Home/Product/newforma project center
Product

newforma project center

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-35062
< 2023.1
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated atta
5.3MEDIUM
CVE-2025-35061
< 2023.2
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NI
5.9MEDIUM
CVE-2025-35060
< 2024.1
Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG
5.5MEDIUM
CVE-2025-35059
< 2024.1
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' paramete
4.3MEDIUM
CVE-2025-35058
< 2023.2
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make
5.9MEDIUM
CVE-2025-35057
< 2024.3
Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make
5.3MEDIUM
CVE-2025-35056
< 2024.1
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns a
5.0MEDIUM
CVE-2025-35055
< 2023.1
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to
8.8HIGH
CVE-2025-35054
<= 2024.3
Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentia
5.3MEDIUM
CVE-2025-35053
<= 2024.3
Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' comman
6.4MEDIUM
CVE-2025-35052
<= 2024.3
Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specif
5.3MEDIUM
CVE-2025-35051
all versions
Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a r
9.8CRITICAL
CVE-2025-35050
all versions
Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthentic
9.8CRITICAL
CVE-2024-32499
<= 2023.3.0.32259
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
4.9MEDIUM
threatengine.sh