← Back

Deltaww

deltaww

294 CVEs • 66 products

Products (66)

Click to collapse
Toggle
Diaenergie
diaenergie
Dopsoft
dopsoft
Cncsoft G2
cncsoft-g2
Tpeditor
tpeditor
Dialink
dialink
Diascreen
diascreen
Cncsoft
cncsoft
Cncsoft B
cncsoft-b
Ispsoft
ispsoft
Wplsoft
wplsoft
Asda Soft
asda_soft
Screeneditor
screeneditor
Diaview
diaview
Drasimucad
drasimucad
Commgr2
commgr2
Pmsoft
pmsoft
Commgr
commgr
Dcisoft
dcisoft
Dmars
dmars
Dtn Soft
dtn_soft
Dvw W02w2 E2
dvw-w02w2-e2
Dx 2100 L1 Cn
dx-2100-l1-cn
Dx 3021l9
dx-3021l9
Dx 2100l1 Cn
dx-2100l1-cn
Dvp32es200r
dvp32es200r
Dvp32es200t
dvp32es200t
Dvp32es211t
dvp32es211t
Dvp32es200rc
dvp32es200rc
Dvp32es200tc
dvp32es200tc
Dvp32es200re
dvp32es200re
Dvp32es200te
dvp32es200te
Dvp15mc11t
dvp15mc11t
Dvp 12se
dvp-12se
Dvp 12se11t
dvp-12se11t
As320t
as320t

CVEs (294)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 29, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between...Show more
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.Show less
1Deltaww
1Cncsoft Screeneditor
Jun 17, 2026
Mar 25, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.
1Deltaww
1Diaenergie
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”.
1Deltaww
1Diaenergie
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.
1Deltaww
1Diaenergie
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.
1Deltaww
1Diaenergie
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.
1Deltaww
1Cncsoft
Jun 17, 2026
Dec 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may al...Show more
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.Show less
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may all...Show more
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.Show less
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet applic...Show more
The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.Show less
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious f...Show more
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.Show less
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without auth...Show more
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.Show less
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Read...Show more
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.Show less
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allo...Show more
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.Show less
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which...Show more
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.Show less