Vulnerability index

Browse CVEs

286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cncsoft G2 HIGH 8.8
CVE-2024-39883

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If …

No fix yet
Fix from $1,950 2024-07-09
Cncsoft G2 HIGH 8.8
CVE-2024-39880

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. If…

Mitigation only
Fix from $1,950 2024-07-09
Cncsoft G2 HIGH 8.8
CVE-2024-39881

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a m…

Mitigation only
Fix from $1,950 2024-07-09
Diaenergie CRITICAL 9.8
CVE-2024-4547

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is sp…

Fix: 1.10.01.004+
Fix from $2,300 2024-05-06
Diaenergie CRITICAL 9.8
CVE-2024-4548EPSS 29%

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is s…

Fix: 1.10.01.004+
Fix from $2,300 2024-05-06
Diaenergie HIGH 7.5
CVE-2024-4549

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe …

Fix: 1.10.01.004+
Fix from $1,950 2024-05-06
Diaenergie HIGH 8.8
CVE-2024-34032EPSS 9%

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker c…

Mitigation only
Fix from $1,950 2024-05-03
Diaenergie HIGH 8.8
CVE-2024-34033

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the in…

Mitigation only
Fix from $1,950 2024-05-03
Diaenergie HIGH 8.8
CVE-2024-34031

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker ca…

Mitigation only
Fix from $1,950 2024-05-03
Cncsoft G2 HIGH 7.8
CVE-2024-4192

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An…

Fix: 2.1.0.4+
Fix from $1,950 2024-04-30
Diaenergie CRITICAL 9.8
CVE-2024-25574EPSS 9%

SQL injection vulnerability exists in GetDIAE_usListParameters.

Fix: 1.10.00.005+
Fix from $2,300 2024-04-01
Diaenergie HIGH 8.8
CVE-2024-25567

Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that …

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Diaenergie HIGH 8.8
CVE-2024-28040EPSS 8%

SQL injection vulnerability exists in GetDIAE_astListParameters.

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Diaenergie HIGH 8.1
CVE-2024-28171

It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the…

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Diaenergie MEDIUM 5.4
CVE-2024-28045

Improper neutralization of input within the affected product could lead to cross-site scripting.

Fix: 1.10.00.005+
Fix from $1,600 2024-03-21
Diaenergie HIGH 8.8
CVE-2024-23494EPSS 8%

SQL injection vulnerability exists in GetDIAE_unListParameters.

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Diaenergie HIGH 8.8
CVE-2024-23975EPSS 8%

SQL injection vulnerability exists in GetDIAE_slogListParameters.

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Diaenergie HIGH 8.8
CVE-2024-28891EPSS 8%

SQL injection vulnerability exists in the script Handler_CFG.ashx.

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Diaenergie HIGH 8.8
CVE-2024-28029

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged fu…

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Diaenergie HIGH 8.8
CVE-2024-25937EPSS 8%

SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Cncsoft B HIGH 7.8
CVE-2024-1941

Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitr…

Fix: after 1.0.0.4
Fix from $1,950 2024-03-01
Cncsoft B HIGH 7.8
CVE-2024-1595

Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over t…

Fix: 4.0.0.94+
Fix from $1,950 2024-02-29
Ispsoft HIGH 8.8
CVE-2023-5131

A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a special…

Mitigation only
Fix from $1,950 2024-01-18
Wplsoft HIGH 8.8
CVE-2023-5130

A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open …

Mitigation only
Fix from $1,950 2024-01-18
Dopsoft HIGH 7.8
CVE-2023-43821

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS fil…

Fix: after 2.00.07.04
Fix from $1,950 2024-01-18
Dopsoft HIGH 7.8
CVE-2023-43822

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file.…

Fix: after 2.00.07.04
Fix from $1,950 2024-01-18
Dopsoft HIGH 7.8
CVE-2023-43823

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remo…

Fix: after 2.00.07.04
Fix from $1,950 2024-01-18
Dopsoft HIGH 7.8
CVE-2023-43824

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A r…

Fix: after 2.00.07.04
Fix from $1,950 2024-01-18
Dopsoft HIGH 7.8
CVE-2023-43817

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An …

Fix: after 2.00.07.04
Fix from $1,950 2024-01-18
Dopsoft HIGH 7.8
CVE-2023-43818

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability …

Fix: after 2.00.07.04
Fix from $1,950 2024-01-18