Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce… (CVE-2026-69224)CVE-2026-69224
0

An information disclosure vulnerability exists in Esri Portal for ArcGIS versions 12.0 and earlier. Under difficult to reproduce conditions, a remote, unauthenticated attacker may be able to cause sensitive information to be reflected in an HTTP response body. The vulnerability has a moderate severity score and does not require authentication for exploitation. No known exploits are reported in the wild, and no patch or remediation information is currently available.

Join the discussion
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged… (CVE-2026-69233)CVE-2026-69233
0

A stored cross-site scripting (XSS) vulnerability exists in Esri Portal for ArcGIS versions 11.5 and earlier. This flaw allows a remote attacker with administrative privileges to inject malicious scripts that could execute in the browsers of other users. The vulnerability affects versions including 11.1, 11.3, and 11.5. Users are advised to upgrade to the latest long-term support release to mitigate the risk.

Join the discussion
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to… (CVE-2026-69231)CVE-2026-69231
0

A stored cross-site scripting (XSS) vulnerability exists in Esri Portal for ArcGIS versions 11.5 and prior. This vulnerability may allow a remote, privileged attacker to inject malicious JavaScript code that executes in the context of other users' browsers. The issue affects versions including 11.1, 11.3, and 11.5. Users are advised to patch or upgrade to the latest long-term support release to mitigate this risk.

Join the discussion
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated… (CVE-2026-69234)CVE-2026-69234
0

A reflected cross-site scripting (XSS) vulnerability exists in Esri Portal for ArcGIS versions 11.5 and earlier. This flaw allows a remote, unauthenticated attacker to craft a malicious link that, when clicked by a victim, may execute arbitrary JavaScript in the victim's browser. Users of ArcGIS Enterprise versions 11.1, 11.3, and 11.5 are advised to apply patches or upgrade to the latest long-term support release. Additionally, users of ArcGIS Web App Builder developer edition should migrate to ArcGIS Experience Builder as the former is unsupported for this vulnerability.

Join the discussion
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to… (CVE-2026-69235)CVE-2026-69235
0

A stored cross-site scripting (XSS) vulnerability exists in Esri Portal for ArcGIS versions 11.5 and prior. This vulnerability allows a remote, privileged attacker to inject malicious code that may execute in the browser of a victim. Users of ArcGIS Enterprise versions 11.1, 11.3, and 11.5 are specifically advised to apply patches or upgrade to the latest long-term support release to mitigate this issue.

Join the discussion
CVE-2026-69236: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69236
0

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.

Join the discussion
CVE-2026-69232: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69232
0

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Join the discussion
CVE-2026-69231: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69231
0

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Join the discussion
CVE-2026-69230: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69230
0

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Join the discussion
CVE-2026-69229: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69229
0

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Package: pkg:github/esri/Portal-for-ArcGIS
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses