Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2023-1135
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in l…
Infrasuite Device Master
1.0.5+
HIGH 7.5
CVE-2023-1136
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to …
Infrasuite Device Master
1.0.5+
HIGH 7.5
CVE-2023-1138
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to…
Infrasuite Device Master
1.0.5+
HIGH 8.8
CVE-2023-0822
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass aut…
Diaenergie
1.9.03.001+
HIGH 7.8
CVE-2023-0249
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attacker to remotely execute arbitr…
Diascreen
after 1.2.1.23
HIGH 7.8
CVE-2023-0250
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely ex…
Diascreen
after 1.2.1.23
HIGH 7.8
CVE-2023-0251
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restrictions of operations within memory…
Diascreen
after 1.2.1.23
HIGH 7.8
CVE-2022-4634EPSS 5%
All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buf…
Cncsoft
1.01.5 / 1.01.34+
HIGH 7.8
CVE-2023-0123
Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely ex…
Dopsoft
4.00.16.22+
HIGH 7.8
CVE-2023-0124
Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute a…
Dopsoft
4.00.16.22+
HIGH 8.8
CVE-2023-0444
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Onl…
Infrasuite Device Master
Mitigation only
CRITICAL 9.1
CVE-2022-4616
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to
command injection through the network diagnosis page. This vulnerability
cou…
Dx 3021l9 Firmware
1.24+
HIGH 8.8
CVE-2022-41778
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect servic…
Infrasuite Device Master
after 00.00.01a
HIGH 7.5
CVE-2022-2966
Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.
Dopsoft
No fix yet
HIGH 8.8
CVE-2022-42139EPSS 18%
Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.
Dvw W02w2 E2 Firmware
No fix yet
HIGH 7.2
CVE-2022-42140
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.
Dx 2100 L1 Cn Firmware
No fix yet
MEDIUM 5.4
CVE-2022-42141
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.
Dx 2100 L1 Cn Firmware
No fix yet
HIGH 7.5
CVE-2022-2660
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attac…
Dialink
after 1.4.0.0
HIGH 7.5
CVE-2022-2969
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or d…
Dialink
1.5.0.0+
HIGH 8.8
CVE-2022-43447
SQL Injection in
AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queri…
Diaenergie
1.9.02.001+
HIGH 8.8
CVE-2022-43452EPSS 8%
SQL Injection in
FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL que…
Diaenergie
1.9.02.001+
HIGH 8.8
CVE-2022-43457
SQL Injection in
HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL quer…
Diaenergie
1.9.02.001+
HIGH 8.8
CVE-2022-43506
SQL Injection in
HandlerTag_KID.ashx
in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries vi…
Diaenergie
1.9.02.001+
HIGH 8.8
CVE-2022-41775
SQL Injection in
Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via …
Diaenergie
1.9.02.001+
CRITICAL 9.8
CVE-2022-41657EPSS 21%
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in fil…
Infrasuite Device Master
00.00.02a+
CRITICAL 9.8
CVE-2022-41772EPSS 25%
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This pa…
Infrasuite Device Master
00.00.02a+
CRITICAL 9.8
CVE-2022-41779
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connec…
Infrasuite Device Master
00.00.02a+
CRITICAL 9.1
CVE-2022-41629
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could all…
Infrasuite Device Master
00.00.02a+
HIGH 8.8
CVE-2022-41644
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacke…
Infrasuite Device Master
00.00.02a+
HIGH 7.5
CVE-2022-41688
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. …
Infrasuite Device Master
00.00.02a+