Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Environmental Systems Research Institute, Inc.

First CVE: May 3, 2005Active for: 21 yearsTotal CVEs: 169
25.0
VTI Score
Low

Environmental Systems Research Institute (Esri) maintains a portfolio of geographic information systems and mapping applications that includes Portal for ArcGIS, ArcGIS Server, ArcGIS Pro, and ArcGIS Enterprise, products deeply embedded in critical infrastructure, government, and enterprise spatial-data workflows. The vendor's vulnerability profile clusters around web-facing input-handling and server-side processing weaknesses, with recurring issues in cross-site scripting, open redirects, path traversal, SQL injection, and server-side request forgery that reflect the complexity of web-based GIS services and their integration with external data sources. A meaningful share of the vendor's disclosures reach serious severity, though the modest exploit-availability tendency suggests that weaponization does not immediately follow disclosure. Because these products often serve as authoritative spatial-data sources and sit at architectural boundaries in mission-critical deployments, defenders should prioritize patching for this vendor and treat its advisories as applicable across both internet-facing services and trusted internal networks. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
169
Total CVEs
More Total CVEs than 100% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Environmental Systems Research Institute, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2005
21 years ago
Most Recent CVE
Jul 7, 2026
17 days ago

Self-Reporting Analysis

Of all the CVEs published by Environmental Systems Research Institute, Inc. as a CNA, 98.1% affect products that Environmental Systems Research Institute, Inc. develops as a vendor.

98.1%
Self-reported: 151 (98.1%)
Third-party: 3 (1.9%)

Of all the CVEs published that affect products developed by Environmental Systems Research Institute, Inc., 89.3% are self-published by Environmental Systems Research Institute, Inc. as a CNA.

89.3%
10.7%
Self-published: 151 (89.3%)
Other CNAs: 18 (10.7%)

Products(18 total)

Top CVEs

Signals from CVEs in this vendor scope (169 CVEs).

169 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1661HIGH
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitra
Jul 12, 20129.353NOYES
CVE-2007-1770HIGH
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, a
Mar 30, 200710.045NOYES
CVE-2026-9181CRITICAL
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending cr
Jul 6, 20269.843NONO
CVE-2026-13019CRITICAL
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated
Jul 7, 20269.842NONO
CVE-2026-9182CRITICAL
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Su
Jul 6, 20269.841NONO
CVE-2026-13020CRITICAL
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attack
Jul 7, 20269.840NONO
CVE-2026-33519CRITICAL
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to
Apr 21, 20269.833NONO
CVE-2026-33518CRITICAL
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that
Apr 21, 20269.832NONO
CVE-2025-57870CRITICAL
A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attack
Oct 22, 202510.032NONO
CVE-2022-38193CRITICAL
There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentiall
Aug 16, 20229.631NONO
View all 169 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products169 CVEs
69%
20%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (7.1%)
Network143 (84.6%)
Unknown14 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low152 (89.9%)
High3 (1.8%)
Unknown14 (8.3%)
User Interaction
None42 (24.9%)
Unknown14 (8.3%)
Required113 (66.9%)
Privileges Required
Low23 (13.6%)
High44 (26.0%)
None88 (52.1%)
Unknown14 (8.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (169 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Environmental Systems Research Institute, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Environmental Systems Research Institute, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Environmental Systems Research Institute, Inc.'s Products

View all 4 CNAs →

Top CWEs