AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Delta Electronics
DE
Platform

Delta Electronics

IPC systems, VFDs, DIAView SCADA, and DVP/AS-series PLCs for comprehensive industrial automation solutions.

https://www.deltaww.com →
225
Total CVEs
0
Resources
62
CRIT
137
HIGH
21
MED
4
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
62 / 225
CVE-2025-58321CRITICAL

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Sep 11, 2025
10.0
CVE-2026-3630CRITICAL

Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.

Mar 9, 2026
9.8
CVE-2025-62582CRITICAL

Delta Electronics DIAView has multiple vulnerabilities.

Jan 16, 2026
9.8
CVE-2025-62581CRITICAL

Delta Electronics DIAView has multiple vulnerabilities.

Jan 16, 2026
9.8
CVE-2025-3495CRITICAL

Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.

Apr 16, 2025
9.8
CVE-2024-10456CRITICAL

Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.

Oct 30, 2024
9.8
CVE-2024-43699CRITICAL

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product.

Oct 3, 2024
9.8
CVE-2024-8255CRITICAL

Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.

Aug 29, 2024
9.8
CVE-2024-3871CRITICAL

The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices. This issue affects DVW-W02W2-E2 through version 2.5.2.

Apr 16, 2024
9.8
CVE-2023-47207CRITICAL

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.

Nov 30, 2023
9.8
CVE-2023-39226CRITICAL

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.

Nov 30, 2023
9.8
CVE-2023-1140CRITICAL

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.

Mar 27, 2023
9.8
CVE-2023-1136CRITICAL

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.

Mar 27, 2023
9.8
CVE-2023-1133CRITICAL

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

Mar 27, 2023
9.8
CVE-2022-41778CRITICAL

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.

Jan 13, 2023
9.8
CVE-2022-41772CRITICAL

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.

Oct 31, 2022
9.8
CVE-2022-41688CRITICAL

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group.

Oct 31, 2022
9.8
CVE-2022-41657CRITICAL

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations and could ultimately result in remote code execution.

Oct 31, 2022
9.8
CVE-2022-40202CRITICAL

The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution.

Oct 31, 2022
9.8
CVE-2022-38142CRITICAL

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.

Oct 31, 2022
9.8
CVE-2022-43775CRITICAL

The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

Oct 26, 2022
9.8
CVE-2022-43774CRITICAL

The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

Oct 26, 2022
9.8
CVE-2022-1378CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1377CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1376CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1375CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1374CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1372CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1371CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1370CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1369CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1367CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-1366CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

May 2, 2022
9.8
CVE-2022-27175CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26887CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_loopmapHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26836CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26667CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetDemandAnalysisData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26666CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerECC.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26514CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_tagHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26349CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_eccoefficientHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26338CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerPageP_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26069CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26065CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in GetLatestDemandNode. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26059CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetQueryData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-26013CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-25980CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-25880CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2022-25347CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

Mar 29, 2022
9.8
CVE-2022-0923CRITICAL

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Mar 29, 2022
9.8
CVE-2021-38393CRITICAL

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

Aug 30, 2021
9.8
CVE-2021-38391CRITICAL

A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

Aug 30, 2021
9.8
CVE-2021-38390CRITICAL

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

Aug 30, 2021
9.8
CVE-2021-32983CRITICAL

A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

Aug 30, 2021
9.8
CVE-2021-32967CRITICAL

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.

Aug 30, 2021
9.8
CVE-2021-32955CRITICAL

Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

Aug 30, 2021
9.8
CVE-2019-12899CRITICAL

Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem+0x00000000000005e3.

Jun 19, 2019
9.8
CVE-2019-12898CRITICAL

Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000000017a45e.

Jun 19, 2019
9.8
CVE-2018-10594CRITICAL

Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.

Jun 26, 2018
9.8
CVE-2018-10623CRITICAL

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buffer where the position can be determined by a value read from a .dpa file. This may cause improper restriction of operations within the bounds of the memory buffer, allow remote code execution, alter the intended control flow, allow reading of sensitive information, or cause the application to crash.

