Skip to main content

Vendor archive

deltaww CVEs

Beta · best-effort

293 CVEs tagged to vendor deltaww72 Critical, 183 High, 33 Medium, 5 Low, 0 Unrated.

CVE-2024-47966

Published Oct 10, 2024

Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulne…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47965

Published Oct 10, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to vis…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47964

Published Oct 10, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47963

Published Oct 10, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to vi…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47962

Published Oct 10, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an in…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43699

Published Oct 3, 2024

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records con…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-42417

Published Oct 3, 2024

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the ta…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8255

Published Aug 29, 2024

Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7502

Published Aug 6, 2024

A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39883

Published Jul 9, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious pa…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39882

Published Jul 9, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39881

Published Jul 9, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a malicious page or opens a malic…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39880

Published Jul 9, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. If a target visits a malicious p…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4549

Published May 6, 2024

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4548

Published May 6, 2024

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4547

Published May 6, 2024

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-34033

Published May 3, 2024

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file na…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34032

Published May 3, 2024

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to poten…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34031

Published May 3, 2024

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potent…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4192

Published Apr 30, 2024

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28171

Published Mar 21, 2024

It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the origina…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28045

Published Mar 21, 2024

Improper neutralization of input within the affected product could lead to cross-site scripting.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25567

Published Mar 21, 2024

Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file sys…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 51-75 of 293 CVEsPage 3 of 12