Vulnerability index

Browse CVEs

286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infrasuite Device Master HIGH 7.8
CVE-2023-1135

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in l…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Infrasuite Device Master HIGH 7.5
CVE-2023-1136

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to …

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Infrasuite Device Master HIGH 7.5
CVE-2023-1138

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Diaenergie HIGH 8.8
CVE-2023-0822

The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass aut…

Fix: 1.9.03.001+
Fix from $1,950 2023-02-17
Diascreen HIGH 7.8
CVE-2023-0249

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attacker to remotely execute arbitr…

Fix: after 1.2.1.23
Fix from $1,950 2023-02-08
Diascreen HIGH 7.8
CVE-2023-0250

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely ex…

Fix: after 1.2.1.23
Fix from $1,950 2023-02-08
Diascreen HIGH 7.8
CVE-2023-0251

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restrictions of operations within memory…

Fix: after 1.2.1.23
Fix from $1,950 2023-02-08
Cncsoft HIGH 7.8
CVE-2022-4634EPSS 5%

All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buf…

Fix: 1.01.5 / 1.01.34+
Fix from $1,950 2023-02-03
Dopsoft HIGH 7.8
CVE-2023-0123

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely ex…

Fix: 4.00.16.22+
Fix from $1,950 2023-02-03
Dopsoft HIGH 7.8
CVE-2023-0124

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute a…

Fix: 4.00.16.22+
Fix from $1,950 2023-02-03
Infrasuite Device Master HIGH 8.8
CVE-2023-0444

A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Onl…

Mitigation only
Fix from $1,950 2023-01-26
Dx 3021l9 Firmware CRITICAL 9.1
CVE-2022-4616

The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability cou…

Fix: 1.24+
Fix from $2,300 2023-01-13
Infrasuite Device Master HIGH 8.8
CVE-2022-41778

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect servic…

Fix: after 00.00.01a
Fix from $1,950 2023-01-13
Dopsoft HIGH 7.5
CVE-2022-2966

Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.

No fix yet
Fix from $1,950 2022-12-16
Dvw W02w2 E2 Firmware HIGH 8.8
CVE-2022-42139EPSS 18%

Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

No fix yet
Fix from $1,950 2022-12-14
Dx 2100 L1 Cn Firmware HIGH 7.2
CVE-2022-42140

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

No fix yet
Fix from $1,950 2022-12-14
Dx 2100 L1 Cn Firmware MEDIUM 5.4
CVE-2022-42141

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.

No fix yet
Fix from $1,600 2022-12-14
Dialink HIGH 7.5
CVE-2022-2660

Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attac…

Fix: after 1.4.0.0
Fix from $1,950 2022-12-13
Dialink HIGH 7.5
CVE-2022-2969

Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or d…

Fix: 1.5.0.0+
Fix from $1,950 2022-12-01
Diaenergie HIGH 8.8
CVE-2022-43447

SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queri…

Fix: 1.9.02.001+
Fix from $1,950 2022-11-17
Diaenergie HIGH 8.8
CVE-2022-43452EPSS 8%

SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL que…

Fix: 1.9.02.001+
Fix from $1,950 2022-11-17
Diaenergie HIGH 8.8
CVE-2022-43457

SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL quer…

Fix: 1.9.02.001+
Fix from $1,950 2022-11-17
Diaenergie HIGH 8.8
CVE-2022-43506

SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries vi…

Fix: 1.9.02.001+
Fix from $1,950 2022-11-17
Diaenergie HIGH 8.8
CVE-2022-41775

SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via …

Fix: 1.9.02.001+
Fix from $1,950 2022-11-17
Infrasuite Device Master CRITICAL 9.8
CVE-2022-41657EPSS 21%

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in fil…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Infrasuite Device Master CRITICAL 9.8
CVE-2022-41772EPSS 25%

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This pa…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Infrasuite Device Master CRITICAL 9.8
CVE-2022-41779

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connec…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Infrasuite Device Master CRITICAL 9.1
CVE-2022-41629

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could all…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Infrasuite Device Master HIGH 8.8
CVE-2022-41644

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacke…

Fix: 00.00.02a+
Fix from $1,950 2022-10-31
Infrasuite Device Master HIGH 7.5
CVE-2022-41688

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. …

Fix: 00.00.02a+
Fix from $1,950 2022-10-31