Vulnerabilities

Summary — last 7 days

New vulnerabilities3,091▲ 520 vs. last week
Critical / high1,463▲ 65 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)1.2%—Myiosoft Ajaxportal6/30/20096/16/2026
PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the pathtoserverdata parameter. NOTE: the installation instructions specify deleting the install/ folder.
ModifiedHigh (7.5)0.99%💥 ExploitMyiosoft Ajaxportal5/1/20096/16/2026
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModifiedHigh (7.5)6.1%💥 ExploitMagtrb AJA Portal2/10/20096/16/2026
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter to admin/case.php in the (1) Contact_Plus and (2) Reviews modules, and (3) the module_name parameter to…
ModifiedHigh (7.5)1.0%💥 ExploitMyiosoft.com Ajaxportal12/17/20086/16/2026
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third party information.
ModifiedHigh (7.5)1.3%—Myiosoft.com Ajaxportal7/18/20066/16/2026
SQL injection vulnerability in AjaxPortal 3.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the 'Search' field, a different vulnerability than CVE-2006-3515.
ModifiedHigh (7.5)1.5%—Myiosoft.com Ajaxportal7/11/20066/16/2026
SQL injection vulnerability in the loginADP function in ajaxp.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
Orbitaley — Vulnerabilities