Vendor CVEs
Deltaww
All CVEs
293 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47725 | Hig | 0.47 | 7.3 | 0.00 | Jun 4, 2025 | Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | ||
| CVE-2025-47724 | Hig | 0.47 | 7.3 | 0.00 | Jun 4, 2025 | Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | ||
| CVE-2022-4616 | Hig | 0.47 | 7.2 | 0.05 | Jan 13, 2023 | The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions. | ||
| CVE-2022-42140 | Hig | 0.47 | 7.2 | 0.02 | Dec 14, 2022 | Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose. | ||
| CVE-2023-43815 | Hig | 0.46 | 7.1 | 0.01 | Jan 18, 2024 | A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to… | ||
| CVE-2023-1134 | Hig | 0.46 | 7.1 | 0.01 | Mar 27, 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges. | ||
| CVE-2022-0988 | Hig | 0.46 | 7.1 | 0.01 | Mar 25, 2022 | Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product. | ||
| CVE-2020-10597 | Hig | 0.46 | 7.1 | 0.01 | Mar 20, 2020 | Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information and/or crash the application. | ||
| CVE-2021-31558 | Med | 0.43 | 6.5 | 0.11 | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”. | ||
| CVE-2023-5459 | Med | 0.42 | 6.5 | 0.01 | Oct 9, 2023 | A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and… | ||
| CVE-2023-34316 | Med | 0.42 | 6.5 | 0.01 | Jul 10, 2023 | An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents. | ||
| CVE-2023-1137 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation. | ||
| CVE-2018-14824 | Med | 0.42 | 6.5 | 0.02 | Sep 27, 2018 | Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be executed when processing project files, which may allow an attacker to read confidential information. | ||
| CVE-2023-43816 | Med | 0.41 | 6.3 | 0.00 | Jan 18, 2024 | A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve… | ||
| CVE-2025-57703 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting | ||
| CVE-2025-57702 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting | ||
| CVE-2025-57701 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting | ||
| CVE-2025-57700 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Stored Cross-site Scripting | ||
| CVE-2022-33005 | Med | 0.40 | 6.1 | 0.01 | Jun 27, 2022 | A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field. | ||
| CVE-2021-44768 | Med | 0.40 | 6.1 | 0.01 | Mar 25, 2022 | Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information. | ||
| CVE-2021-38424 | Med | 0.38 | 5.9 | 0.00 | Nov 3, 2021 | The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application. | ||
| CVE-2021-38488 | Med | 0.37 | 5.5 | 0.12 | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code. | ||
| CVE-2021-38428 | Med | 0.37 | 5.5 | 0.11 | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code. | ||
| CVE-2022-2759 | Med | 0.36 | 5.5 | 0.01 | Aug 31, 2022 | Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control,… | ||
| CVE-2022-1331 | Med | 0.36 | 5.5 | 0.01 | May 3, 2022 | In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure. | ||
| CVE-2021-38411 | Med | 0.36 | 5.5 | 0.01 | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code. | ||
| CVE-2021-38407 | Med | 0.36 | 5.5 | 0.01 | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code. | ||
| CVE-2021-38403 | Med | 0.36 | 5.5 | 0.01 | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code. | ||
| CVE-2021-33003 | Med | 0.36 | 5.5 | 0.00 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm. | ||
| CVE-2021-27455 | Med | 0.36 | 5.5 | 0.01 | Jul 2, 2021 | Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information. | ||
| CVE-2020-6976 | Med | 0.36 | 5.5 | 0.01 | Mar 18, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation. | ||
| CVE-2019-10992 | Med | 0.36 | 5.5 | 0.01 | Jul 24, 2019 | Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files. | ||
| CVE-2019-10949 | Med | 0.36 | 5.5 | 0.02 | Apr 17, 2019 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnerabilities may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files. | ||
| CVE-2019-6547 | Med | 0.36 | 5.5 | 0.01 | Feb 28, 2019 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.84 and prior. An out-of-bounds read vulnerability may cause the software to crash due to lacking user input validation for processing project files. | ||
| CVE-2022-42141 | Med | 0.35 | 5.4 | 0.00 | Dec 14, 2022 | Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter. | ||
| CVE-2024-28045 | Med | 0.30 | 4.6 | 0.00 | Mar 21, 2024 | Improper neutralization of input within the affected product could lead to cross-site scripting. | ||
| CVE-2021-32991 | Med | 0.28 | 4.3 | 0.00 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally. | ||
| CVE-2025-59301 | Med | 0.26 | 4.0 | 0.00 | Dec 22, 2025 | Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service. | ||
