AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Delta Electronics
DE
Platform

Delta Electronics

IPC systems, VFDs, DIAView SCADA, and DVP/AS-series PLCs for comprehensive industrial automation solutions.

https://www.deltaww.com →
225
Total CVEs
0
Resources
62
CRIT
137
HIGH
21
MED
4
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
225 entries
CVE-2025-58321CRITICAL

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Sep 11, 2025
10.0
CVE-2026-3630CRITICAL

Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.

Mar 9, 2026
9.8
CVE-2025-62582CRITICAL

Delta Electronics DIAView has multiple vulnerabilities.

Jan 16, 2026
9.8
CVE-2025-62581CRITICAL

Delta Electronics DIAView has multiple vulnerabilities.

Jan 16, 2026
9.8
CVE-2025-3495CRITICAL

Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.

Apr 16, 2025
9.8
CVE-2024-10456CRITICAL

Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.

Oct 30, 2024
9.8
CVE-2024-43699CRITICAL

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product.

Oct 3, 2024
9.8
CVE-2024-8255CRITICAL

Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.

Aug 29, 2024
9.8
CVE-2024-3871CRITICAL

The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices. This issue affects DVW-W02W2-E2 through version 2.5.2.

Apr 16, 2024
9.8
CVE-2023-47207CRITICAL

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.

Nov 30, 2023
9.8
CVE-2023-39226CRITICAL

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.

Nov 30, 2023
9.8
CVE-2023-1140CRITICAL

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.

Mar 27, 2023
9.8
CVE-2023-1136CRITICAL

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.

Mar 27, 2023
9.8
CVE-2023-1133CRITICAL

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

Mar 27, 2023
9.8
CVE-2022-41778CRITICAL

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.

Jan 13, 2023
9.8
CVE-2022-41772CRITICAL

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.

Oct 31, 2022
9.8
CVE-2022-41688CRITICAL

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group.

Oct 31, 2022
9.8
CVE-2022-41657CRITICAL

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations and could ultimately result in remote code execution.

Oct 31, 2022
9.8
CVE-2022-40202CRITICAL

The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution.

Oct 31, 2022
9.8
CVE-2022-38142CRITICAL

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.

Oct 31, 2022
9.8
CVE-2022-43775CRITICAL

The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

Oct 26, 2022
9.8
CVE-2022-43774CRITICAL

The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

Oct 26, 2022
9.8
CVE-2022-1378CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1377CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1376CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1375CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1374CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1372CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1371CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1370CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1369CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1367CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1366CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-27175CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26887CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_loopmapHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26836CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26667CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetDemandAnalysisData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26666CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerECC.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26514CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_tagHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26349CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_eccoefficientHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26338CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerPageP_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26069CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26065CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in GetLatestDemandNode. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26059CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetQueryData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26013CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-25980CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-25880CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-25347CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

Mar 29, 2022
9.8
CVE-2022-0923CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2021-38393CRITICAL

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

Aug 30, 2021
9.8
CVE-2021-38391CRITICAL

A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

Aug 30, 2021
9.8
CVE-2021-38390CRITICAL

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

Aug 30, 2021
9.8
CVE-2021-32983CRITICAL

A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

Aug 30, 2021
9.8
CVE-2021-32967CRITICAL

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.

Aug 30, 2021
9.8
CVE-2021-32955CRITICAL

Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

Aug 30, 2021
9.8
CVE-2019-12899CRITICAL

Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem+0x00000000000005e3.

Jun 19, 2019
9.8
CVE-2019-12898CRITICAL

Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000000017a45e.

Jun 19, 2019
9.8
CVE-2018-10594CRITICAL

Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.

Jun 26, 2018
9.8
CVE-2018-10623CRITICAL

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buffer where the position can be determined by a value read from a .dpa file. This may cause improper restriction of operations within the bounds of the memory buffer, allow remote code execution, alter the intended control flow, allow reading of sensitive information, or cause the application to crash.

Jun 18, 2018
9.8
CVE-2018-10621CRITICAL

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow remote code execution or cause the application to crash.

Jun 18, 2018
9.8
CVE-2018-10617CRITICAL

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow remote code execution or cause the application to crash.

