Latest CVE Feed
-
5.3
MEDIUMCVE-2025-1881
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Video Footage/Live Video Stream. The manipulation leads to improper access co... Read more
- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-1880
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. It is possible to... Read more
- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Authentication
-
6.8
MEDIUMCVE-2025-1879
A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the ph... Read more
- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2024-5888
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.9
MEDIUMCVE-2024-51966
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. ... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Path Traversal
-
4.8
MEDIUMCVE-2024-51963
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in th... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2024-51962
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges. There is a high impact to integrity and... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-51961
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote se... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Path Traversal
-
4.8
MEDIUMCVE-2024-51960
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-51959
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.9
MEDIUMCVE-2024-51958
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. ... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Path Traversal
-
4.8
MEDIUMCVE-2024-51957
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-51956
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2024-51954
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standa... Read more
- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2024-51953
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-51952
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-51951
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-51950
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-51949
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-51948
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting