Environmental Systems Research Institute, Inc.

First CVE: Mar 25, 2021Active for: 5 years
154
CVEs Published
More CVEs Published than 75% of tracked CNAs
25.7
Avg CVEs / Year
More Avg CVEs / Year than 74% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Environmental Systems Research Institute, Inc. as a CNA, 98.1% affect products that Environmental Systems Research Institute, Inc. develops as a vendor.

98.1%
Self-reported: 151Third-party: 3

Of all the CVEs published that affect products developed by Environmental Systems Research Institute, Inc., 89.3% are self-published by Environmental Systems Research Institute, Inc. as a CNA.

89.3%
10.7%
Self-published: 151Published by other CNAs: 18

Trends Over Time

The number and severity of CVEs published by Environmental Systems Research Institute, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2021
5 years ago
Most Recent CVE
Jul 7, 2026
17 days ago

Top CVEs

All CVEs published by Environmental Systems Research Institute, Inc. as a CNA, regardless of affected vendor or product.

154 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending cr
Jul 6, 20269.843NONO
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated
Jul 7, 20269.842NONO
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Su
Jul 6, 20269.841NONO
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attack
Jul 7, 20269.840NONO
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to
Apr 21, 20269.833NONO
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that
Apr 21, 20269.832NONO
A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attack
Oct 22, 202510.032NONO
There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentiall
Aug 16, 20229.631NONO
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity a
Dec 7, 20219.830NONO
A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to 
Mar 20, 20259.829NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA154 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local12 (7.8%)
Network142 (92.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low151 (98.1%)
High3 (1.9%)
Unknown0 (0.0%)
User Interaction
None41 (26.6%)
Unknown0 (0.0%)
Required113 (73.4%)
Privileges Required
Low22 (14.3%)
High45 (29.2%)
None87 (56.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (154 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Environmental Systems Research Institute, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Environmental Systems Research Institute, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs