Newforma kayıtları
newforma üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-294 Authentication Bypass by Capture-replay3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-306 Missing Authentication for Critical Function2
- CWE-276 Incorrect Default Permissions1
- CWE-257 Storing Passwords in a Recoverable Format1
- CWE-321 Use of Hard-coded Cryptographic Key1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-32499İstismar yok | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.newforma · project center · CWE-94 | Kritik9,8 | — | %0,5 | 28 Nis 2025 |
37İzleyin | CVE-2025-35050İstismar yok | Newforma Info Exchange (NIX) .NET unauthenticated deserializationnewforma · project center · CWE-306 | Kritik9,3 | — | %0,9 | 9 Eki 2025 |
36İzleyin | CVE-2025-35051İstismar yok | Newforma Project Center Server (NPCS) .NET unauthenticated deserializationnewforma · project center · CWE-306 | Kritik9,2 | — | %0,8 | 9 Eki 2025 |
34İzleyin | CVE-2025-35055İstismar yok | Newforma Info Exchange (NIX) insecure file uploadnewforma · project center · CWE-22 | Yüksek8,7 | — | %0,5 | 9 Eki 2025 |
32İzleyin | CVE-2025-35061İstismar yok | Newforma Info Exchange (NIX) forced NTLMv2 authentication via /NPCSRemoteWeb/LegacyIntegrationServices.asmxnewforma · project center · CWE-294 | Yüksek8,2 | — | %0,4 | 9 Eki 2025 |
32İzleyin | CVE-2025-35058İstismar yok | Newforma Info Exchange (NIX) forced NTLMv2 authentication via /UserWeb/Common/MarkupServices.ashxnewforma · project center · CWE-294 | Yüksek8,2 | — | %0,4 | 9 Eki 2025 |
27İzleyin | CVE-2025-35062İstismar yok | Newforma Info Exchange (NIX) default anonymous accessnewforma · project center · CWE-276 | Orta6,9 | — | %0,4 | 9 Eki 2025 |
25İzleyin | CVE-2025-35052İstismar yok | Newforma Info Exchange (NIX) shared hard-coded secret keynewforma · project center · CWE-321 | Orta6,3 | — | %0,4 | 9 Eki 2025 |
24İzleyin | CVE-2025-35053İstismar yok | Newforma Info Exchange (NIX) arbitrary file read and deletenewforma · project center · CWE-22 | Orta6,1 | — | %0,4 | 9 Eki 2025 |
24İzleyin | CVE-2025-35057İstismar yok | Newforma Info Exchange (NIX) forced NTLMv2 authentication via /RemoteWeb/IntegrationServices.ashxnewforma · project center · CWE-294 | Orta6,0 | — | %0,3 | 9 Eki 2025 |
21İzleyin | CVE-2025-35056İstismar yok | Newforma Info Exchange (NIX) limited file readnewforma · project center · CWE-22 | Orta5,3 | — | %0,4 | 9 Eki 2025 |
21İzleyin | CVE-2025-35059İstismar yok | Newforma Info Exchange (NIX) open URL redirect via /DownloadWeb/hyperlinkredirect.aspxnewforma · project center · CWE-601 | Orta5,3 | — | %0,2 | 9 Eki 2025 |
20İzleyin | CVE-2025-35060İstismar yok | Newforma Info Exchange (NIX) stored XSS via SVG file uploadnewforma · project center · CWE-79 | Orta5,1 | — | %0,2 | 9 Eki 2025 |
19İzleyin | CVE-2025-35054İstismar yok | Newforma Info Exchange (NIX) insufficiently protected credentialsnewforma · project center · CWE-257 | Orta4,8 | — | %0,1 | 9 Eki 2025 |
- CVE-2024-3249939İzleyin
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
KritikCVSS 9,8İstismar yokEPSS %0newforma · project center28 Nis 2025
- CVE-2025-3505037İzleyin
Newforma Info Exchange (NIX) .NET unauthenticated deserialization
KritikCVSS 9,3İstismar yokEPSS %1newforma · project center9 Eki 2025
- CVE-2025-3505136İzleyin
Newforma Project Center Server (NPCS) .NET unauthenticated deserialization
KritikCVSS 9,2İstismar yokEPSS %1newforma · project center9 Eki 2025
- CVE-2025-3505534İzleyin
Newforma Info Exchange (NIX) insecure file upload
YüksekCVSS 8,7İstismar yokEPSS %1newforma · project center9 Eki 2025
- CVE-2025-3506132İzleyin
Newforma Info Exchange (NIX) forced NTLMv2 authentication via /NPCSRemoteWeb/LegacyIntegrationServices.asmx
YüksekCVSS 8,2İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3505832İzleyin
Newforma Info Exchange (NIX) forced NTLMv2 authentication via /UserWeb/Common/MarkupServices.ashx
YüksekCVSS 8,2İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3506227İzleyin
Newforma Info Exchange (NIX) default anonymous access
OrtaCVSS 6,9İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3505225İzleyin
Newforma Info Exchange (NIX) shared hard-coded secret key
OrtaCVSS 6,3İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3505324İzleyin
Newforma Info Exchange (NIX) arbitrary file read and delete
OrtaCVSS 6,1İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3505724İzleyin
Newforma Info Exchange (NIX) forced NTLMv2 authentication via /RemoteWeb/IntegrationServices.ashx
OrtaCVSS 6,0İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3505621İzleyin
Newforma Info Exchange (NIX) limited file read
OrtaCVSS 5,3İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3505921İzleyin
Newforma Info Exchange (NIX) open URL redirect via /DownloadWeb/hyperlinkredirect.aspx
OrtaCVSS 5,3İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3506020İzleyin
Newforma Info Exchange (NIX) stored XSS via SVG file upload
OrtaCVSS 5,1İstismar yokEPSS %0newforma · project center9 Eki 2025
- CVE-2025-3505419İzleyin
Newforma Info Exchange (NIX) insufficiently protected credentials
OrtaCVSS 4,8İstismar yokEPSS %0newforma · project center9 Eki 2025