AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-38428

MEDIUM · CVSS 5.5 EPSS 11.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-11-03 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.5. It affects Java. Its EPSS score suggests a 11.4% probability of exploitation in the next 30 days. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2021-38428
Severity
MEDIUM
CVSS
5.5
EPSS
11.43%
Java

Original NVD Description

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.

Related CVEs

Other vulnerabilities affecting the same vendor(s)