Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 8.5% | — | Deltaww Diaenergie | 21/3/2024 | 17/6/2026 | SQL injection vulnerability exists in GetDIAE_astListParameters. | |
| Analizada | Alta (8.8) | 0.66% | — | Deltaww Diaenergie | 21/3/2024 | 17/6/2026 | Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten. | |
| Analizada | Alta (8.8) | 8.5% | — | Deltaww Diaenergie | 21/3/2024 | 17/6/2026 | SQL injection vulnerability exists in GetDIAE_slogListParameters. | |
| Analizada | Alta (8.8) | 8.5% | — | Deltaww Diaenergie | 21/3/2024 | 17/6/2026 | SQL injection vulnerability exists in GetDIAE_unListParameters. | |
| Analizada | Alta (8.8) | 8.5% | — | Deltaww Diaenergie | 21/3/2024 | 17/6/2026 | SQL injection vulnerability exists in the script Handler_CFG.ashx. | |
| Modificada | Alta (8.8) | 0.65% | — | Deltaww Diaenergie | 21/3/2024 | 17/6/2026 | Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality. | |
| Analizada | Alta (8.8) | 8.5% | — | Deltaww Diaenergie | 21/3/2024 | 17/6/2026 | SQL injection vulnerability exists in the script DIAE_tagHandler.ashx. | |
| Modificada | Alta (8.8) | 0.63% | — | Deltaww Diaenergie | 17/2/2023 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality. | |
| Modificada | Alta (8.8) | 0.73% | — | Deltaww Diaenergie | 17/11/2022 | 17/6/2026 | SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | |
| Modificada | Alta (8.8) | 0.66% | — | Deltaww Diaenergie | 17/11/2022 | 17/6/2026 | SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | |
| Modificada | Alta (8.8) | 7.7% | — | Deltaww Diaenergie | 17/11/2022 | 17/6/2026 | SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | |
| Modificada | Alta (8.8) | 0.66% | — | Deltaww Diaenergie | 17/11/2022 | 17/6/2026 | SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | |
| Modificada | Alta (8.8) | 0.66% | — | Deltaww Diaenergie | 17/11/2022 | 17/6/2026 | SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | |
| Modificada | Alta (8.8) | 7.9% | — | Deltaww Diaenergie | 27/10/2022 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries. | |
| Modificada | Media (5.4) | 11% | — | Deltaww Diaenergie | 27/10/2022 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API. | |
| Modificada | Media (5.4) | 11% | — | Deltaww Diaenergie | 27/10/2022 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API. | |
| Modificada | Media (5.4) | 11% | — | Deltaww Diaenergie | 27/10/2022 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API. | |
| Modificada | Media (5.4) | 11% | — | Deltaww Diaenergie | 27/10/2022 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API. | |
| Modificada | Alta (8.8) | 27% | — | Deltaww Diaenergie | 27/10/2022 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries. | |
| Modificada | Alta (8.8) | 7.7% | — | Deltaww Diaenergie | 27/10/2022 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries. | |
| Modificada | Media (5.4) | 11% | — | Deltaww Diaenergie | 27/10/2022 | 17/6/2026 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API. | |
| Modificada | Crítica (9.8) | 21% | — | Deltaww Diaenergie | 26/10/2022 | 17/6/2026 | The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system. | |
| Modificada | Crítica (9.8) | 0.77% | — | Deltaww Diaenergie | 26/10/2022 | 17/6/2026 | The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system. | |
| Modificada | Crítica (9.8) | 2.0% | — | Deltaww Diaenergie | 16/9/2022 | 17/6/2026 | Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to 1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution. | |
| Modificada | Media (6.1) | 0.63% | — | Deltaww Diaenergie | 27/6/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field. |