Airc maintains a narrowly scoped portfolio centered on the MyNet product, a web-based application where vulnerabilities cluster around input-handling and output-encoding weaknesses including cross-site scripting, SQL injection, and broader injection-class flaws. These disclosures skew toward serious outcomes, reflecting the severity impact of unsanitized user input flowing through web application logic and database queries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airc over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27708CRITICAL Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter. | Dec 22, 2025 | 9.6 | 34 | NO | NO |
CVE-2024-39037MEDIUM MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu parameter. | Dec 24, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-40317MEDIUM A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted pay | Dec 24, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-35322MEDIUM MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro parameter. | Dec 24, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-25812MEDIUM MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter. | Dec 22, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-25814MEDIUM MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter. | Dec 22, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-35321MEDIUM MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parameter. | Dec 22, 2025 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airc.
Media articles that mention a CVE ID that affects a product developed by Airc — matched by CVE ID, not by vendor name.