Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Esri — Vulnerabilities & Security Advisories 147

Browse all 147 CVE security advisories affecting Esri. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Esri develops geographic information system (GIS) software, enabling organizations to map, analyze, and visualize spatial data for urban planning, logistics, and environmental management. The company’s extensive portfolio, including ArcGIS Server and Portal for ArcGIS, has historically been associated with 147 recorded Common Vulnerabilities and Exposures (CVEs). These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or insecure default configurations in web-facing components. While no single catastrophic breach has defined the vendor’s public history, the high volume of vulnerabilities highlights the complexity of securing large-scale enterprise GIS deployments. Many issues require administrative access to exploit, yet successful attacks can lead to full system compromise or data exfiltration. Continuous patching and strict network segmentation remain critical for mitigating risks associated with these legacy and modern software components within critical infrastructure environments.

CVE IDTitleCVSSSeverityPublished
CVE-2022-38190 Stored cross-site scripting vulnerability in Esri Portal for ArcGIS Configurable Apps — Portal for ArcGISCWE-79 6.1 Medium2022-08-15
CVE-2022-38186 Esri Portal For ArcGis 跨站脚本漏洞 — Portal for ArcGISCWE-79 6.1 -2022-08-15
CVE-2021-29117 arcreader use-after-free — ArcReaderCWE-416 7.8 -2022-08-12
CVE-2021-29112 Esri ArcReader PMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — ArcReaderCWE-125 5.5 -2022-08-12
CVE-2021-29118 Esri ArcReader PMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — ArcReaderCWE-125 5.5 -2022-08-12
CVE-2021-29116 BUG-000142180 Hosted feature services vulnerable to stored XSS — ArcGIS ServerCWE-79 6.1 -2021-12-07
CVE-2021-29115 An information disclosure vulnerability — ArcGIS ServerCWE-200 5.3 -2021-12-07
CVE-2021-29114 SQL injection vulnerability in ArcGIS Server — ArcGIS ServerCWE-89 9.8 -2021-12-07
CVE-2021-29113 Remote file inclusion vulnerability in ArcGIS Server help documentation — ArcGIS ServerCWE-98 4.7 -2021-12-07
CVE-2021-29110 Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application. — Portal for ArcGISCWE-79 5.4 -2021-10-01
CVE-2021-29109 A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9. — Portal for ArcGISCWE-79 6.1 -2021-10-01
CVE-2021-29108 There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below. — Portal for ArcGISCWE-347 8.8 High2021-10-01
CVE-2021-29104 There is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below. — ArcGIS ServerCWE-79 6.1 -2021-07-11
CVE-2021-29102 There is a Server-Side Request Forgery (SSRF) vulnerability in Esri ArcGIS Server Manager version 10.8.1 and below. — ArcGIS ServerCWE-918 7.5 -2021-07-11
CVE-2021-29103 There is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below. — ArcGIS ServerCWE-79 6.1 -2021-07-11
CVE-2021-29105 There is a stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below. — ArcGIS ServerCWE-79 5.4 -2021-07-11
CVE-2021-29106 There is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below. — ArcGIS ServerCWE-79 6.1 -2021-07-10
CVE-2021-29107 There is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below. — ArcGIS ServerCWE-79 6.1 -2021-07-10
CVE-2021-29099 There is a SQL injection vulnerability in ArcGIS Server — ArcGIS ServerCWE-89 5.3 -2021-06-07
CVE-2021-29101 ArcGIS GeoEvent Server has a Directory Traversal security vulnerability. — ArcGIS GeoEvent ServerCWE-23 7.5 -2021-05-05
CVE-2021-29100 ArcGIS Earth has a File Parsing Directory Traversal Vulnerability — ArcGIS EarthCWE-23 7.8 -2021-05-05
CVE-2021-29098 ArcGIS general raster security update: uninitialized pointer — ArcReaderCWE-824 7.8 -2021-03-25
CVE-2021-29097 ArcGIS general raster security update: buffer overflow — ArcReaderCWE-122 7.8 -2021-03-25
CVE-2021-29095 ArcGIS Server image service and raster analytics security update: uninitialized pointer — ArcGIS ServerCWE-824 6.8 -2021-03-25
CVE-2021-29094 ArcGIS Server image service and raster analytics security update: buffer overflow — ArcGIS ServerCWE-120 6.8 -2021-03-25
CVE-2021-29093 ArcGIS Server image service and raster analytics security update: use-after-free — ArcGIS ServerCWE-416 6.8 -2021-03-25
CVE-2021-29096 ArcGIS general raster security update: use-after-free — ArcReaderCWE-416 7.8 -2021-03-25

This page lists every published CVE security advisory associated with Esri. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.