Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Project Center CRITICAL 9.8
CVE-2025-35062

Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit add…

Fix: 2023.1+
Fix from $2,300 2025-10-09
Project Center MEDIUM 6.1
CVE-2025-35059

Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

Fix: 2024.1+
Fix from $1,600 2025-10-09
Project Center MEDIUM 5.9
CVE-2025-35061

Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB co…

Fix: 2023.2+
Fix from $1,600 2025-10-09
Project Center MEDIUM 5.4
CVE-2025-35060

Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain …

Fix: 2024.1+
Fix from $1,600 2025-10-09
Project Center HIGH 8.8
CVE-2025-35055

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writab…

Fix: 2023.1+
Fix from $1,950 2025-10-09
Project Center MEDIUM 6.4
CVE-2025-35053

Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an aut…

Fix: after 2024.3
Fix from $1,600 2025-10-09
Project Center MEDIUM 5.9
CVE-2025-35058

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection t…

Fix: 2023.2+
Fix from $1,600 2025-10-09
Project Center MEDIUM 5.3
CVE-2025-35052

Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download…

Fix: after 2024.3
Fix from $1,600 2025-10-09
Project Center MEDIUM 5.3
CVE-2025-35054

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credential…

Fix: after 2024.3
Fix from $1,600 2025-10-09
Project Center MEDIUM 5.3
CVE-2025-35057

Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection t…

Fix: 2024.3+
Fix from $1,600 2025-10-09
Project Center MEDIUM 5.0
CVE-2025-35056

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the spec…

Fix: 2024.1+
Fix from $1,600 2025-10-09
Project Center CRITICAL 9.8
CVE-2025-35050

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to ex…

Mitigation only
Fix from $2,300 2025-10-09
Project Center CRITICAL 9.8
CVE-2025-35051

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthentica…

Mitigation only
Fix from $2,300 2025-10-09
Project Center CRITICAL 9.8
CVE-2024-32499

Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.

Fix: after 2023.3.0.32259
Fix from $2,300 2025-04-28