VYPR

Vendor CVEs

Delta Electronics

All CVEs

276 total · sorted by risk
  • CVE-2025-57703MedAug 18, 2025
    risk 0.40cvss 6.1epss 0.00

    DIAEnergie - Reflected Cross-site Scripting

  • CVE-2025-57702MedAug 18, 2025
    risk 0.40cvss 6.1epss 0.00

    DIAEnergie - Reflected Cross-site Scripting

  • CVE-2025-57701MedAug 18, 2025
    risk 0.40cvss 6.1epss 0.00

    DIAEnergie - Reflected Cross-site Scripting

  • CVE-2025-57700MedAug 18, 2025
    risk 0.40cvss 6.1epss 0.00

    DIAEnergie - Stored Cross-site Scripting

  • CVE-2022-33005MedJun 27, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.

  • CVE-2021-44768MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.

  • CVE-2025-58318MedSep 1, 2025
    risk 0.38cvss epss 0.00

    Delta Electronics DIAView has an authentication bypass vulnerability.

  • CVE-2021-38424MedNov 3, 2021
    risk 0.38cvss 5.9epss 0.00

    The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

  • CVE-2021-38488MedNov 3, 2021
    risk 0.37cvss 5.5epss 0.12

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.

  • CVE-2021-38428MedNov 3, 2021
    risk 0.37cvss 5.5epss 0.11

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.

  • CVE-2025-57704MedAug 26, 2025
    risk 0.36cvss 5.5epss 0.00

    Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.

  • CVE-2022-2759MedAug 31, 2022
    risk 0.36cvss 5.5epss 0.01

    Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control,…

  • CVE-2021-38411MedNov 3, 2021
    risk 0.36cvss 5.5epss 0.01

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.

  • CVE-2021-38407MedNov 3, 2021
    risk 0.36cvss 5.5epss 0.01

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.

  • CVE-2021-38403MedNov 3, 2021
    risk 0.36cvss 5.5epss 0.01

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.

  • CVE-2021-33003MedAug 30, 2021
    risk 0.36cvss 5.5epss 0.00

    Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

  • CVE-2021-27455MedJul 2, 2021
    risk 0.36cvss 5.5epss 0.01

    Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.

  • CVE-2019-10992MedJul 24, 2019
    risk 0.36cvss 5.5epss 0.01

    Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files.

  • CVE-2022-42141MedDec 14, 2022
    risk 0.35cvss 5.4epss 0.00

    Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.

  • CVE-2024-28045MedMar 21, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper neutralization of input within the affected product could lead to cross-site scripting.

  • CVE-2021-32991MedAug 30, 2021
    risk 0.28cvss 4.3epss 0.00

    Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.

  • CVE-2025-59301MedDec 22, 2025
    risk 0.26cvss 4.0epss 0.00

    Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.

  • CVE-2023-5461LowOct 9, 2023
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sensitive information. It is possible to launch the attack…

  • CVE-2023-5460LowOct 9, 2023
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some unknown processing of the component Modbus Data Packet Handler. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the…

  • CVE-2022-2966LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.

  • CVE-2022-1404LowAug 31, 2022
    risk 0.21cvss 3.3epss 0.00

    Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

Page 6 of 6