← Back

Deltaww

deltaww

294 CVEs • 66 products

Products (66)

Click to collapse
Toggle
Diaenergie
diaenergie
Dopsoft
dopsoft
Cncsoft G2
cncsoft-g2
Tpeditor
tpeditor
Dialink
dialink
Diascreen
diascreen
Cncsoft
cncsoft
Cncsoft B
cncsoft-b
Ispsoft
ispsoft
Wplsoft
wplsoft
Asda Soft
asda_soft
Screeneditor
screeneditor
Diaview
diaview
Drasimucad
drasimucad
Commgr2
commgr2
Pmsoft
pmsoft
Commgr
commgr
Dcisoft
dcisoft
Dmars
dmars
Dtn Soft
dtn_soft
Dvw W02w2 E2
dvw-w02w2-e2
Dx 2100 L1 Cn
dx-2100-l1-cn
Dx 3021l9
dx-3021l9
Dx 2100l1 Cn
dx-2100l1-cn
Dvp32es200r
dvp32es200r
Dvp32es200t
dvp32es200t
Dvp32es211t
dvp32es211t
Dvp32es200rc
dvp32es200rc
Dvp32es200tc
dvp32es200tc
Dvp32es200re
dvp32es200re
Dvp32es200te
dvp32es200te
Dvp15mc11t
dvp15mc11t
Dvp 12se
dvp-12se
Dvp 12se11t
dvp-12se11t
As320t
as320t

CVEs (294)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Deltaww
1Dopsoft
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could lev...Show more
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.Show less
1Deltaww
1Dopsoft
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this...Show more
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.Show less
1Deltaww
1Dopsoft
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer overflow while trying to copy to a buffer...Show more
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage this vulnerability to execute code in the context of the current process.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value...Show more
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value sup...Show more
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value...Show more
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.Show less
1Deltaww
1Dopsoft
Jun 17, 2026
Aug 30, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow an attacker to execute arbitrary code.
1Deltaww
1Tpeditor
Jun 17, 2026
Aug 30, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to execu...Show more
A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value suppl...Show more
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with admini...Show more
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.
1Deltaww
1Dopsoft
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.
1Deltaww
1Dopsoft
Jun 17, 2026
Jul 2, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.
1Deltaww
1Cncsoft Screeneditor
Jun 17, 2026
May 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execut...Show more
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.Show less
1Deltaww
1Cncsoft Screeneditor
Jun 17, 2026
May 10, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbi...Show more
Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.Show less
1Deltaww
1Industrial Automation Commgr
Jun 17, 2026
Apr 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute remote code.
1Deltaww
1Tpeditor
Jun 17, 2026
Jan 26, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
1Deltaww
1Tpeditor
Jun 17, 2026
Jan 26, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.