Latest CVE Feed
- 
                                
                                9.3CRITICALCVE-2025-55321Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.... Read more Affected Products : azure_monitor- Published: Oct. 09, 2025
- Modified: Oct. 23, 2025
 
- 
                                
                                5.5MEDIUMCVE-2025-43296A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.... Read more Affected Products : macos- Published: Oct. 09, 2025
- Modified: Oct. 20, 2025
- Vuln Type: Authentication
 
- 
                                
                                9.8CRITICALCVE-2025-35062Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                8.2HIGHCVE-2025-35061Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                5.5MEDIUMCVE-2025-35060Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                6.1MEDIUMCVE-2025-35059Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Misconfiguration
 
- 
                                
                                8.2HIGHCVE-2025-35058Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX s... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Server-Side Request Forgery
 
- 
                                
                                6.0MEDIUMCVE-2025-35057Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the NIX service account.... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                5.3MEDIUMCVE-2025-35056Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                8.8HIGHCVE-2025-35055Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can upload and run a web shell or other content executable by the w... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                5.3MEDIUMCVE-2025-35054Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can ac... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cryptography
 
- 
                                
                                6.4MEDIUMCVE-2025-35053Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT AUTHORITY\NetworkService' privileges. In Newf... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                6.3MEDIUMCVE-2025-35052Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                9.8CRITICALCVE-2025-35051Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. According to the rec... Read more - Published: Oct. 09, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Information Disclosure
 
- 
                                
                                9.8CRITICALCVE-2025-35050Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpoint is used by New... Read more - Published: Oct. 09, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                7.2HIGHCVE-2025-34248D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to del... Read more Affected Products :- Published: Oct. 09, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                9.8CRITICALCVE-2025-11558A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/user_index_search.php. Performing manipulation of the argument Search results in sql injection. The attack is possible to be carried out ... Read more - Published: Oct. 09, 2025
- Modified: Oct. 23, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11557A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of the argument fullname leads to sql injection. The attack can be executed remotely. ... Read more Affected Products : gate_pass_management_system- Published: Oct. 09, 2025
- Modified: Oct. 20, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11556A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /user.php. This manipulation of the argument table causes sql injection. Remote exploitation of the attack is possible. The exploit has be... Read more Affected Products : simple_leave_manager- Published: Oct. 09, 2025
- Modified: Oct. 20, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11555A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/calendar_of_events.php. The manipulation of the argument date_start results in sql injection. The attack may be launched remot... Read more Affected Products : online_learning_management_system- Published: Oct. 09, 2025
- Modified: Oct. 20, 2025
- Vuln Type: Injection
 
 
                         
                         
                         
                                             
                                            