Known Vulnerabilities for Arcgis by Esri
Listed below are 10 of the newest known vulnerabilities associated with "Arcgis" by "Esri".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33519 json | An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernete... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-33518 json | An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2023-25841 json | There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 10.8.1 – 11.0 on Windows and Linux pla... | 6.1 - MEDIUM | 2023-07-21 | 2023-08-02 |
| CVE-2023-25840 json | There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 10.8.1 – 11.1 that may allow a remote, authent... | 3.4 - LOW | 2023-07-21 | 2023-08-01 |
| CVE-2021-29098 json | Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGI... | 7.8 - HIGH | 2021-03-25 | 2023-11-07 |
| CVE-2021-29097 json | Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engi... | 7.8 - HIGH | 2021-03-25 | 2023-11-07 |
| CVE-2021-29095 json | Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlie... | 6.8 - MEDIUM | 2021-03-25 | 2023-11-07 |
| CVE-2021-29094 json | Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) all... | 6.8 - MEDIUM | 2021-03-25 | 2023-11-07 |
| CVE-2021-29093 json | A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an aut... | 6.8 - MEDIUM | 2021-03-25 | 2023-11-07 |
| CVE-2013-7232 json | SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands ... | 7.5 - HIGH | 2013-12-30 | 2013-12-31 |