← Back

Deltaww

deltaww

294 CVEs • 66 products

Products (66)

Click to collapse
Toggle
Diaenergie
diaenergie
Dopsoft
dopsoft
Cncsoft G2
cncsoft-g2
Tpeditor
tpeditor
Dialink
dialink
Diascreen
diascreen
Cncsoft
cncsoft
Cncsoft B
cncsoft-b
Ispsoft
ispsoft
Wplsoft
wplsoft
Asda Soft
asda_soft
Screeneditor
screeneditor
Diaview
diaview
Drasimucad
drasimucad
Commgr2
commgr2
Pmsoft
pmsoft
Commgr
commgr
Dcisoft
dcisoft
Dmars
dmars
Dtn Soft
dtn_soft
Dvw W02w2 E2
dvw-w02w2-e2
Dx 2100 L1 Cn
dx-2100-l1-cn
Dx 3021l9
dx-3021l9
Dx 2100l1 Cn
dx-2100l1-cn
Dvp32es200r
dvp32es200r
Dvp32es200t
dvp32es200t
Dvp32es211t
dvp32es211t
Dvp32es200rc
dvp32es200rc
Dvp32es200tc
dvp32es200tc
Dvp32es200re
dvp32es200re
Dvp32es200te
dvp32es200te
Dvp15mc11t
dvp15mc11t
Dvp 12se
dvp-12se
Dvp 12se11t
dvp-12se11t
As320t
as320t

CVEs (294)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 27, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary...Show more
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
1Deltaww
1Diaenergie
Jun 17, 2026
Sep 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could b...Show more
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.Show less
1Deltaww
1Delta Robot Automation Studio
Jun 17, 2026
Aug 31, 2022
N/A· v4
8.6 HIGH· v3
N/A· v2
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to...Show more
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.Show less
1Deltaww
1Cncsoft
Jun 17, 2026
Aug 31, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buffer overflow condition.
1Deltaww
1Cncsoft
Jun 17, 2026
Aug 31, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.
1Deltaww
1Diaenergie
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Nam...Show more
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.Show less
1Deltaww
1Diascreen
Jun 17, 2026
May 24, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow an attacker to remotely execute arbitrary code.
1Deltaww
1Diascreen
Jun 17, 2026
May 24, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.
1Deltaww
1Dmars
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify databas...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify dat...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify databa...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database content...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents,...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database content...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less