Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-69236: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69236
0

CVE-2026-69236 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 12.1 and prior. It allows a remote, privileged attacker to inject malicious JavaScript code that could execute in the browsers of users interacting with the affected portal. The vulnerability affects versions including 11.1, 11.3, 11.5, 12.0, and 12.1. Users are advised to upgrade to the latest long-term support release and apply available patches.

Join the discussion
CVE-2026-69232: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69232
0

CVE-2026-69232 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.5 and earlier. It allows a remote, privileged attacker to inject malicious JavaScript code that could execute in the browsers of users interacting with the affected portal. The vulnerability affects versions 11.1 through 11.5 inclusive. The CVSS score is 5.5, indicating medium severity. Users are advised to patch or upgrade to the latest long-term support release.

Join the discussion
CVE-2026-69231: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69231
0

CVE-2026-69231 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.5 and earlier. It allows a remote, privileged attacker to inject malicious JavaScript code that could execute in the browsers of users interacting with the affected portal. The vulnerability affects versions 11.1 through 11.5. The CVSS score is 5.5, indicating a medium severity level. Users of ArcGIS Enterprise 11.1, 11.3, and 11.5 are advised to patch or upgrade to the latest long-term support release.

Join the discussion
CVE-2026-69230: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69230
0

CVE-2026-69230 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.5 and earlier. It allows a remote attacker with administrative privileges to inject malicious code that could execute in the browsers of other users. The vulnerability affects versions 11.1, 11.3, and 11.5 specifically. Users are advised to upgrade to the latest long-term support release to mitigate this issue.

Join the discussion
CVE-2026-69229: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69229
0

CVE-2026-69229 is a medium severity HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior. It allows a remote, authenticated attacker to inject arbitrary HTML into the Portal for ArcGIS Home application. The vulnerability affects versions including 11.1, 11.3, 11.5, and 12.0. Users are advised to upgrade to the latest long-term support release to mitigate this issue.

Join the discussion
CVE-2026-69228: CWE-306 Missing Authentication for Critical Function in Esri Portal for ArcGISCVE-2026-69228
0

CVE-2026-69228 is a medium severity vulnerability in Esri Portal for ArcGIS versions 11.1 through 12.0. It involves missing authentication for a critical function, allowing remote unauthenticated attackers to access a specific resource that should be restricted to authenticated users. The vulnerability does not affect user content but exposes other sensitive resources. No official patch or remediation level has been confirmed yet. Users are advised to upgrade to the latest long-term support release when available.

Join the discussion
CVE-2026-69235: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Esri Portal for ArcGISCVE-2026-69235
0

CVE-2026-69235 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.5 and prior. It allows a remote, privileged attacker to inject malicious code that could execute in a victim's browser. The vulnerability affects versions including 11.1, 11.3, and 11.5. Users are advised to upgrade to the latest long-term support release to mitigate this issue.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/esri/portal-for-arcgis
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses