Записи Newforma
14 опубликованных записей вендора newforma.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-294 Authentication Bypass by Capture-replay3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-306 Missing Authentication for Critical Function2
- CWE-276 Incorrect Default Permissions1
- CWE-257 Storing Passwords in a Recoverable Format1
- CWE-321 Use of Hard-coded Cryptographic Key1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-32499Эксплойта нет | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.newforma · project center · CWE-94 | Критическая9,8 | — | 0,5 % | 28 апр. 2025 г. |
37Наблюдать | CVE-2025-35050Эксплойта нет | Newforma Info Exchange (NIX) .NET unauthenticated deserializationnewforma · project center · CWE-306 | Критическая9,3 | — | 0,9 % | 9 окт. 2025 г. |
36Наблюдать | CVE-2025-35051Эксплойта нет | Newforma Project Center Server (NPCS) .NET unauthenticated deserializationnewforma · project center · CWE-306 | Критическая9,2 | — | 0,8 % | 9 окт. 2025 г. |
34Наблюдать | CVE-2025-35055Эксплойта нет | Newforma Info Exchange (NIX) insecure file uploadnewforma · project center · CWE-22 | Высокая8,7 | — | 0,5 % | 9 окт. 2025 г. |
32Наблюдать | CVE-2025-35061Эксплойта нет | Newforma Info Exchange (NIX) forced NTLMv2 authentication via /NPCSRemoteWeb/LegacyIntegrationServices.asmxnewforma · project center · CWE-294 | Высокая8,2 | — | 0,4 % | 9 окт. 2025 г. |
32Наблюдать | CVE-2025-35058Эксплойта нет | Newforma Info Exchange (NIX) forced NTLMv2 authentication via /UserWeb/Common/MarkupServices.ashxnewforma · project center · CWE-294 | Высокая8,2 | — | 0,4 % | 9 окт. 2025 г. |
27Наблюдать | CVE-2025-35062Эксплойта нет | Newforma Info Exchange (NIX) default anonymous accessnewforma · project center · CWE-276 | Средняя6,9 | — | 0,4 % | 9 окт. 2025 г. |
25Наблюдать | CVE-2025-35052Эксплойта нет | Newforma Info Exchange (NIX) shared hard-coded secret keynewforma · project center · CWE-321 | Средняя6,3 | — | 0,4 % | 9 окт. 2025 г. |
24Наблюдать | CVE-2025-35053Эксплойта нет | Newforma Info Exchange (NIX) arbitrary file read and deletenewforma · project center · CWE-22 | Средняя6,1 | — | 0,4 % | 9 окт. 2025 г. |
24Наблюдать | CVE-2025-35057Эксплойта нет | Newforma Info Exchange (NIX) forced NTLMv2 authentication via /RemoteWeb/IntegrationServices.ashxnewforma · project center · CWE-294 | Средняя6,0 | — | 0,3 % | 9 окт. 2025 г. |
21Наблюдать | CVE-2025-35056Эксплойта нет | Newforma Info Exchange (NIX) limited file readnewforma · project center · CWE-22 | Средняя5,3 | — | 0,4 % | 9 окт. 2025 г. |
21Наблюдать | CVE-2025-35059Эксплойта нет | Newforma Info Exchange (NIX) open URL redirect via /DownloadWeb/hyperlinkredirect.aspxnewforma · project center · CWE-601 | Средняя5,3 | — | 0,2 % | 9 окт. 2025 г. |
20Наблюдать | CVE-2025-35060Эксплойта нет | Newforma Info Exchange (NIX) stored XSS via SVG file uploadnewforma · project center · CWE-79 | Средняя5,1 | — | 0,2 % | 9 окт. 2025 г. |
19Наблюдать | CVE-2025-35054Эксплойта нет | Newforma Info Exchange (NIX) insufficiently protected credentialsnewforma · project center · CWE-257 | Средняя4,8 | — | 0,1 % | 9 окт. 2025 г. |
- CVE-2024-3249939Наблюдать
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %newforma · project center28 апр. 2025 г.
- CVE-2025-3505037Наблюдать
Newforma Info Exchange (NIX) .NET unauthenticated deserialization
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505136Наблюдать
Newforma Project Center Server (NPCS) .NET unauthenticated deserialization
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505534Наблюдать
Newforma Info Exchange (NIX) insecure file upload
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %newforma · project center9 окт. 2025 г.
- CVE-2025-3506132Наблюдать
Newforma Info Exchange (NIX) forced NTLMv2 authentication via /NPCSRemoteWeb/LegacyIntegrationServices.asmx
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505832Наблюдать
Newforma Info Exchange (NIX) forced NTLMv2 authentication via /UserWeb/Common/MarkupServices.ashx
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3506227Наблюдать
Newforma Info Exchange (NIX) default anonymous access
СредняяCVSS 6,9Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505225Наблюдать
Newforma Info Exchange (NIX) shared hard-coded secret key
СредняяCVSS 6,3Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505324Наблюдать
Newforma Info Exchange (NIX) arbitrary file read and delete
СредняяCVSS 6,1Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505724Наблюдать
Newforma Info Exchange (NIX) forced NTLMv2 authentication via /RemoteWeb/IntegrationServices.ashx
СредняяCVSS 6,0Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505621Наблюдать
Newforma Info Exchange (NIX) limited file read
СредняяCVSS 5,3Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505921Наблюдать
Newforma Info Exchange (NIX) open URL redirect via /DownloadWeb/hyperlinkredirect.aspx
СредняяCVSS 5,3Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3506020Наблюдать
Newforma Info Exchange (NIX) stored XSS via SVG file upload
СредняяCVSS 5,1Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.
- CVE-2025-3505419Наблюдать
Newforma Info Exchange (NIX) insufficiently protected credentials
СредняяCVSS 4,8Эксплойта нетEPSS 0 %newforma · project center9 окт. 2025 г.