Project Center
Vendor:
First CVE: Apr 28, 2025 · Active for 1 year
14
Total CVEs
More Total CVEs than 91% of tracked products
14.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Project Center over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 28, 2025
14 months ago
Most Recent CVE
Oct 9, 2025
291 days ago
CVE Severity & Scoring
Project Center14 CVEs
64%
29%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (78.6%)
High3 (21.4%)
Unknown0 (0.0%)
User Interaction
None12 (85.7%)
Unknown0 (0.0%)
Required2 (14.3%)
Privileges Required
Low6 (42.9%)
High0 (0.0%)
None8 (57.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-35050CRITICAL Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT A | Oct 9, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-35051CRITICAL Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitra | Oct 9, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-35062CRITICAL Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that re | Oct 9, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-35055HIGH Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An a | Oct 9, 2025 | 8.8 | 29 | NO | NO |
CVE-2024-32499CRITICAL Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. | Apr 28, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-35053MEDIUM Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and del | Oct 9, 2025 | 6.4 | 22 | NO | NO |
CVE-2025-35061MEDIUM Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-control | Oct 9, 2025 | 5.9 | 21 | NO | NO |
CVE-2025-35059MEDIUM Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter. | Oct 9, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-35060MEDIUM Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content tha | Oct 9, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-35058MEDIUM Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system | Oct 9, 2025 | 5.9 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Project Center
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2024.3 | 2 | 9.8 | 0.8% | 0 | 0 |