Environmental Systems Research Institute, Inc.
Self-Reporting Analysis
Of all the CVEs published by Environmental Systems Research Institute, Inc. as a CNA, 98.1% affect products that Environmental Systems Research Institute, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Environmental Systems Research Institute, Inc., 89.3% are self-published by Environmental Systems Research Institute, Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Environmental Systems Research Institute, Inc. over time
Top CVEs
All CVEs published by Environmental Systems Research Institute, Inc. as a CNA, regardless of affected vendor or product.
154 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9181CRITICAL Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending cr | Jul 6, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-13019CRITICAL Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated | Jul 7, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-9182CRITICAL Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Su | Jul 6, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-13020CRITICAL A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attack | Jul 7, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-33519CRITICAL An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to | Apr 21, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-33518CRITICAL An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that | Apr 21, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-57870CRITICAL A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attack | Oct 22, 2025 | 10.0 | 32 | NO | NO |
CVE-2022-38193CRITICAL There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentiall | Aug 16, 2022 | 9.6 | 31 | NO | NO |
CVE-2021-29114CRITICAL A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity a | Dec 7, 2021 | 9.8 | 30 | NO | NO |
CVE-2025-2538CRITICAL A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to | Mar 20, 2025 | 9.8 | 29 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (154 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Environmental Systems Research Institute, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Environmental Systems Research Institute, Inc. as a CNA — matched by CVE ID, not by organization name.