Jun 18, 2018
9.8
CVE-2018-8871CRITICAL

In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, which may allow remote code execution.

May 25, 2018
9.8
CVE-2024-42417HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.

Oct 3, 2024
8.8
CVE-2024-39883HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Jul 9, 2024
8.8
CVE-2024-39882HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Jul 9, 2024
8.8
CVE-2024-39881HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Jul 9, 2024
8.8
CVE-2024-34033HIGH

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

May 3, 2024
8.8
CVE-2024-34032HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

May 3, 2024
8.8
CVE-2024-34031HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

May 3, 2024
8.8
CVE-2023-43824HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43823HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43822HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43821HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43820HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43819HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43818HIGH

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-46690HIGH

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.

Nov 30, 2023
8.8
CVE-2023-1144HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.

Mar 27, 2023
8.8
CVE-2023-1143HIGH

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.

Mar 27, 2023
8.8
CVE-2023-1141HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution.

Mar 27, 2023
8.8
CVE-2023-1139HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

Mar 27, 2023
8.8
CVE-2023-0444HIGH

A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator.

Jan 26, 2023
8.8
CVE-2022-42139HIGH

Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

Dec 14, 2022
8.8
CVE-2022-43506HIGH

SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-43457HIGH

SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-43452HIGH

SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-43447HIGH

SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-41775HIGH

SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-41779HIGH

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution.

Oct 31, 2022
8.8
CVE-2022-41644HIGH

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their own privileges.

Oct 31, 2022
8.8
CVE-2021-38418HIGH

Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.

Nov 3, 2021
8.8
CVE-2018-7509HIGH

WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of the intended buffer space, which could cause memory corruption or may allow remote code execution.

May 4, 2018
8.8
CVE-2018-7507HIGH

WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

May 4, 2018
8.8
CVE-2018-7494HIGH

WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

May 4, 2018
8.8
CVE-2025-53418HIGH

Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.

Aug 26, 2025
8.6
CVE-2023-5131HIGH

A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

Jan 18, 2024
8.2
CVE-2023-5130HIGH

A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

Jan 18, 2024
8.2
CVE-2026-3094HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Mar 4, 2026
7.8
CVE-2026-0975HIGH

Delta Electronics DIAView has Command Injection vulnerability.

Jan 16, 2026
7.8
CVE-2025-59300HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Oct 3, 2025
7.8
CVE-2025-59299HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Oct 3, 2025
7.8
CVE-2025-59298HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Oct 3, 2025
7.8
CVE-2025-59297HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Oct 3, 2025
7.8
CVE-2025-58319HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Sep 24, 2025
7.8
CVE-2025-58317HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Sep 24, 2025
7.8
CVE-2025-53419HIGH

Delta Electronics COMMGR has Code Injection vulnerability.

Aug 26, 2025
7.8
CVE-2025-53416HIGH

Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Jun 30, 2025
7.8
CVE-2025-53415HIGH

Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Jun 30, 2025
7.8
CVE-2025-4125HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

Apr 30, 2025
7.8
CVE-2025-4124HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

Apr 30, 2025
7.8
CVE-2025-22884HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

Apr 30, 2025
7.8
CVE-2025-22883HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

Apr 30, 2025
7.8
CVE-2025-22882HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.

Apr 30, 2025
7.8
CVE-2025-22881HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Feb 26, 2025
7.8
CVE-2025-22880HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Feb 7, 2025
7.8
CVE-2024-12836HIGH

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of STP files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22450.

Dec 30, 2024
7.8
CVE-2024-12835HIGH

Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICS files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22415.

Dec 30, 2024
7.8
CVE-2024-12834HIGH

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of STP files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22414.

Dec 30, 2024
7.8
CVE-2024-12677HIGH

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

Dec 20, 2024
7.8
CVE-2024-47131HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetObjectInfo can be exploited, allowing the attacker to remotely execute arbitrary code.

Nov 11, 2024
7.8
CVE-2024-39605HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetParameter can be exploited, allowing the attacker to remotely execute arbitrary code.

Nov 11, 2024
7.8
CVE-2024-39354HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in CEtherIPTagItem can be exploited, allowing the attacker to remotely execute arbitrary code.

Nov 11, 2024
7.8
CVE-2024-47966HIGH

Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-47965HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-47964HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-47963HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-47962HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-7502HIGH

A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

Aug 6, 2024
7.8
CVE-2024-39880HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Jul 9, 2024
7.8
CVE-2024-4192HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

Apr 30, 2024
7.8
CVE-2024-1941HIGH

Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

Mar 1, 2024
7.8
CVE-2024-1595HIGH

Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.

Feb 29, 2024
7.8
CVE-2023-5944HIGH

Delta Electronics DOPSoft is vulnerable to a stack-based buffer overflow, which may allow for arbitrary code execution if an attacker can lead a legitimate user to execute a specially crafted file.

Dec 4, 2023
7.8
CVE-2023-5068HIGH

Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file. This could allow an attacker to execute code in the context of the current process.

Sep 21, 2023
7.8
CVE-2023-4685HIGH

Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

Sep 7, 2023
7.8
CVE-2023-25177HIGH

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

Jun 7, 2023
7.8
CVE-2023-24014HIGH

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

Jun 7, 2023
7.8
CVE-2023-1145HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

Mar 27, 2023
7.8
CVE-2023-1135HIGH

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.

Mar 27, 2023
7.8
CVE-2023-0251HIGH

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restrictions of operations within memory, which could allow an attacker to remotely execute arbitrary code.

Feb 8, 2023
7.8
CVE-2023-0250HIGH

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.

Feb 8, 2023
7.8
CVE-2023-0249HIGH

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

Feb 8, 2023
7.8
CVE-2023-0124HIGH

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

Feb 3, 2023
7.8
CVE-2023-0123HIGH

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

Feb 3, 2023
7.8
CVE-2021-32969HIGH

Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow an attacker to remotely execute arbitrary code.

May 24, 2022
7.8
CVE-2021-32965HIGH

Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.

May 24, 2022
7.8
CVE-2022-1098HIGH

Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges

Apr 1, 2022
7.8
CVE-2022-26839HIGH

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.

Mar 29, 2022
7.8
CVE-2021-43982HIGH

Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

Dec 9, 2021
7.8
CVE-2021-38422HIGH

Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.

Nov 3, 2021
7.8
CVE-2021-38420HIGH

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

Nov 3, 2021
7.8
CVE-2021-38416HIGH

Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.

Nov 3, 2021
7.8
CVE-2021-33019HIGH

A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

Aug 30, 2021
7.8
CVE-2021-33007HIGH

A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code.

Aug 30, 2021
7.8
CVE-2021-27412HIGH

Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.

Jul 2, 2021
7.8
CVE-2021-22672HIGH

Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.

May 10, 2021
7.8
CVE-2020-27293HIGH

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27291HIGH

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27289HIGH

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27287HIGH

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27281HIGH

A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27277HIGH

Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27275HIGH

Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-16227HIGH

Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by processing a specially crafted project file not validated when the data is entered by a user. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16225HIGH

Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16223HIGH

Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16221HIGH

Delta Electronics TPEditor Versions 1.97 and prior. A stack-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16219HIGH

Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by processing specially crafted project files. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2019-13544HIGH

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files, which may allow remote code execution.

Sep 11, 2019
7.8
CVE-2019-13540HIGH

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

Sep 11, 2019
7.8
CVE-2019-13536HIGH

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

Sep 11, 2019
7.8
CVE-2019-10982HIGH

Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.

Jul 24, 2019
7.8
CVE-2018-14800HIGH

Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application to read past the boundary allocated to a stack object, which could allow execution of code under the context of the application.

Oct 3, 2018
7.8
CVE-2018-8839HIGH

Delta PMSoft versions 2.10 and prior have multiple stack-based buffer overflow vulnerabilities where a .ppm file can introduce a value larger than is readable by PMSoft's fixed-length stack buffer. This can cause the buffer to be overwritten, which may allow arbitrary code execution or cause the application to crash. CVSS v3 base score: 7.1; CVSS vector string: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H. Delta Electronics recommends affected users update to at least PMSoft v2.11, which was made available as of March 22, 2018, or the latest available version.

