Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Diaowen

First CVE: Aug 7, 2019Active for: 7 yearsTotal CVEs: 7

Diaowen maintains a focused survey and data-collection application (DwSurvey) with a narrow but specialized user base. Vulnerabilities in this product skew strongly toward critical severity and center on application-layer input handling and access control, recurring across cross-site scripting, unrestricted file upload, authorization bypass, and code injection weaknesses that are characteristic of web-facing survey and form-management systems. Live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Diaowen over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2019
6 years ago
Most Recent CVE
Nov 5, 2025
262 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-39383CRITICAL
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
Mar 20, 20229.832NONO
CVE-2021-39384CRITICAL
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.
Mar 20, 20229.830NONO
CVE-2023-40980CRITICAL
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/Upload
Sep 1, 20239.826NONO
CVE-2025-63248HIGH
DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another questionnaire can enable the deletio
Nov 5, 20257.524NONO
CVE-2019-14747MEDIUM
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
Aug 7, 20196.121NONO
CVE-2020-20070MEDIUM
Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.acti
Jun 20, 20236.120NONO
CVE-2019-15095MEDIUM
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
Aug 16, 20196.120NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
14%
43%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Diaowen.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Diaowen — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Diaowen's Products

View all 1 CNAs →

Top CWEs