esri
168 tracked vulnerabilities.
CVE-2021-29118
MEDIUM
Esri ArcReader < 10.8.1 - Unauthenticated Out-of-bounds Read via Crafted File
Aug 12, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-29117
HIGH
Esri ArcReader < 10.8.1 - Use-After-Free via Crafted File Parsing
Aug 12, 2022
CVSS 7.8
EPSS 0.00
CVE-2021-29112
MEDIUM
Esri ArcReader < 10.8.1 - Unauthenticated Out-of-bounds Read via Crafted File
Aug 12, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-29116
MEDIUM
Esri ArcGIS Server 10.8.1 and 10.9 - Unauthenticated Stored Cross-Site Scripting via Feature Service Queries
Dec 07, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-29115
MEDIUM
Esri ArcGIS Enterprise < 10.9 - Information Disclosure via ArcGIS Service Directory
Dec 07, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-29114
CRITICAL
Esri ArcGIS Server < 10.9.0 - Unauthenticated SQL Injection via Feature Service Queries
Dec 07, 2021
CVSS 9.8
EPSS 0.00
CVE-2021-29113
MEDIUM
ArcGIS Server < 10.9.0 - Unauthenticated Remote File Inclusion in Help Documentation
Dec 07, 2021
CVSS 4.7
EPSS 0.00
CVE-2021-29110
MEDIUM
Esri Portal for ArcGIS < 10.9 - Unauthenticated Stored Cross-Site Scripting in Home Application
Oct 01, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-29109
MEDIUM
Esri Portal for ArcGIS < 10.9 - Reflected Cross-Site Scripting
Oct 01, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-29108
HIGH
Esri Portal for ArcGIS < 10.9 - Authenticated Privilege Escalation via SAML Assertion XML Signature Wrapping
Oct 01, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-29105
MEDIUM
Esri ArcGIS Server < 10.9.0 - Authenticated Stored Cross-Site Scripting
Jul 11, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-29104
MEDIUM
ArcGIS Server < 10.9.0 - Unauthenticated Stored Cross-Site Scripting
Jul 11, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-29103
MEDIUM
ArcGIS Server < 10.9.0 - Reflected Cross-Site Scripting
Jul 11, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-29102
CRITICAL
ArcGIS Server < 10.9.0 - Unauthenticated Server-Side Request Forgery
Jul 11, 2021
CVSS 9.1
EPSS 0.01
CVE-2021-29107
MEDIUM
ArcGIS Server Manager <= 10.8.1 - Unauthenticated Stored Cross-Site Scripting
Jul 10, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-29106
MEDIUM
Esri ArcGIS Server < 10.9.0 - Reflected Cross-Site Scripting
Jul 10, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-29099
MEDIUM
ArcGIS Server < 10.8.1 - SQL Injection
Jun 07, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-29101
HIGH
ArcGIS GeoEvent Server <= 10.8.1 - Unauthenticated Path Traversal
May 05, 2021
CVSS 7.5
EPSS 0.02
CVE-2021-29100
HIGH
Esri ArcGIS Earth < 1.11.0 - Path Traversal and Arbitrary File Write via Crafted File Upload
May 05, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-3012
MEDIUM
ESRI ArcGIS Enterprise < 10.9 - Authenticated Stored Cross-Site Scripting via Document Link URL Parameter
Apr 08, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-29098
HIGH
Esri ArcGIS Engine/Pro/Map/Reader < 10.8.1/2.7 - RCE via Crafted File
Mar 25, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-29097
HIGH
Esri ArcGIS Engine/Pro/Map/Reader < 10.8.1/2.7 - Unauthenticated Buffer Overflow via Crafted File
Mar 25, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-29095
MEDIUM
Esri ArcGIS Server < 10.8.1 - Authenticated Arbitrary Code Execution via Crafted File Parsing
Mar 25, 2021
CVSS 6.8
EPSS 0.00
CVE-2021-29094
MEDIUM
Esri ArcGIS Server < 10.8.1 - Authenticated Remote Code Execution via Crafted File Parsing
Mar 25, 2021
CVSS 6.8
EPSS 0.01
CVE-2021-29093
MEDIUM
Esri ArcGIS Server < 10.8.1 - Authenticated Use-After-Free via Crafted File Parsing
Mar 25, 2021
CVSS 6.8
EPSS 0.00
Products
portal_for_arcgis 73
arcgis_server 67
arcgis_pro 6
arcreader 6
arcgis_enterprise 5
arcmap 4
arcgis_engine 3
ArcGIS Server 2
Portal for ArcGIS 2
arcgis_allsource 2
arcgis_insights 2
arcinfo_workstation 2
arcsde 2
ArcGIS Enterprise Builder 1
ArcGIS Monitor 1
ArcGIS Web AppBuilder {Developer Edition) 1
arcgis_earth 1
arcgis_for_desktop 1
arcgis_for_engine 1
arcgis_geoevent_server 1
arcgis_quickcapture 1
arcgisruntime_sdk 1
arcpad 1
Quick Filters