DIAEnergie
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32955 | Cri | 0.67 | 9.8 | 0.37 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code. | ||
| CVE-2021-38393 | Cri | 0.65 | 9.8 | 0.18 | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as… | ||
| CVE-2021-38390 | Cri | 0.65 | 9.8 | 0.20 | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as… | ||
| CVE-2026-78308 | Cri | 0.64 | 9.8 | 0.00 | Sep 24, 2026 | Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. | ||
| CVE-2021-38391 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of… | ||
| CVE-2021-32983 | Cri | 0.64 | 9.8 | 0.04 | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part… | ||
| CVE-2021-32967 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges. | ||
| CVE-2026-78312 | Cri | 0.59 | 9.1 | 0.00 | Sep 24, 2026 | Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. | ||
| CVE-2026-78311 | Hig | 0.57 | 8.8 | 0.00 | Sep 24, 2026 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. | ||
| CVE-2026-78309 | Hig | 0.57 | 8.8 | 0.00 | Sep 24, 2026 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. | ||
| CVE-2026-78317 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||
| CVE-2026-78316 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||
| CVE-2026-78315 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||
| CVE-2026-78314 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||
| CVE-2026-78313 | Med | 0.42 | 6.5 | 0.00 | Sep 24, 2026 | Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. | ||
| CVE-2025-57703 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting | ||
| CVE-2025-57702 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting | ||
| CVE-2025-57701 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting | ||
| CVE-2025-57700 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Stored Cross-site Scripting | ||
| CVE-2022-33005 | Med | 0.40 | 6.1 | 0.01 | Jun 27, 2022 | A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field. |
- risk 0.67cvss 9.8epss 0.37
Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.
- risk 0.65cvss 9.8epss 0.18
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as…
- risk 0.65cvss 9.8epss 0.20
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as…
- risk 0.64cvss 9.8epss 0.00
Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
- risk 0.64cvss 9.8epss 0.03
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of…
- risk 0.64cvss 9.8epss 0.04
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part…
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.
- risk 0.59cvss 9.1epss 0.00
Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
- risk 0.57cvss 8.8epss 0.00
SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
- risk 0.57cvss 8.8epss 0.00
SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
- risk 0.42cvss 6.5epss 0.00
Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Stored Cross-site Scripting
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.
Page 1 of 2