Apr 30, 2018
7.8
CVE-2018-5476HIGH

A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.00.01 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dop or .dpb files may allow an attacker to remotely execute arbitrary code.

Mar 15, 2018
7.8
CVE-2017-16751HIGH

A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dpb files may allow an attacker to remotely execute arbitrary code.

Mar 15, 2018
7.8
CVE-2017-16749HIGH

A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files could exploit a use-after-free vulnerability.

Mar 15, 2018
7.8
CVE-2017-16747HIGH

An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

Mar 15, 2018
7.8
CVE-2017-16745HIGH

A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. An access of resource using incompatible type ('type confusion') vulnerability may allow an attacker to execute remote code when processing specially crafted .dpb files.

Mar 15, 2018
7.8
CVE-2016-5805HIGH

An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of arbitrary code or a denial of service.

Feb 13, 2017
7.8
CVE-2016-5802HIGH

An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to 2.10.10. Multiple instances of out-of-bounds write conditions may allow malicious files to be read and executed by the affected software.

Feb 13, 2017
7.8
CVE-2026-3631HIGH

Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.

Mar 9, 2026
7.5
CVE-2024-4549HIGH

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

May 6, 2024
7.5
CVE-2023-43817HIGH

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

Jan 18, 2024
7.5
CVE-2023-47279HIGH

In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.

Nov 30, 2023
7.5
CVE-2023-1142HIGH

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.

Mar 27, 2023
7.5
CVE-2023-1138HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.

Mar 27, 2023
7.5
CVE-2022-41776HIGH

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the changing of administrative passwords.

Oct 31, 2022
7.5
CVE-2022-41629HIGH

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.

Oct 31, 2022
7.5
CVE-2025-58320HIGH

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Sep 11, 2025
7.3
CVE-2025-47728HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2025-47727HIGH

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2025-47726HIGH

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2025-47725HIGH

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2025-47724HIGH

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2022-42140HIGH

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

Dec 14, 2022
7.2
CVE-2023-43815HIGH

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

Jan 18, 2024
7.1
CVE-2023-1134HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.

Mar 27, 2023
7.1
CVE-2022-0988HIGH

Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.

Mar 25, 2022
7.1
CVE-2023-5459MEDIUM

A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. VDB-241582 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Oct 9, 2023
6.5
CVE-2023-34316MEDIUM

​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.

Jul 10, 2023
6.5
CVE-2023-1137MEDIUM

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.

Mar 27, 2023
6.5
CVE-2018-14824MEDIUM

Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be executed when processing project files, which may allow an attacker to read confidential information.

Sep 27, 2018
6.5
CVE-2023-43816MEDIUM

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

Jan 18, 2024
6.3
CVE-2022-33005MEDIUM

A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.

Jun 27, 2022
6.1
CVE-2021-44768MEDIUM

Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.

Mar 25, 2022
6.1
CVE-2021-38424MEDIUM

The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

Nov 3, 2021
5.9
CVE-2025-57704MEDIUM

Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.

Aug 26, 2025
5.5
CVE-2022-2759MEDIUM

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

Aug 31, 2022
5.5
CVE-2021-38488MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-38428MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-38411MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-38407MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-38403MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-33003MEDIUM

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

Aug 30, 2021
5.5
CVE-2021-27455MEDIUM

Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.

Jul 2, 2021
5.5
CVE-2019-10992MEDIUM

Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files.

Jul 24, 2019
5.5
CVE-2022-42141MEDIUM

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.

Dec 14, 2022
5.4
CVE-2021-32991MEDIUM

Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.

Aug 30, 2021
4.3
CVE-2025-59301MEDIUM

Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.

Dec 22, 2025
4.0
CVE-2023-5461LOW

A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241584. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Oct 9, 2023
3.7
CVE-2023-5460LOW

A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some unknown processing of the component Modbus Data Packet Handler. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-241583. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Oct 9, 2023
3.5
CVE-2022-2966LOW

Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.

Dec 16, 2022
3.3
CVE-2022-1404LOW

Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

Aug 31, 2022
3.3
CVE-2025-58318Awaiting Analysis

Delta Electronics DIAView has an authentication bypass vulnerability.

