Vulnerabilities > Deltaww

DATE CVE VULNERABILITY TITLE RISK
2021-12-22 CVE-2021-23228 Cross-site Scripting vulnerability in Deltaww Diaenergie 1.7.5
DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.
network
deltaww CWE-79
4.3
2021-12-22 CVE-2021-31558 Cross-site Scripting vulnerability in Deltaww Diaenergie 1.7.5
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.
network
deltaww CWE-79
4.3
2021-12-22 CVE-2021-44471 Cross-site Scripting vulnerability in Deltaww Diaenergie 1.7.5
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.
network
deltaww CWE-79
4.3
2021-12-22 CVE-2021-44544 Cross-site Scripting vulnerability in Deltaww Diaenergie 1.7.5
DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”.
network
deltaww CWE-79
4.3
2021-12-09 CVE-2021-43982 Stack-based Buffer Overflow vulnerability in Deltaww Cncsoft 1.00.83
Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
network
deltaww CWE-121
6.8
2021-11-03 CVE-2021-38403 Cross-site Scripting vulnerability in Deltaww Dialink 1.2.4.0
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.
network
deltaww CWE-79
3.5
2021-11-03 CVE-2021-38407 Cross-site Scripting vulnerability in Deltaww Dialink 1.2.4.0
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.
network
deltaww CWE-79
3.5
2021-11-03 CVE-2021-38411 Cross-site Scripting vulnerability in Deltaww Dialink 1.2.4.0
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.
network
deltaww CWE-79
3.5
2021-11-03 CVE-2021-38416 Uncontrolled Search Path Element vulnerability in Deltaww Dialink 1.2.4.0
Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.
4.4
2021-11-03 CVE-2021-38418 Cleartext Transmission of Sensitive Information vulnerability in Deltaww Dialink 1.2.4.0
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.
network
deltaww CWE-319
4.3