| CVE-2023-5461 | Low | 0.24 | 3.7 | 0.00 | Oct 9, 2023 | A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sensitive information. It is possible to launch the attack… | ||
| CVE-2023-5460 | Low | 0.23 | 3.5 | 0.00 | Oct 9, 2023 | A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some unknown processing of the component Modbus Data Packet Handler. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the… | ||
| CVE-2020-16201 | Low | 0.22 | 3.3 | 0.01 | Aug 4, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information. | ||
| CVE-2022-2966 | Low | 0.21 | 3.3 | 0.00 | Dec 16, 2022 | Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions. | ||
| CVE-2022-1404 | Low | 0.21 | 3.3 | 0.00 | Aug 31, 2022 | Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition. |
- risk 0.47cvss 7.3epss 0.00
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
- risk 0.47cvss 7.3epss 0.00
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
- risk 0.47cvss 7.2epss 0.05
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions.
- risk 0.47cvss 7.2epss 0.02
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.
- risk 0.46cvss 7.1epss 0.01
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to…
- risk 0.46cvss 7.1epss 0.01
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.
- risk 0.46cvss 7.1epss 0.01
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
- risk 0.46cvss 7.1epss 0.01
Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information and/or crash the application.
- risk 0.43cvss 6.5epss 0.11
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.
- risk 0.42cvss 6.5epss 0.01
A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and…
- risk 0.42cvss 6.5epss 0.01
An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.
- risk 0.42cvss 6.5epss 0.01
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.
- risk 0.42cvss 6.5epss 0.02
Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be executed when processing project files, which may allow an attacker to read confidential information.
- risk 0.41cvss 6.3epss 0.00
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve…
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Stored Cross-site Scripting
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.
- risk 0.40cvss 6.1epss 0.01
Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.
- risk 0.38cvss 5.9epss 0.00
The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.
- risk 0.37cvss 5.5epss 0.12
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.
- risk 0.37cvss 5.5epss 0.11
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.
- risk 0.36cvss 5.5epss 0.01
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control,…
- risk 0.36cvss 5.5epss 0.01
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.
- risk 0.36cvss 5.5epss 0.01
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.
- risk 0.36cvss 5.5epss 0.01
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.
- risk 0.36cvss 5.5epss 0.01
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.
- risk 0.36cvss 5.5epss 0.00
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.
- risk 0.36cvss 5.5epss 0.01
Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.
- risk 0.36cvss 5.5epss 0.01
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation.
- risk 0.36cvss 5.5epss 0.01
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files.
- risk 0.36cvss 5.5epss 0.02
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnerabilities may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files.
- risk 0.36cvss 5.5epss 0.01
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.84 and prior. An out-of-bounds read vulnerability may cause the software to crash due to lacking user input validation for processing project files.
- risk 0.35cvss 5.4epss 0.00
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.
- risk 0.30cvss 4.6epss 0.00
Improper neutralization of input within the affected product could lead to cross-site scripting.
- risk 0.28cvss 4.3epss 0.00
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.
- risk 0.26cvss 4.0epss 0.00
Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.
- risk 0.24cvss 3.7epss 0.00
A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sensitive information. It is possible to launch the attack…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some unknown processing of the component Modbus Data Packet Handler. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the…
- risk 0.22cvss 3.3epss 0.01
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information.
- risk 0.21cvss 3.3epss 0.00
Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.
- risk 0.21cvss 3.3epss 0.00
Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.
Page 6 of 6