Vulnerabilidades en Esri

167 resultados
Análisis Vexday

Com 150 CVEs catalogadas, o portfólio da Esri apresenta uma taxa de exploração ativa abaixo da média geral do catálogo KEV, sem nenhuma vulnerabilidade confirmada em uso por agentes de ameaça no momento. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que indica exposição persistente a vetores de injeção de scripts em interfaces web. A CVE mais perigosa ativa no momento, CVE-2021-29097, registra um EPSS de 0,0241, sugerindo probabilidade relativamente baixa de exploração em curto prazo, embora as 7 vulnerabilidades de severidade crítica no total mereçam atenção contínua de equipes de gestão de patch. A ausência de PoCs públicas conhecidas reduz a superfície de risco imediato, mas não elimina a necessidade de monitoramento, especialmente diante das 4 CVEs registradas nos últimos 90 dias.

CVE-2024-51954HIGHUnauthorized access to secure services in ArcGIS ServerEPSS 0.3%CVE-2026-2813MEDIUMUnvalidated Redirect in ArcGIS ServerEPSS 0.3%CVE-2025-67707MEDIUMUnvalidated File Upload vulnerability in ArcGIS Server.EPSS 0.3%CVE-2026-33518CRITICALIncorrect privilege assignment in Portal for ArcGISEPSS 0.3%CVE-2024-25694MEDIUMBUG-000163019 - Stored XSS in Portal for ArcGISEPSS 0.3%CVE-2024-38039MEDIUMBUG-000161683 - HTML injection vulnerability in Portal for ArcGIS.EPSS 0.3%CVE-2024-25701MEDIUMBUG-000160765 - Stored XSS in ArcGIS Experience BuilderEPSS 0.3%CVE-2024-25702MEDIUMBUG-000160599 - Stored XSS in Portal for ArcGIS Web App BuilderEPSS 0.3%CVE-2023-25848MEDIUMBUG-000158039 - There is an information disclosure issue in ArcGIS Server.EPSS 0.3%CVE-2022-38199MEDIUMBUG-000144172 - Remote file download issue in ArcGIS ServerEPSS 0.3%CVE-2023-25832HIGHBUG-000148346 There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.EPSS 0.3%CVE-2026-13020HIGHWeak Password Recovery Mechanism in Portal for ArcGISEPSS 0.3%CVE-2024-51942MEDIUMStored XSS vulnerability in Rest Admin API under Hosted Feature Services pageEPSS 0.3%CVE-2024-51948MEDIUMStored XSS vulnerability in Rest Services under Job IDEPSS 0.3%CVE-2024-51956MEDIUMStored XSS vulnerability in ArcGIS Server Administrator DirectoryEPSS 0.3%CVE-2024-51960MEDIUMStored XSS in ArcGIS Server Administrator DirectoryEPSS 0.3%CVE-2024-51957MEDIUMStored XSS vulnerability in ArcGIS Rest Services DirectoryEPSS 0.3%CVE-2024-51953MEDIUMStored XSS in ArcGIS Server Rest servicesEPSS 0.3%CVE-2024-51946MEDIUMStored XSS in Rest Services Directory under Identify operationEPSS 0.3%CVE-2024-10904MEDIUMStored XSS in Server Admin APIEPSS 0.3%