cbcvebase.

Deltaww Diaenergie vulnerabilities

88 known vulnerabilities affecting deltaww/diaenergie.

Total CVEs
88
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL41HIGH32MEDIUM15

Vulnerabilities

Page 5 of 5
CVE-2022-41555P4MEDIUMCVSS 5.4fixed in 1.9.01.0022022-10-27
CVE-2022-41555 [MEDIUM] CWE-79 CVE-2022-41555: The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.
nvd
CVE-2021-44471P4MEDIUMCVSS 6.1≤ 1.7.52021-12-22
CVE-2021-44471 [MEDIUM] CWE-79 CVE-2021-44471: DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthentica DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.
nvd
CVE-2024-28045P4MEDIUMCVSS 5.4fixed in 1.10.00.0052024-03-21
CVE-2024-28045 [MEDIUM] CWE-79 CVE-2024-28045: Improper neutralization of input within the affected product could lead to cross-site scripting. Improper neutralization of input within the affected product could lead to cross-site scripting.
nvd
CVE-2022-33005P4MEDIUMCVSS 6.1v1.08.002022-06-27
CVE-2022-33005 [MEDIUM] CWE-79 CVE-2022-33005: A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Elect A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.
nvd
CVE-2021-33003P4MEDIUMCVSS 5.5≤ 1.7.52021-08-30
CVE-2021-33003 [MEDIUM] CWE-916 CVE-2021-33003: Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.
nvd
CVE-2026-78310P4MEDIUMCVSS 4.3fixed in 1.11.00.0222026-09-24
CVE-2026-78310 [MEDIUM] CWE-639 CVE-2026-78310: Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: befo Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
nvd
CVE-2021-23228P4MEDIUMCVSS 6.1≤ 1.7.52021-12-22
CVE-2021-23228 [MEDIUM] CWE-79 CVE-2021-23228: DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.
nvd
CVE-2021-32991P4MEDIUMCVSS 4.3≤ 1.7.52021-08-30
CVE-2021-32991 [MEDIUM] CWE-352 CVE-2021-32991: Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, wh Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.
nvd
Deltaww Diaenergie vulnerabilities | cvebase