Deltaww
Deltaww Diaenergie: vulnerabilidades y CVE
Deltaww Diaenergie tiene 92 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 41 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE92
Últimos 12 meses10
Críticas41
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-78313 | Media (6.5) | 0.46% | — | 24 sept 2026 | Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78312 | Crítica (9.1) | 0.34% | — | 24 sept 2026 | Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78311 | Alta (8.8) | 0.24% | — | 24 sept 2026 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78310 | Media (4.3) | 0.21% | — | 24 sept 2026 | Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78309 | Alta (8.8) | 0.24% | — | 24 sept 2026 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78308 | Crítica (9.8) | 0.35% | — | 24 sept 2026 | Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78317 | Alta (8.8) | 0.66% | — | 24 ago 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. |
| CVE-2026-78316 | Alta (8.8) | 0.66% | — | 24 ago 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. |
| CVE-2026-78315 | Alta (8.8) | 0.66% | — | 24 ago 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. |
| CVE-2026-78314 | Alta (8.8) | 0.66% | — | 24 ago 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. |
| CVE-2025-57703 | Media (5.9) | 0.16% | — | 18 ago 2025 | DIAEnergie - Reflected Cross-site Scripting |
| CVE-2025-57702 | Media (5.9) | 0.16% | — | 18 ago 2025 | DIAEnergie - Reflected Cross-site Scripting |
| CVE-2025-57701 | Media (5.9) | 0.16% | — | 18 ago 2025 | DIAEnergie - Reflected Cross-site Scripting |
| CVE-2025-57700 | Alta (7) | 0.18% | — | 18 ago 2025 | DIAEnergie - Stored Cross-site Scripting |
| CVE-2024-43699 | Crítica (9.3) | 0.54% | — | 3 oct 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product. |
| CVE-2024-42417 | Alta (8.7) | 7.0% | — | 3 oct 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product. |
| CVE-2024-4549 | Alta (7.5) | 1.1% | — | 6 may 2024 | A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system. |
| CVE-2024-4548 | Crítica (9.8) | 29% | — | 6 may 2024 | An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An… |
| CVE-2024-4547 | Crítica (9.8) | 1.9% | — | 6 may 2024 | A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An… |
| CVE-2024-34033 | Alta (8.8) | 1.0% | — | 3 may 2024 | Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on… |
| CVE-2024-34032 | Alta (8.8) | 8.7% | — | 3 may 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which… |
| CVE-2024-34031 | Alta (8.8) | 0.50% | — | 3 may 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which… |
| CVE-2024-25574 | Crítica (9.8) | 8.8% | — | 1 abr 2024 | SQL injection vulnerability exists in GetDIAE_usListParameters. |
| CVE-2024-28171 | Alta (8.1) | 0.65% | — | 21 mar 2024 | It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten. |
| CVE-2024-28045 | Media (5.4) | 0.29% | — | 21 mar 2024 | Improper neutralization of input within the affected product could lead to cross-site scripting. |
| CVE-2024-28040 | Alta (8.8) | 8.5% | — | 21 mar 2024 | SQL injection vulnerability exists in GetDIAE_astListParameters. |
| CVE-2024-25567 | Alta (8.8) | 0.66% | — | 21 mar 2024 | Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be… |
| CVE-2024-23975 | Alta (8.8) | 8.5% | — | 21 mar 2024 | SQL injection vulnerability exists in GetDIAE_slogListParameters. |
| CVE-2024-23494 | Alta (8.8) | 8.5% | — | 21 mar 2024 | SQL injection vulnerability exists in GetDIAE_unListParameters. |
| CVE-2024-28891 | Alta (8.8) | 8.5% | — | 21 mar 2024 | SQL injection vulnerability exists in the script Handler_CFG.ashx. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.