Vulnerabilities in Esri

167 results
Vexday analysis

Com 150 CVEs catalogadas, o portfólio da Esri apresenta uma taxa de exploração ativa abaixo da média geral do catálogo KEV, sem nenhuma vulnerabilidade confirmada em uso por agentes de ameaça no momento. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que indica exposição persistente a vetores de injeção de scripts em interfaces web. A CVE mais perigosa ativa no momento, CVE-2021-29097, registra um EPSS de 0,0241, sugerindo probabilidade relativamente baixa de exploração em curto prazo, embora as 7 vulnerabilidades de severidade crítica no total mereçam atenção contínua de equipes de gestão de patch. A ausência de PoCs públicas conhecidas reduz a superfície de risco imediato, mas não elimina a necessidade de monitoramento, especialmente diante das 4 CVEs registradas nos últimos 90 dias.

CVE-2024-38037MEDIUMBUG-000167983 - Unvalidated redirect in Portal for ArcGISEPSS 0.3%CVE-2026-2813MEDIUMUnvalidated Redirect in ArcGIS ServerEPSS 0.3%CVE-2026-33518CRITICALIncorrect privilege assignment in Portal for ArcGISEPSS 0.3%CVE-2025-67707MEDIUMUnvalidated File Upload vulnerability in ArcGIS Server.EPSS 0.3%CVE-2023-25848MEDIUMBUG-000158039 - There is an information disclosure issue in ArcGIS Server.EPSS 0.3%CVE-2022-38199MEDIUMBUG-000144172 - Remote file download issue in ArcGIS ServerEPSS 0.3%CVE-2023-25832HIGHBUG-000148346 There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.EPSS 0.3%CVE-2024-25702MEDIUMBUG-000160599 - Stored XSS in Portal for ArcGIS Web App BuilderEPSS 0.3%CVE-2024-25701MEDIUMBUG-000160765 - Stored XSS in ArcGIS Experience BuilderEPSS 0.3%CVE-2024-38039MEDIUMBUG-000161683 - HTML injection vulnerability in Portal for ArcGIS.EPSS 0.3%CVE-2024-25694MEDIUMBUG-000163019 - Stored XSS in Portal for ArcGISEPSS 0.3%CVE-2026-13020HIGHWeak Password Recovery Mechanism in Portal for ArcGISEPSS 0.3%CVE-2024-51951MEDIUMStored XSS in Server Admin APIEPSS 0.3%CVE-2024-51948MEDIUMStored XSS vulnerability in Rest Services under Job IDEPSS 0.3%CVE-2024-51944MEDIUMStored XSS in Rest Services DirectoryEPSS 0.3%CVE-2024-5888MEDIUMStored XSS in Rest Services API for a Toolbox published as GP ServiceEPSS 0.3%CVE-2024-51945MEDIUMStored XSS issues in Server Admin APIEPSS 0.3%CVE-2024-51952MEDIUMStored XSS issue in ArcGIS ServerEPSS 0.3%CVE-2024-51953MEDIUMStored XSS in ArcGIS Server Rest servicesEPSS 0.3%CVE-2024-51959MEDIUMStored XSS issue in Server Admin APIEPSS 0.3%