Sep 1, 2025
0.0
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2025-58321CRITICAL
10.0
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.Sep 11, 2025›
CVE-2026-3630CRITICAL
9.8
Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.Mar 9, 2026›
CVE-2025-62582CRITICAL
9.8
Delta Electronics DIAView has multiple vulnerabilities.Jan 16, 2026›
CVE-2025-62581CRITICAL
9.8
Delta Electronics DIAView has multiple vulnerabilities.Jan 16, 2026›
CVE-2025-3495CRITICAL
9.8
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CW…Apr 16, 2025›
CVE-2024-10456CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserializatio…Oct 30, 2024›
CVE-2024-43699CRITICAL
9.8
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An u…Oct 3, 2024›
CVE-2024-8255CRITICAL
9.8
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote co…Aug 29, 2024›
CVE-2024-3871CRITICAL
9.8
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This inte…Apr 16, 2024›
CVE-2023-47207CRITICAL
9.8
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthe…Nov 30, 2023›
CVE-2023-39226CRITICAL
9.8
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthe…Nov 30, 2023›
CVE-2023-1140CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that coul…Mar 27, 2023›
CVE-2023-1136CRITICAL
9.8
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker c…Mar 27, 2023›
CVE-2023-1133CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which …Mar 27, 2023›
CVE-2022-41778CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied d…Jan 13, 2023›
CVE-2022-41772CRITICAL
9.8
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives con…Oct 31, 2022›
CVE-2022-41688CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication …Oct 31, 2022›
CVE-2022-41657CRITICAL
9.8
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided dat…Oct 31, 2022›
CVE-2022-40202CRITICAL
9.8
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and p…Oct 31, 2022›
CVE-2022-38142CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied d…Oct 31, 2022›
CVE-2022-43775CRITICAL
9.8
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could all…Oct 26, 2022›
CVE-2022-43774CRITICAL
9.8
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that co…Oct 26, 2022›
CVE-2022-1378CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1377CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1376CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1375CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1374CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1372CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1371CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1370CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1369CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1367CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1366CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-27175CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26887CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26836CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26667CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26666CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26514CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26349CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26338CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26069CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26065CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26059CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26013CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-25980CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-25880CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-25347CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal atta…Mar 29, 2022›
CVE-2022-0923CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2021-38393CRITICAL
9.8
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of De…Aug 30, 2021›
CVE-2021-38391CRITICAL
9.8
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta …Aug 30, 2021›
CVE-2021-38390CRITICAL
9.8
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of De…Aug 30, 2021›
CVE-2021-32983CRITICAL
9.8
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta El…Aug 30, 2021›
CVE-2021-32967CRITICAL
9.8
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrati…Aug 30, 2021›
CVE-2021-32955CRITICAL
9.8
Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may all…Aug 30, 2021›
CVE-2019-12899CRITICAL
9.8
Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem…Jun 19, 2019›
CVE-2019-12898CRITICAL
9.8
Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000…Jun 19, 2019›
CVE-2018-10594CRITICAL
9.8
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying …Jun 26, 2018›
CVE-2018-10623CRITICAL
9.8
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operat…Jun 18, 2018›
CVE-2018-10621CRITICAL
9.8
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-len…Jun 18, 2018›
CVE-2018-10617CRITICAL
9.8
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-len…Jun 18, 2018›
CVE-2018-8871CRITICAL
9.8
In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may…May 25, 2018›
