Arcgis Server
Vendor:
First CVE: Nov 14, 2012 · Active for 13 years
70
Total CVEs
More Total CVEs than 99% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 23% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Arcgis Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2012
13 years ago
Most Recent CVE
Jul 6, 2026
22 days ago
CVE Severity & Scoring
Arcgis Server70 CVEs
77%
9%
9%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network62 (88.6%)
Unknown8 (11.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (88.6%)
High0 (0.0%)
Unknown8 (11.4%)
User Interaction
None19 (27.1%)
Unknown8 (11.4%)
Required43 (61.4%)
Privileges Required
Low4 (5.7%)
High24 (34.3%)
None34 (48.6%)
Unknown8 (11.4%)
Top CVEs
Signals from CVEs in this product scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9181CRITICAL Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending cr | Jul 6, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-9182CRITICAL Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Su | Jul 6, 2026 | 9.8 | 41 | NO | NO |
CVE-2025-57870CRITICAL A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attack | Oct 22, 2025 | 10.0 | 32 | NO | NO |
CVE-2021-29114CRITICAL A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity a | Dec 7, 2021 | 9.8 | 30 | NO | NO |
CVE-2012-4949MEDIUM SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service. | Nov 14, 2012 | 6.5 | 30 | NO | YES |
CVE-2020-35712CRITICAL Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations. | Dec 26, 2020 | 9.8 | 29 | NO | NO |
CVE-2021-29102CRITICAL A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary | Jul 11, 2021 | 9.1 | 28 | NO | NO |
CVE-2022-38196HIGH Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authenticated attacker to overwrite in | Oct 25, 2022 | 8.1 | 26 | NO | NO |
CVE-2024-51962HIGH A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenti | Mar 3, 2025 | 8.7 | 25 | NO | NO |
CVE-2022-38202HIGH There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file syst | Dec 28, 2022 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (70 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (70 CVEs).
Media Mentions
Signals from CVEs in this product scope (70 CVEs).
Top CNAs Publishing CVEs For Arcgis Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.5 | 1 | 4.7 | 0.3% | 0 | 0 |
| 10.9.1 | 1 | 6.1 | 0.3% | 0 | 0 |
| 10.9.0 | 1 | 6.1 | 0.8% | 0 | 0 |
| 10.8.1 | 3 | 6.1 | 0.5% | 0 | 0 |
| 10.7.1 | 2 | 6.1 | 0.3% | 0 | 0 |
| 10.6.1 | 1 | 6.1 | 0.9% | 0 | 0 |
| 10.2 | 2 | 3.5 | 1.1% | 0 | 0 |
| 10.1.1 | 2 | 5.0 | 2.3% | 0 | 0 |
| 10.1 | 4 | 4.3 | 1.9% | 0 | 1 |