VYPR

DIAEnergie

by Delta Electronics

CVEs (23)

  • CVE-2021-32955CriAug 30, 2021
    risk 0.67cvss 9.8epss 0.37

    Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

  • CVE-2021-38393CriAug 30, 2021
    risk 0.65cvss 9.8epss 0.18

    A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as…

  • CVE-2021-38390CriAug 30, 2021
    risk 0.65cvss 9.8epss 0.20

    A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as…

  • CVE-2026-78308CriSep 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.

  • CVE-2021-38391CriAug 30, 2021
    risk 0.64cvss 9.8epss 0.03

    A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of…

  • CVE-2021-32983CriAug 30, 2021
    risk 0.64cvss 9.8epss 0.04

    A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part…

  • CVE-2021-32967CriAug 30, 2021
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.

  • CVE-2026-78312CriSep 24, 2026
    risk 0.59cvss 9.1epss 0.00

    Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

  • CVE-2026-78311HigSep 24, 2026
    risk 0.57cvss 8.8epss 0.00

    SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

  • CVE-2026-78309HigSep 24, 2026
    risk 0.57cvss 8.8epss 0.00

    SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

  • CVE-2026-78317HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

  • CVE-2026-78316HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

  • CVE-2026-78315HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

  • CVE-2026-78314HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

  • CVE-2026-78313MedSep 24, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

  • CVE-2025-57703MedAug 18, 2025
    risk 0.40cvss 6.1epss 0.00

    DIAEnergie - Reflected Cross-site Scripting

  • CVE-2025-57702MedAug 18, 2025
    risk 0.40cvss 6.1epss 0.00

    DIAEnergie - Reflected Cross-site Scripting

  • CVE-2025-57701MedAug 18, 2025
    risk 0.40cvss 6.1epss 0.00

    DIAEnergie - Reflected Cross-site Scripting

  • CVE-2025-57700MedAug 18, 2025
    risk 0.40cvss 6.1epss 0.00

    DIAEnergie - Stored Cross-site Scripting

  • CVE-2022-33005MedJun 27, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.

Page 1 of 2