VendorsDeltawwdiaenergieany version
Vulnerabilities

Deltaww Delta Electronics DIAEnergie any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

76CVEs
CVE-2021-38390
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
Published 2021-08-30 · Modified
10.0EPSS 0.198
CVE-2022-1366
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.193
CVE-2022-1367
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.193
CVE-2022-1378
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.193
CVE-2021-38393
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
Published 2021-08-30 · Modified
10.0EPSS 0.185
CVE-2022-26887
Delta Electronics DIAEnergie SQL Injection in DIAE_HandlerTag_KID.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.097
CVE-2022-26013
Delta Electronics DIAEnergie SQL Injection in DIAE_dmdsetHandler.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.091
CVE-2021-32983
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
Published 2021-08-30 · Modified
10.0EPSS 0.039
CVE-2021-38391
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
Published 2021-08-30 · Modified
10.0EPSS 0.035
CVE-2021-32967
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.
Published 2021-08-30 · Modified
10.0EPSS 0.014
CVE-2022-26349
Delta Electronics DIAEnergie SQL Injection in DIAE_eccoefficientHandler.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-26069
Delta Electronics DIAEnergie SQL Injection in HandlerPage_KID.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-26338
Delta Electronics DIAEnergie SQL Injection in DIAE_hierarchyHandler.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-26667
Delta Electronics DIAEnergie SQL Injection in GetDemandAnalysisData
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-26666
Delta Electronics DIAEnergie SQL Injection in HandlerDialogECC.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-1370
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.012
CVE-2022-26836
Delta Electronics DIAEnergie SQL Injection in HandlerExport.ashx/Calendar.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-1369
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.012
CVE-2022-1374
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.012
CVE-2022-1375
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.012
CVE-2022-1376
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.012
CVE-2022-26514
Delta Electronics DIAEnergie SQL Injection in DIAE_tagHandler.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-1377
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.012
CVE-2022-1371
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.012
CVE-2022-25880
Delta Electronics DIAEnergie SQL Injection in DIAE_hierarchyHandler.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-25980
Delta Electronics DIAEnergie SQL Injection in HandlerCommon.ashx
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-26065
Delta Electronics DIAEnergie SQL Injection in GetLatestDemandNode and GetDemandAnalysisData
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-1372
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Published 2022-05-02 · Modified
10.0EPSS 0.012
CVE-2022-27175
Delta Electronics DIAEnergie SQL Injection in GetCalcTagList
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2022-26059
Delta Electronics DIAEnergie SQL Injection in GetQueryData
Published 2022-03-29 · Modified
10.0EPSS 0.012
CVE-2021-32955
Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.
Published 2021-08-30 · Modified
9.8EPSS 0.373
CVE-2024-4548
Delta Electronics DIAEnergie SQL Injection
Published 2024-05-06 · Analyzed
9.8EPSS 0.294
CVE-2022-25347
Delta Electronics DIAEnergie Path Traversal
Published 2022-03-29 · Modified
9.8EPSS 0.114
CVE-2024-25574
Delta Electronics DIAEnergie SQL Injection
Published 2024-04-01 · Analyzed
9.8EPSS 0.088
CVE-2022-3214
Delta Electronics DIAEnergy Use of Hard-coded Credentials
Published 2022-09-16 · Modified
9.8EPSS 0.020
CVE-2024-4547
Delta Electronics DIAEnergie Unauthenticated SQL Injection
Published 2024-05-06 · Analyzed
9.8EPSS 0.019
CVE-2022-0923
Delta Electronics DIAEnergie SQL Injection in HandlerDialog_KID.ashx
Published 2022-03-29 · Modified
9.8EPSS 0.010
CVE-2024-43699
Delta Electronics DIAEnergie SQL Injection
Published 2024-10-03 · Analyzed
9.8EPSS 0.005
CVE-2022-41133
Delta Electronics DIAEnergie
Published 2022-10-27 · Modified
8.8EPSS 0.266
CVE-2024-28040
Delta Electronics DIAEnergie SQL injection
Published 2024-03-21 · Analyzed
8.8EPSS 0.085
1 / 2Next →