Jun 18, 2018
9.8
CVE-2018-10621CRITICAL

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow remote code execution or cause the application to crash.

Jun 18, 2018
9.8
CVE-2018-10617CRITICAL

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow remote code execution or cause the application to crash.

Jun 18, 2018
9.8
CVE-2018-8871CRITICAL

In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, which may allow remote code execution.

May 25, 2018
9.8
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2025-58321CRITICAL
10.0
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.Sep 11, 2025›
CVE-2026-3630CRITICAL
9.8
Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.Mar 9, 2026›
CVE-2025-62582CRITICAL
9.8
Delta Electronics DIAView has multiple vulnerabilities.Jan 16, 2026›
CVE-2025-62581CRITICAL
9.8
Delta Electronics DIAView has multiple vulnerabilities.Jan 16, 2026›
CVE-2025-3495CRITICAL
9.8
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CW…Apr 16, 2025›
CVE-2024-10456CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserializatio…Oct 30, 2024›
CVE-2024-43699CRITICAL
9.8
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An u…Oct 3, 2024›
CVE-2024-8255CRITICAL
9.8
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote co…Aug 29, 2024›
CVE-2024-3871CRITICAL
9.8
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This inte…Apr 16, 2024›
CVE-2023-47207CRITICAL
9.8
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthe…Nov 30, 2023›
CVE-2023-39226CRITICAL
9.8
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthe…Nov 30, 2023›
CVE-2023-1140CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that coul…Mar 27, 2023›
CVE-2023-1136CRITICAL
9.8
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker c…Mar 27, 2023›
CVE-2023-1133CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which …Mar 27, 2023›
CVE-2022-41778CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied d…Jan 13, 2023›
CVE-2022-41772CRITICAL
9.8
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives con…Oct 31, 2022›
CVE-2022-41688CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication …Oct 31, 2022›
CVE-2022-41657CRITICAL
9.8
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided dat…Oct 31, 2022›
CVE-2022-40202CRITICAL
9.8
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and p…Oct 31, 2022›
CVE-2022-38142CRITICAL
9.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied d…Oct 31, 2022›
CVE-2022-43775CRITICAL
9.8
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could all…Oct 26, 2022›
CVE-2022-43774CRITICAL
9.8
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that co…Oct 26, 2022›
CVE-2022-1378CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1377CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1376CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1375CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1374CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1372CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1371CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1370CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1369CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1367CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-1366CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…May 2, 2022›
CVE-2022-27175CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26887CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26836CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26667CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26666CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26514CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26349CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26338CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26069CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26065CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26059CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-26013CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-25980CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-25880CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2022-25347CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal atta…Mar 29, 2022›
CVE-2022-0923CRITICAL
9.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerabil…Mar 29, 2022›
CVE-2021-38393CRITICAL
9.8
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of De…Aug 30, 2021›
CVE-2021-38391CRITICAL
9.8
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta …Aug 30, 2021›
CVE-2021-38390CRITICAL
9.8
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of De…Aug 30, 2021›
CVE-2021-32983CRITICAL
9.8
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta El…Aug 30, 2021›
CVE-2021-32967CRITICAL
9.8
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrati…Aug 30, 2021›
CVE-2021-32955CRITICAL
9.8
Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may all…Aug 30, 2021›
CVE-2019-12899CRITICAL
9.8
Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem…Jun 19, 2019›
CVE-2019-12898CRITICAL
9.8
Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000…Jun 19, 2019›
CVE-2018-10594CRITICAL
9.8
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying …Jun 26, 2018›
CVE-2018-10623CRITICAL
9.8
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operat…Jun 18, 2018›
CVE-2018-10621CRITICAL
9.8
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-len…Jun 18, 2018›
CVE-2018-10617CRITICAL
9.8
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-len…Jun 18, 2018›
CVE-2018-8871CRITICAL
9.8
In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may…May 25, 2018›