8.7

CVSS4.0

CVE-2025-35055 - Newforma Info Exchange (NIX) insecure file upload

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can upload and run a web shell or other content executable by the web server. An attacker can also delete direc…

πŸ“… Published: Oct. 9, 2025, 8:20 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 8:20 p.m.

4.8

CVSS4.0

CVE-2025-35054 - Newforma Info Exchange (NIX) insufficiently protected credentials

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption…

πŸ“… Published: Oct. 9, 2025, 8:20 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 8:20 p.m.

6.1

CVSS4.0

CVE-2025-35053 - Newforma Info Exchange (NIX) arbitrary file read and delete

Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT AUTHORITY\NetworkService' privileges. In Newforma before 2023.1, anonymous access is enab…

πŸ“… Published: Oct. 9, 2025, 8:20 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 8:20 p.m.

6.3

CVSS4.0

CVE-2025-35052 - Newforma Info Exchange (NIX) shared hard-coded secret key

Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/DownloadWeb/download.aspx'. This key is shar…

πŸ“… Published: Oct. 9, 2025, 8:20 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 8:20 p.m.

7.7

CVSS4.0

CVE-2025-35051 - Newforma Project Center Server (NPCS) .NET unauthenticated deserialization

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. According to the recommended architecture, the vulnerable NPCS e…

πŸ“… Published: Oct. 9, 2025, 8:19 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 8:19 p.m.

9.3

CVSS4.0

CVE-2025-35050 - Newforma Info Exchange (NIX) .NET unauthenticated deserialization

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpoint is used by Newforma Project Center Server (NPCS), so a com…

πŸ“… Published: Oct. 9, 2025, 8:19 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 8:19 p.m.

5.3

CVSS4.0

CVE-2025-11554 - Portabilis i-Educar User Type AccessLevelController.php insecure inherited permissions

A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipulation leads to insecure inherited permissions. The attack ma…

πŸ“… Published: Oct. 9, 2025, 8:02 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 8:02 p.m.

5.3

CVSS4.0

CVE-2025-11553 - code-projects Courier Management System add-courier.php sql injection

A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-courier.php. Executing manipulation of the argument Shippername can lead to sql injection. The attack can be launched remotely. The exploit has …

πŸ“… Published: Oct. 9, 2025, 7:32 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:32 p.m.

5.3

CVSS4.0

CVE-2025-11552 - code-projects Online Complaint Site category.php sql injection

A vulnerability was identified in code-projects Online Complaint Site 1.0. This impacts an unknown function of the file /admin/category.php. Such manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might b…

πŸ“… Published: Oct. 9, 2025, 7:02 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:02 p.m.

8.5

CVSS3.1

CVE-2025-59146 - New API has Authenticated Server-Side Request Forgery (SSRF) issue

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in versions prior to 0.9.0.5. A feature within the application allows authenticated users to submit a URL for the server …

πŸ“… Published: Oct. 9, 2025, 6:58 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:07 p.m.
Total resulsts: 313599
Page 10 of 31,360
Β« previous page Β» next page
Filters