Vulnerability index

Browse CVEs

286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infrasuite Device Master HIGH 7.5
CVE-2022-41776

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which c…

Fix: 00.00.02a+
Fix from $1,950 2022-10-31
Infrasuite Device Master CRITICAL 9.8
CVE-2022-38142EPSS 18%

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service po…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Infrasuite Device Master CRITICAL 9.8
CVE-2022-40202

The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker coul…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Diaenergie HIGH 8.8
CVE-2022-41773EPSS 8%

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authe…

Fix: 1.9.01.002+
Fix from $1,950 2022-10-27
Diaenergie MEDIUM 5.4
CVE-2022-41651EPSS 11%

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.

Fix: 1.9.01.002+
Fix from $1,600 2022-10-27
Diaenergie MEDIUM 5.4
CVE-2022-41701EPSS 11%

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.

Fix: 1.9.01.002+
Fix from $1,600 2022-10-27
Diaenergie MEDIUM 5.4
CVE-2022-41702EPSS 11%

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg AP…

Fix: 1.9.01.002+
Fix from $1,600 2022-10-27
Diaenergie HIGH 8.8
CVE-2022-41133EPSS 27%

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListPara…

Fix: 1.9.01.002+
Fix from $1,950 2022-10-27
Diaenergie MEDIUM 5.4
CVE-2022-41555EPSS 11%

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessa…

Fix: 1.9.01.002+
Fix from $1,600 2022-10-27
Diaenergie HIGH 8.8
CVE-2022-40967EPSS 8%

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privile…

Fix: 1.9.01.002+
Fix from $1,950 2022-10-27
Diaenergie MEDIUM 5.4
CVE-2022-40965EPSS 11%

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyTy…

Fix: 1.9.01.002+
Fix from $1,600 2022-10-27
Diaenergie CRITICAL 9.8
CVE-2022-43774

The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a…

Mitigation only
Fix from $2,300 2022-10-26
Diaenergie CRITICAL 9.8
CVE-2022-43775EPSS 21%

The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote…

Mitigation only
Fix from $2,300 2022-10-26
Diaenergie CRITICAL 9.8
CVE-2022-3214

Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions pr…

Fix: 1.9.03.009+
Fix from $2,300 2022-09-16
Delta Robot Automation Studio HIGH 8.6
CVE-2022-2759

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes a…

Fix: 1.13.20+
Fix from $1,950 2022-08-31
Cncsoft HIGH 7.8
CVE-2022-1405

CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buf…

Fix: 1.01.32+
Fix from $1,950 2022-08-31
Cncsoft HIGH 7.1
CVE-2022-1404

Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possi…

Fix: 1.01.32+
Fix from $1,950 2022-08-31
Diaenergie MEDIUM 6.1
CVE-2022-33005

A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to ex…

No fix yet
Fix from $1,600 2022-06-27
Diascreen HIGH 7.8
CVE-2021-32965

Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.

Fix: 1.1.0+
Fix from $1,950 2022-05-24
Diascreen HIGH 7.8
CVE-2021-32969

Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow a…

Fix: 1.1.0+
Fix from $1,950 2022-05-24
Dmars MEDIUM 5.5
CVE-2022-1331

In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific p…

Fix: 2.1.10.24+
Fix from $1,600 2022-05-03
Diaenergie CRITICAL 9.8
CVE-2022-1367EPSS 19%

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an at…

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02
Diaenergie CRITICAL 9.8
CVE-2022-1369

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker…

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02
Diaenergie CRITICAL 9.8
CVE-2022-1370

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacke…

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02
Diaenergie CRITICAL 9.8
CVE-2022-1371

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker t…

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02
Diaenergie CRITICAL 9.8
CVE-2022-1372

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacke…

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02
Diaenergie CRITICAL 9.8
CVE-2022-1374

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an…

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02
Diaenergie CRITICAL 9.8
CVE-2022-1375

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows …

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02
Diaenergie CRITICAL 9.8
CVE-2022-1376

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allo…

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02
Diaenergie CRITICAL 9.8
CVE-2022-1377

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows a…

Fix: 1.8.02.004+
Fix from $2,300 2022-05-02