← Back
CWE-311

511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

JSON object

Loading...

CVEs (511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Verify Information Queue
Jun 17, 2026
Aug 31, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
IBM Security Verify Information Queue 10.0.4 and 10.0.5 stores sensitive information in plain clear text which can be read by a local user. IBM X-Force ID: 256013.
1Sick
3Lms500 Firmware
Lms511 FirmwareLms531 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can...Show more
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the LMS5xx and the Client, and potentially manipulate the data being transmitted.Show less
1Genians
2Genian Nac
Genian Ztna
Jun 17, 2026
Aug 17, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Man in the Middle Attack.This issue affects Genian NAC V4....Show more
Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Man in the Middle Attack.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15. Show less
1Maximatech
1Portal Executivo
Jun 17, 2026
Aug 16, 2023
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
A vulnerability has been found in MaximaTech Portal Executivo 21.9.1.140 and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to missing encryptio...Show more
A vulnerability has been found in MaximaTech Portal Executivo 21.9.1.140 and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to missing encryption of sensitive data. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237316. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Sulimet
15 In 1 Smart Door Lock Firmware
Jun 17, 2026
Aug 15, 2023
N/A· v4
2.4 LOW· v3
N/A· v2
Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
1Mydigoo
1Dg Hamb Smart Home Security System Firmware
Jun 17, 2026
Aug 15, 2023
N/A· v4
2.4 LOW· v3
N/A· v2
Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
1Etekcity
13 In 1 Smart Door Lock Firmware
Jun 17, 2026
Aug 15, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
1Nextcloud
1User Oidc
Jun 17, 2026
Aug 10, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the dat...Show more
user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked servers. user_oidc 1.3.3 contains a patch. No known workarounds are available.Show less
1Phoenixcontact
6Wp 6070 Wvps Firmware
Wp 6101 Wxps FirmwareWp 6121 Wxps Firmware+3 more
Jun 17, 2026
Aug 9, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web applicat...Show more
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password. Show less
1Mindsdb
1Mindsdb
Jun 17, 2026
Aug 4, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always v...Show more
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior.Show less
1Xithrius
1Twitch Tui
Jun 17, 2026
Aug 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communicati...Show more
twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC servers unencrypted. As a result, communication, including auth tokens, can be sniffed. Version 2.4.1 has a patch for this issue.Show less
1Bd
1Alaris 8015 Pcu Firmware
Jun 17, 2026
Jul 13, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.
1Inageya
1Inageya
Jul 9, 2026
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.
1Entetsu
1Entetsu Store
Jul 9, 2026
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Entetsu Store function.
1Shizutetsu
1Shizutetsu Store
Jul 9, 2026
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
2Keisei Store
Livre
2Keisei Store
Livre
Jul 9, 2026
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
1Jenkins
1Active Directory
Jun 17, 2026
Jul 12, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffi...Show more
Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory credentials.Show less
1Bitcoin
1Bitcoin Core
Jun 17, 2026
Jul 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their ow...Show more
Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.Show less
1Ibm
2Cics Tx
Txseries For Multiplatforms
Jun 17, 2026
Jun 7, 2023
N/A· v4
3.7 LOW· v3
N/A· v2
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques...Show more
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.Show less
1Bmc
1Patrol
Jun 17, 2026
May 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be...Show more
An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution.Show less