CVE-2024-42417HIGH
8.8
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An au…Oct 3, 2024›
CVE-2024-39883HIGH
8.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Jul 9, 2024›
CVE-2024-39882HIGH
8.8
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a re…Jul 9, 2024›
CVE-2024-39881HIGH
8.8
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a me…Jul 9, 2024›
CVE-2024-34033HIGH
8.8
Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a…May 3, 2024›
CVE-2024-34032HIGH
8.8
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the Get…May 3, 2024›
CVE-2024-34031HIGH
8.8
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the scr…May 3, 2024›
CVE-2023-43824HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43823HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43822HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43821HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43820HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43819HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43818HIGH
8.8
A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthe…Jan 18, 2024›
CVE-2023-46690HIGH
8.8
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacke…Nov 30, 2023›
CVE-2023-1144HIGH
8.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access contr…Mar 27, 2023›
CVE-2023-1143HIGH
8.8
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scr…Mar 27, 2023›
CVE-2023-1141HIGH
8.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulne…Mar 27, 2023›
CVE-2023-1139HIGH
8.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization…Mar 27, 2023›
CVE-2023-0444HIGH
8.8
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a.…Jan 26, 2023›
CVE-2022-42139HIGH
8.8
Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.Dec 14, 2022›
CVE-2022-43506HIGH
8.8
SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.0…Nov 17, 2022›
CVE-2022-43457HIGH
8.8
SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to …Nov 17, 2022›
CVE-2022-43452HIGH
8.8
SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to…Nov 17, 2022›
CVE-2022-43447HIGH
8.8
SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v…Nov 17, 2022›
CVE-2022-41775HIGH
8.8
SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.…Nov 17, 2022›
CVE-2022-41779HIGH
8.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets…Oct 31, 2022›
CVE-2022-41644HIGH
8.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for …Oct 31, 2022›
CVE-2021-38418HIGH
8.8
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an att…Nov 3, 2021›
CVE-2018-7509HIGH
8.8
WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of…May 4, 2018›
CVE-2018-7507HIGH
8.8
WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a v…May 4, 2018›
CVE-2018-7494HIGH
8.8
WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a …May 4, 2018›
CVE-2025-53418HIGH
8.6
Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.Aug 26, 2025›
CVE-2023-5131HIGH
8.2
A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this v…Jan 18, 2024›
CVE-2023-5130HIGH
8.2
A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can explo…Jan 18, 2024›
CVE-2026-3094HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a ma…Mar 4, 2026›
CVE-2026-0975HIGH
7.8
Delta Electronics DIAView has Command Injection vulnerability.Jan 16, 2026›
CVE-2025-59300HIGH
7.8
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a mal…Oct 3, 2025›
CVE-2025-59299HIGH
7.8
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a mal…Oct 3, 2025›
CVE-2025-59298HIGH
7.8
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a mal…Oct 3, 2025›
CVE-2025-59297HIGH
7.8
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a mal…Oct 3, 2025›
CVE-2025-58319HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a ma…Sep 24, 2025›
CVE-2025-58317HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a ma…Sep 24, 2025›
CVE-2025-53419HIGH
7.8
Delta Electronics COMMGR has Code Injection vulnerability.Aug 26, 2025›
CVE-2025-53416HIGH
7.8
Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execut…Jun 30, 2025›
CVE-2025-53415HIGH
7.8
Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execut…Jun 30, 2025›
CVE-2025-4125HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that co…Apr 30, 2025›
CVE-2025-4124HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that co…Apr 30, 2025›
CVE-2025-22884HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability …Apr 30, 2025›
CVE-2025-22883HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that co…Apr 30, 2025›
CVE-2025-22882HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability …Apr 30, 2025›
CVE-2025-22881HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Feb 26, 2025›
CVE-2025-22880HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Feb 7, 2025›
CVE-2024-12836HIGH
7.8
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. Th…Dec 30, 2024›
CVE-2024-12835HIGH
7.8
Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilit…Dec 30, 2024›
CVE-2024-12834HIGH
7.8
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. Th…Dec 30, 2024›
CVE-2024-12677HIGH
7.8
Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary …Dec 20, 2024›
CVE-2024-47131HIGH
7.8
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing m…Nov 11, 2024›
CVE-2024-39605HIGH
7.8
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing m…Nov 11, 2024›
CVE-2024-39354HIGH
7.8
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing m…Nov 11, 2024›
CVE-2024-47966HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacke…Oct 10, 2024›
CVE-2024-47965HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a re…Oct 10, 2024›
CVE-2024-47964HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Oct 10, 2024›
CVE-2024-47963HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a wr…Oct 10, 2024›
CVE-2024-47962HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Oct 10, 2024›
CVE-2024-7502HIGH
7.8
A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which c…Aug 6, 2024›
CVE-2024-39880HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Jul 9, 2024›
CVE-2024-4192HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to c…Apr 30, 2024›
CVE-2024-1941HIGH
7.8
Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overf…Mar 1, 2024›
CVE-2024-1595HIGH
7.8
Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow…Feb 29, 2024›
CVE-2023-5944HIGH
7.8
Delta Electronics DOPSoft is vulnerable to a stack-based buffer overflow, which may allow for arbit…Dec 4, 2023›
CVE-2023-5068HIGH
7.8
Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially…Sep 21, 2023›
CVE-2023-4685HIGH
7.8
Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable …Sep 7, 2023›
CVE-2023-25177HIGH
7.8
Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to stack-based buff…Jun 7, 2023›
CVE-2023-24014HIGH
7.8
Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer…Jun 7, 2023›
CVE-2023-1145HIGH
7.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserial…Mar 27, 2023›
CVE-2023-1135HIGH
7.8
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an a…Mar 27, 2023›
CVE-2023-0251HIGH
7.8
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through …Feb 8, 2023›
CVE-2023-0250HIGH
7.8
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overf…Feb 8, 2023›
CVE-2023-0249HIGH
7.8
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which…Feb 8, 2023›
CVE-2023-0124HIGH
7.8
Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, wh…Feb 3, 2023›
CVE-2023-0123HIGH
7.8
Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overf…Feb 3, 2023›
CVE-2021-32969HIGH
7.8
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write conditi…May 24, 2022›
CVE-2021-32965HIGH
7.8
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allo…May 24, 2022›
CVE-2022-1098HIGH
7.8
Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking co…Apr 1, 2022›
CVE-2022-26839HIGH
7.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect defaul…Mar 29, 2022›
CVE-2021-43982HIGH
7.8
Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow…Dec 9, 2021›
CVE-2021-38422HIGH
7.8
Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, whic…Nov 3, 2021›
CVE-2021-38420HIGH
7.8
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions …Nov 3, 2021›
CVE-2021-38416HIGH
7.8
Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an …Nov 3, 2021›
CVE-2021-33019HIGH
7.8
A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior m…Aug 30, 2021›
CVE-2021-33007HIGH
7.8
A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by p…Aug 30, 2021›
CVE-2021-27412HIGH
7.8
Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, whic…Jul 2, 2021›
CVE-2021-22672HIGH
7.8
Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of …May 10, 2021›
CVE-2020-27293HIGH
7.8
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing p…Jan 11, 2021›
CVE-2020-27291HIGH
7.8
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while …Jan 11, 2021›
CVE-2020-27289HIGH
7.8
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while pr…Jan 11, 2021›
CVE-2020-27287HIGH
7.8
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while…Jan 11, 2021›
CVE-2020-27281HIGH
7.8
A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 a…Jan 11, 2021›
CVE-2020-27277HIGH
7.8
Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while proc…Jan 11, 2021›
CVE-2020-27275HIGH
7.8
Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while p…Jan 11, 2021›
CVE-2020-16227HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by…Aug 7, 2020›
CVE-2020-16225HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by…Aug 7, 2020›
CVE-2020-16223HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by…Aug 7, 2020›
CVE-2020-16221HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. A stack-based buffer overflow may be exploited b…Aug 7, 2020›
CVE-2020-16219HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by proces…Aug 7, 2020›
CVE-2019-13544HIGH
7.8
Delta Electronics TPEditor, Versions 1.94 and prior. Multiple out-of-bounds write vulnerabilities ma…Sep 11, 2019›
CVE-2019-13540HIGH
7.8
Delta Electronics TPEditor, Versions 1.94 and prior. Multiple stack-based buffer overflow vulnerabil…Sep 11, 2019›
CVE-2019-13536HIGH
7.8
Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabili…Sep 11, 2019›
