Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Trimble

First CVE: Mar 7, 2013Active for: 13 yearsTotal CVEs: 41
60.8
VTI Score
TOP TARGET

Trimble's vulnerability footprint spans modeling and design software, infrastructure surveying and positioning systems, and geospatial applications that serve construction, engineering, and GIS workflows. The recurring weakness classes—use-after-free conditions, buffer boundary violations, out-of-bounds reads and writes, and uninitialized-variable bugs—reflect the memory-safety demands of native-compiled design and mapping tools and embedded firmware in GNSS receivers. Products such as SketchUp, CityWorks, and the Infrastructure GNSS Series firmware represent the vendor's exposure across consumer-facing 3D modeling, enterprise municipal infrastructure management, and precision positioning hardware. These weakness patterns are characteristic of large codebases handling complex geometry, spatial data, and real-time positioning logic, where memory-management errors can arise across rendering pipelines and protocol parsers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
2.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Trimble over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2013
13 years ago
Most Recent CVE
May 22, 2026
63 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-0994HIGH
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authen
Feb 6, 20258.882YESNO
CVE-2013-3664HIGH
Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which
Jul 1, 20149.346NONO
CVE-2026-9264CRITICAL
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP fi
May 22, 20269.338NONO
CVE-2013-7388HIGH
Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a craf
Jul 1, 20149.333NONO
CVE-2025-2024HIGH
Trimble SketchUp SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta
Mar 7, 20257.829NONO
CVE-2024-9712HIGH
Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Nov 22, 20247.823NONO
CVE-2024-7509HIGH
Trimble SketchUp SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected
Nov 22, 20247.822NONO
CVE-2023-50196HIGH
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal
May 3, 20247.822NONO
CVE-2023-50195HIGH
Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in
May 3, 20247.822NONO
CVE-2023-50194HIGH
Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in
May 3, 20247.822NONO
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
90%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local36 (87.8%)
Network1 (2.4%)
Unknown4 (9.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (90.2%)
High0 (0.0%)
Unknown4 (9.8%)
User Interaction
None2 (4.9%)
Unknown4 (9.8%)
Required35 (85.4%)
Privileges Required
Low1 (2.4%)
High0 (0.0%)
None36 (87.8%)
Unknown4 (9.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
1 CVE
2.4% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Trimble.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Trimble — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Trimble's Products

View all 5 CNAs →

Top CWEs