Cncsoft
Vendor:
First CVE: Aug 13, 2018 · Active for 7 years
11
Total CVEs
More Total CVEs than 90% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cncsoft over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 13, 2018
7 years ago
Most Recent CVE
Jun 4, 2025
419 days ago
CVE Severity & Scoring
Cncsoft11 CVEs
9%
91%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local9 (81.8%)
Network2 (18.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required11 (100.0%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None7 (63.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10636HIGH CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabilities that could cause the software to crash due to lacking u | Aug 13, 2018 | 8.8 | 31 | NO | NO |
CVE-2021-43982HIGH Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. | Dec 9, 2021 | 7.8 | 29 | NO | NO |
CVE-2018-10598HIGH CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validatio | Aug 13, 2018 | 8.1 | 27 | NO | NO |
CVE-2022-1405HIGH CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buffer overflow condition. | Aug 31, 2022 | 7.8 | 26 | NO | NO |
CVE-2025-47727HIGH Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the co | Jun 4, 2025 | 7.3 | 21 | NO | NO |
CVE-2025-47725HIGH Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the co | Jun 4, 2025 | 7.3 | 21 | NO | NO |
CVE-2022-4634HIGH All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow | Feb 3, 2023 | 7.8 | 21 | NO | NO |
CVE-2025-47726HIGH Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the co | Jun 4, 2025 | 7.3 | 20 | NO | NO |
CVE-2025-47724HIGH Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the co | Jun 4, 2025 | 7.3 | 20 | NO | NO |
CVE-2021-44768MEDIUM Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose info | Mar 25, 2022 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Cncsoft
Top CWEs
Versions
No cataloged versions.