Diaenergie
by Deltaww
CVEs (46)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-57701 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting | ||
| CVE-2025-57700 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Stored Cross-site Scripting | ||
| CVE-2022-33005 | Med | 0.40 | 6.1 | 0.01 | Jun 27, 2022 | A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field. | ||
| CVE-2021-33003 | Med | 0.36 | 5.5 | 0.00 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm. | ||
| CVE-2024-28045 | Med | 0.30 | 4.6 | 0.00 | Mar 21, 2024 | Improper neutralization of input within the affected product could lead to cross-site scripting. | ||
| CVE-2021-32991 | Med | 0.28 | 4.3 | 0.00 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally. |
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Stored Cross-site Scripting
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.
- risk 0.36cvss 5.5epss 0.00
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.
- risk 0.30cvss 4.6epss 0.00
Improper neutralization of input within the affected product could lead to cross-site scripting.
- risk 0.28cvss 4.3epss 0.00
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.
Page 3 of 3