4.8

CVSS3.1

CVE-2024-51963 - Stored XSS in ArcGIS Server Manager

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required…

📅 Published: March 3, 2025, 7:59 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

8.7

CVSS3.1

CVE-2024-51962 - SQL injection vulnerability in ArcGIS Server

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced applica…

📅 Published: March 3, 2025, 7:58 p.m. 🔄 Last Modified: Feb. 13, 2026, 7:41 p.m.

7.5

CVSS3.1

CVE-2024-51961 - Local file inclusion (LFI) vulnerability in ArcGIS Server

There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files access…

📅 Published: March 3, 2025, 7:58 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.8

CVSS3.1

CVE-2024-51960 - Stored XSS in ArcGIS Server Administrator Directory

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:58 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.8

CVSS3.1

CVE-2024-51959 - Stored XSS issue in Server Admin API

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:58 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.9

CVSS3.1

CVE-2024-51958 - Directory traversal vulnerability in the admin api for service thumbnails

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory.  There is no impact to integrity or availabi…

📅 Published: March 3, 2025, 7:57 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.8

CVSS3.1

CVE-2024-51957 - Stored XSS vulnerability in ArcGIS Rest Services Directory

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:57 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.8

CVSS3.1

CVE-2024-51956 - Stored XSS vulnerability in ArcGIS Server Administrator Directory

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:53 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

8.5

CVSS3.1

CVE-2024-51954 - Unauthorized access to secure services in ArcGIS Server

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS Server instance. Successful…

📅 Published: March 3, 2025, 7:53 p.m. 🔄 Last Modified: Feb. 13, 2026, 7:41 p.m.

4.8

CVSS3.1

CVE-2024-51953 - Stored XSS in ArcGIS Server Rest services

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:53 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.
Total resulsts: 346549
Page 6207 of 34,655
« previous page » next page
Filters