Trimble's vulnerability footprint spans modeling and design software, infrastructure surveying and positioning systems, and geospatial applications that serve construction, engineering, and GIS workflows. The recurring weakness classes—use-after-free conditions, buffer boundary violations, out-of-bounds reads and writes, and uninitialized-variable bugs—reflect the memory-safety demands of native-compiled design and mapping tools and embedded firmware in GNSS receivers. Products such as SketchUp, CityWorks, and the Infrastructure GNSS Series firmware represent the vendor's exposure across consumer-facing 3D modeling, enterprise municipal infrastructure management, and precision positioning hardware. These weakness patterns are characteristic of large codebases handling complex geometry, spatial data, and real-time positioning logic, where memory-management errors can arise across rendering pipelines and protocol parsers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trimble over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-0994HIGH Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authen | Feb 6, 2025 | 8.8 | 82 | YES | NO |
CVE-2013-3664HIGH Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which | Jul 1, 2014 | 9.3 | 46 | NO | NO |
CVE-2026-9264CRITICAL A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP fi | May 22, 2026 | 9.3 | 38 | NO | NO |
CVE-2013-7388HIGH Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a craf | Jul 1, 2014 | 9.3 | 33 | NO | NO |
CVE-2025-2024HIGH Trimble SketchUp SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta | Mar 7, 2025 | 7.8 | 29 | NO | NO |
CVE-2024-9712HIGH Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Nov 22, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-7509HIGH Trimble SketchUp SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected | Nov 22, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-50196HIGH Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal | May 3, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-50195HIGH Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in | May 3, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-50194HIGH Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in | May 3, 2024 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trimble.
Media articles that mention a CVE ID that affects a product developed by Trimble — matched by CVE ID, not by vendor name.