Arcgis Server

Vendor:

First CVE: Nov 14, 2012 · Active for 13 years

70
Total CVEs
More Total CVEs than 99% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 23% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Arcgis Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2012
13 years ago
Most Recent CVE
Jul 6, 2026
22 days ago

CVE Severity & Scoring

Arcgis Server70 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network62 (88.6%)
Unknown8 (11.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (88.6%)
High0 (0.0%)
Unknown8 (11.4%)
User Interaction
None19 (27.1%)
Unknown8 (11.4%)
Required43 (61.4%)
Privileges Required
Low4 (5.7%)
High24 (34.3%)
None34 (48.6%)
Unknown8 (11.4%)

Top CVEs

Signals from CVEs in this product scope (70 CVEs).

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending cr
Jul 6, 20269.843NONO
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Su
Jul 6, 20269.841NONO
A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attack
Oct 22, 202510.032NONO
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity a
Dec 7, 20219.830NONO
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.
Nov 14, 20126.530NOYES
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Dec 26, 20209.829NONO
A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary
Jul 11, 20219.128NONO
Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authenticated attacker to overwrite in
Oct 25, 20228.126NONO
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenti
Mar 3, 20258.725NONO
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file syst
Dec 28, 20227.525NONO

Exploit Exposure

Signals from CVEs in this product scope (70 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (70 CVEs).

Media Mentions

Signals from CVEs in this product scope (70 CVEs).

Top CNAs Publishing CVEs For Arcgis Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
11.514.70.3%00
10.9.116.10.3%00
10.9.016.10.8%00
10.8.136.10.5%00
10.7.126.10.3%00
10.6.116.10.9%00
10.223.51.1%00
10.1.125.02.3%00
10.144.31.9%01