Skip to main content

Vendor/product archive

deltaww / diaenergie CVEs

Beta · best-effort

82 CVEs tagged to deltaww / diaenergie39 Critical, 35 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2022-1366

Published May 2, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-1098

Published Apr 1, 2022

Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27175

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26887

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_loopmapHandler.ashx. This allows an attacker to inject arbit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26839

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plan…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26836

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inje…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26667

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetDemandAnalysisData. This allows an attacker to inject arb…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26666

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerECC.ashx. This allows an attacker to inject arbitrary SQL…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26514

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_tagHandler.ashx. This allows an attacker to inject arbi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26349

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_eccoefficientHandler.ashx. This allows an attacker to i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26338

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerPageP_KID.ashx. This allows an attacker to inject arbitrar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26069

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26065

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in GetLatestDemandNode. This allows an attacker to inject arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26059

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetQueryData. This allows an attacker to inject arbitrary SQ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26013

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-25980

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-25880

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-25347

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0923

Published Mar 29, 2022

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject ar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0988

Published Mar 25, 2022

Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remo…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44544

Published Dec 22, 2021

DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerE…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44471

Published Dec 22, 2021

DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_H…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31558

Published Dec 22, 2021

DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23228

Published Dec 22, 2021

DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38393

Published Aug 30, 2021

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not pr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 51-75 of 82 CVEsPage 3 of 4