Known Vulnerabilities for products from Esri
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Esri".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69238 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69237 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69236 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69235 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69234 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69233 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69232 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69231 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69230 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-69229 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-33519 json | An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernete... | Not Provided | 2026-04-21 | 2026-05-18 |
| CVE-2026-33518 json | An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly... | Not Provided | 2026-04-21 | 2026-05-18 |
| CVE-2026-13020 json | A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windo... | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-13019 json | Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical ... | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-9182 json | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue b... | Not Provided | 2026-07-06 | 2026-07-08 |
| CVE-2026-9181 json | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthen... | Not Provided | 2026-07-06 | 2026-07-08 |
| CVE-2026-2813 json | ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploi... | Not Provided | 2026-05-20 | 2026-07-23 |
| CVE-2026-2812 json | ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticate... | Not Provided | 2026-05-20 | 2026-07-23 |
| CVE-2023-25848 json | ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthoriz... | 5.3 - MEDIUM | 2023-08-25 | 2023-08-31 |
| CVE-2023-25841 json | There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 10.8.1 – 11.0 on Windows and Linux pla... | 6.1 - MEDIUM | 2023-07-21 | 2023-08-02 |
Known software with vulnerabilities from Esri
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Esri | Arcgis | - |
| Application | Esri | Arcgis 3d Analyst | - |
| Application | Esri | Arcgis Arcsde | - |
| Application | Esri | Arcgis Enterprise | 10.6.1 |
| Application | Esri | Arcgis For Server | 10.1.1 |
| Application | Esri | Arcgis Runtime Toolkit | 10.2.0 |
| Application | Esri | Arcgis Server | 10.2.2 |
| Application | Esri | Arcgis Spatial Analyst | - |
| Application | Esri | Arcinfo Workstation | - |
| Application | Esri | Arcmap | 9.0 |
| Application | Esri | Arcpad | - |
| Application | Esri | Arcsde | - |
| Application | Esri | Arcview | - |