CVE-2019-10982HIGH
7.8
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overf…Jul 24, 2019›
CVE-2018-14800HIGH
7.8
Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to c…Oct 3, 2018›
CVE-2018-8839HIGH
7.8
Delta PMSoft versions 2.10 and prior have multiple stack-based buffer overflow vulnerabilities where…Apr 30, 2018›
CVE-2018-5476HIGH
7.8
A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation …Mar 15, 2018›
CVE-2017-16751HIGH
7.8
A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation …Mar 15, 2018›
CVE-2017-16749HIGH
7.8
A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor…Mar 15, 2018›
CVE-2017-16747HIGH
7.8
An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen …Mar 15, 2018›
CVE-2017-16745HIGH
7.8
A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor…Mar 15, 2018›
CVE-2016-5805HIGH
7.8
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions …Feb 13, 2017›
CVE-2016-5802HIGH
7.8
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions …Feb 13, 2017›
CVE-2026-3631HIGH
7.5
Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.Mar 9, 2026›
CVE-2024-4549HIGH
7.5
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. Whe…May 6, 2024›
CVE-2023-43817HIGH
7.5
A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when par…Jan 18, 2024›
CVE-2023-47279HIGH
7.5
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthe…Nov 30, 2023›
CVE-2023-1142HIGH
7.5
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL dec…Mar 27, 2023›
CVE-2023-1138HIGH
7.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access contro…Mar 27, 2023›
CVE-2022-41776HIGH
7.5
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users…Oct 31, 2022›
CVE-2022-41629HIGH
7.5
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users…Oct 31, 2022›
CVE-2025-58320HIGH
7.3
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.Sep 11, 2025›
CVE-2025-47728HIGH
7.3
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a ma…Jun 4, 2025›
CVE-2025-47727HIGH
7.3
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malic…Jun 4, 2025›
CVE-2025-47726HIGH
7.3
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malic…Jun 4, 2025›
CVE-2025-47725HIGH
7.3
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malic…Jun 4, 2025›
CVE-2025-47724HIGH
7.3
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malic…Jun 4, 2025›
CVE-2022-42140HIGH
7.2
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.Dec 14, 2022›
CVE-2023-43815HIGH
7.1
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft vers…Jan 18, 2024›
CVE-2023-1134HIGH
7.1
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal …Mar 27, 2023›
CVE-2022-0988HIGH
7.1
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as th…Mar 25, 2022›
CVE-2023-5459MEDIUM
6.5
A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. Th…Oct 9, 2023›
CVE-2023-34316MEDIUM
6.5
​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1…Jul 10, 2023›
CVE-2023-1137MEDIUM
6.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which …Mar 27, 2023›
CVE-2018-14824MEDIUM
6.5
Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulner…Sep 27, 2018›
CVE-2023-43816MEDIUM
6.3
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft vers…Jan 18, 2024›
CVE-2022-33005MEDIUM
6.1
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Elect…Jun 27, 2022›
CVE-2021-44768MEDIUM
6.1
Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while …Mar 25, 2022›
CVE-2021-38424MEDIUM
5.9
The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attack…Nov 3, 2021›
CVE-2025-57704MEDIUM
5.5
Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Proce…Aug 26, 2025›
CVE-2022-2759MEDIUM
5.5
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by imp…Aug 31, 2022›
CVE-2021-38488MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-38428MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-38411MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-38407MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-38403MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-33003MEDIUM
5.5
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in …Aug 30, 2021›
CVE-2021-27455MEDIUM
5.5
Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while…Jul 2, 2021›
CVE-2019-10992MEDIUM
5.5
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vuln…Jul 24, 2019›
CVE-2022-42141MEDIUM
5.4
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter…Dec 14, 2022›
CVE-2021-32991MEDIUM
4.3
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, wh…Aug 30, 2021›
CVE-2025-59301MEDIUM
4.0
Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denia…Dec 22, 2025›
CVE-2023-5461LOW
3.7
A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. …Oct 9, 2023›
CVE-2023-5460LOW
3.5
A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. Thi…Oct 9, 2023›
CVE-2022-2966LOW
3.3
Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versio…Dec 16, 2022›
CVE-2022-1404LOW
3.3
Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while pro…Aug 31, 2022›
CVE-2025-58318Awaiting Analysis
0.0
Delta Electronics DIAView has an authentication bypass vulnerability.Sep 1, 2025›