Project Center

Vendor:

First CVE: Apr 28, 2025 · Active for 1 year

14
Total CVEs
More Total CVEs than 91% of tracked products
14.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Project Center over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 28, 2025
14 months ago
Most Recent CVE
Oct 9, 2025
291 days ago

CVE Severity & Scoring

Project Center14 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (78.6%)
High3 (21.4%)
Unknown0 (0.0%)
User Interaction
None12 (85.7%)
Unknown0 (0.0%)
Required2 (14.3%)
Privileges Required
Low6 (42.9%)
High0 (0.0%)
None8 (57.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT A
Oct 9, 20259.833NONO
Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitra
Oct 9, 20259.832NONO
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that re
Oct 9, 20259.830NONO
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An a
Oct 9, 20258.829NONO
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
Apr 28, 20259.825NONO
Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and del
Oct 9, 20256.422NONO
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-control
Oct 9, 20255.921NONO
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.
Oct 9, 20256.121NONO
Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content tha
Oct 9, 20255.420NONO
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system
Oct 9, 20255.920NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Project Center

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2024.329.80.8%00