Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2022-41776
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which c…
Infrasuite Device Master
00.00.02a+
CRITICAL 9.8
CVE-2022-38142EPSS 18%
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service po…
Infrasuite Device Master
00.00.02a+
CRITICAL 9.8
CVE-2022-40202
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker coul…
Infrasuite Device Master
00.00.02a+
HIGH 8.8
CVE-2022-41773EPSS 8%
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authe…
Diaenergie
1.9.01.002+
MEDIUM 5.4
CVE-2022-41651EPSS 11%
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.
Diaenergie
1.9.01.002+
MEDIUM 5.4
CVE-2022-41701EPSS 11%
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.
Diaenergie
1.9.01.002+
MEDIUM 5.4
CVE-2022-41702EPSS 11%
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg AP…
Diaenergie
1.9.01.002+
HIGH 8.8
CVE-2022-41133EPSS 27%
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListPara…
Diaenergie
1.9.01.002+
MEDIUM 5.4
CVE-2022-41555EPSS 11%
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessa…
Diaenergie
1.9.01.002+
HIGH 8.8
CVE-2022-40967EPSS 8%
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privile…
Diaenergie
1.9.01.002+
MEDIUM 5.4
CVE-2022-40965EPSS 11%
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyTy…
Diaenergie
1.9.01.002+
CRITICAL 9.8
CVE-2022-43774
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a…
Diaenergie
Mitigation only
CRITICAL 9.8
CVE-2022-43775EPSS 21%
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote…
Diaenergie
Mitigation only
CRITICAL 9.8
CVE-2022-3214
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions pr…
Diaenergie
1.9.03.009+
HIGH 8.6
CVE-2022-2759
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes a…
Delta Robot Automation Studio
1.13.20+
HIGH 7.8
CVE-2022-1405
CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buf…
Cncsoft
1.01.32+
HIGH 7.1
CVE-2022-1404
Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possi…
Cncsoft
1.01.32+
MEDIUM 6.1
CVE-2022-33005
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to ex…
Diaenergie
No fix yet
HIGH 7.8
CVE-2021-32965
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.
Diascreen
1.1.0+
HIGH 7.8
CVE-2021-32969
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow a…
Diascreen
1.1.0+
MEDIUM 5.5
CVE-2022-1331
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific p…
Dmars
2.1.10.24+
CRITICAL 9.8
CVE-2022-1367EPSS 19%
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an at…
Diaenergie
1.8.02.004+
CRITICAL 9.8
CVE-2022-1369
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker…
Diaenergie
1.8.02.004+
CRITICAL 9.8
CVE-2022-1370
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacke…
Diaenergie
1.8.02.004+
CRITICAL 9.8
CVE-2022-1371
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker t…
Diaenergie
1.8.02.004+
CRITICAL 9.8
CVE-2022-1372
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacke…
Diaenergie
1.8.02.004+
CRITICAL 9.8
CVE-2022-1374
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an…
Diaenergie
1.8.02.004+
CRITICAL 9.8
CVE-2022-1375
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows …
Diaenergie
1.8.02.004+
CRITICAL 9.8
CVE-2022-1376
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allo…
Diaenergie
1.8.02.004+
CRITICAL 9.8
CVE-2022-1377
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows a…
Diaenergie
1.8.02.004+