ESI Products maintains WebEOC, an emergency operations and crisis-management platform widely deployed across public safety and disaster-response organizations. The vendor's vulnerability footprint remains modest and concentrated in this single product, with disclosures reflecting the complexity inherent to web-based mission-critical applications that aggregate data from multiple sources and stakeholders. Current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Esi Products over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2286HIGH WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource. | Jul 18, 2005 | 10.0 | 25 | NO | NO |
CVE-2005-2284HIGH Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors. | Jul 18, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-4029MEDIUM WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out va | Dec 5, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-2285MEDIUM WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Username | Jul 18, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-4002MEDIUM WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation. | Dec 5, 2005 | 4.0 | 14 | NO | NO |
CVE-2005-2282MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before 6.0.2 allow remote attackers to inject arbitrary web script and HTML via unknown vectors. | Jul 18, 2005 | 4.3 | 14 | NO | NO |
WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource cons | Jul 18, 2005 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Esi Products.
Media articles that mention a CVE ID that affects a product developed by Esi Products — matched by CVE ID, not by vendor name.