portal for arcgis29 мая 2025 г.
- CVE-2021-2910835Наблюдать
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %esri · portal for arcgis1 окт. 2021 г.
- CVE-2023-2583235Наблюдать
BUG-000148346 There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %esri · portal for arcgis9 мая 2023 г.
- CVE-2024-2569934Наблюдать
Portal for ArcGIS has an invalid authentication vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %esri · portal for arcgis4 апр. 2024 г.
- CVE-2024-5196234Наблюдать
SQL injection vulnerability in ArcGIS Server
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %esri · arcgis server3 мар. 2025 г.
- CVE-2024-5195434Наблюдать
Unauthorized access to secure services in ArcGIS Server
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %linux · linux kernel3 мар. 2025 г.
- CVE-2023-2583733Наблюдать
BUG-000133088 - ArcGIS Enterprise site builder is subject to stored XSS.
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %esri · portal for arcgis21 июл. 2023 г.
- CVE-2023-2583533Наблюдать
BUG-000153659 ArcGIS Enterprise Sites has a stored XSS vulnerability
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %esri · portal for arcgis20 июл. 2023 г.
- CVE-2021-2909732Наблюдать
ArcGIS general raster security update: buffer overflow
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %esri · arcgis engine25 мар. 2021 г.
- CVE-2021-2909832Наблюдать
ArcGIS general raster security update: uninitialized pointer
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %esri · arcgis engine25 мар. 2021 г.
- CVE-2022-3819632Наблюдать
BUG-000150537 - ArcGIS Server has a local file inclusion (LFI) vulnerability
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %esri · arcgis server25 окт. 2022 г.