← Back

Deltaww

deltaww

294 CVEs • 66 products

Products (66)

Click to collapse
Toggle
Diaenergie
diaenergie
Dopsoft
dopsoft
Cncsoft G2
cncsoft-g2
Tpeditor
tpeditor
Dialink
dialink
Diascreen
diascreen
Cncsoft
cncsoft
Cncsoft B
cncsoft-b
Ispsoft
ispsoft
Wplsoft
wplsoft
Asda Soft
asda_soft
Screeneditor
screeneditor
Diaview
diaview
Drasimucad
drasimucad
Commgr2
commgr2
Pmsoft
pmsoft
Commgr
commgr
Dcisoft
dcisoft
Dmars
dmars
Dtn Soft
dtn_soft
Dvw W02w2 E2
dvw-w02w2-e2
Dx 2100 L1 Cn
dx-2100-l1-cn
Dx 3021l9
dx-3021l9
Dx 2100l1 Cn
dx-2100l1-cn
Dvp32es200r
dvp32es200r
Dvp32es200t
dvp32es200t
Dvp32es211t
dvp32es211t
Dvp32es200rc
dvp32es200rc
Dvp32es200tc
dvp32es200tc
Dvp32es200re
dvp32es200re
Dvp32es200te
dvp32es200te
Dvp15mc11t
dvp15mc11t
Dvp 12se
dvp-12se
Dvp 12se11t
dvp-12se11t
As320t
as320t

CVEs (294)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Deltaww
1Cncsoft G2
Jun 17, 2026
Jul 9, 2024
8.4 HIGH· v4
8.8 HIGH· v3
N/A· v2
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker...Show more
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.Show less
1Deltaww
1Cncsoft G2
Jun 17, 2026
Jul 9, 2024
8.4 HIGH· v4
8.8 HIGH· v3
N/A· v2
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or opens a malicious file an attacker can le...Show more
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.Show less
1Deltaww
1Cncsoft G2
Jun 17, 2026
Jul 9, 2024
8.4 HIGH· v4
8.8 HIGH· v3
N/A· v2
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a malicious page or opens a malicious file an attacker can leverage this v...Show more
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.Show less
1Deltaww
1Cncsoft G2
Jun 17, 2026
Jul 9, 2024
8.4 HIGH· v4
8.8 HIGH· v3
N/A· v2
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. If a target visits a malicious page or opens a malicious file an attacker...Show more
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 6, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.
1Deltaww
1Diaenergie
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthe...Show more
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unaut...Show more
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth fieldShow less
1Deltaww
1Diaenergie
Jun 17, 2026
May 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on t...Show more
Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten. Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DI...Show more
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed. Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIA...Show more
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed. Show less
1Deltaww
1Cncsoft G2
Jun 17, 2026
Apr 30, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the conte...Show more
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Apr 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability exists in GetDIAE_usListParameters.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper neutralization of input within the affected product could lead to cross-site scripting.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL injection vulnerability exists in GetDIAE_astListParameters.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be over...Show more
Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten. Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL injection vulnerability exists in GetDIAE_slogListParameters.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL injection vulnerability exists in GetDIAE_unListParameters.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL injection vulnerability exists in the script Handler_CFG.ashx.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.