← Back
CWE-311

511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

JSON object

Loading...

CVEs (511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnome
1Evolution Data Server3
Nov 21, 2024
Nov 25, 2019
N/A· v4
7.3 HIGH· v3
4.3 MEDIUM· v2
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could us...Show more
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.Show less
1Ibm
1Smartcloud Analytics Log Analysis
Jun 17, 2026
Nov 22, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques....Show more
IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.Show less
1Fortinet
1Forticlient
Jun 17, 2026
Nov 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.
1Philips
1Taolight Smart Wi Fi Wiz Connected Led Bulb 9290022656 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness...Show more
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use the control API. The only requirement is that the attacker have network access to the bulb.Show less
2Debian
Rubyonrails
2Debian Linux
Rails
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
1Mailscanner
1Mailscanner
Nov 21, 2024
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain conf...Show more
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.Show less
1Broadcom
1Brocade Sannav
Jun 17, 2026
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
1Broadcom
1Brocade Sannav
Jun 17, 2026
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive...Show more
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.Show less
1Rakuten
1Viber
Jun 17, 2026
Nov 6, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victi...Show more
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains cleartext information such as the device model and OS version, IMSI, and 20 bytes of udid in a binary format, which is located at offset 0x14 of this packet. Then, the attacker installs Viber on his device, initiates the registration process for any phone number, but doesn't enter a pin from SMS. Instead, he closes Viber. Next, the attacker rewrites his udid with the victim's udid, modifying the viber_udid file, which is located in the Viber preferences folder. (The udid is stored in a hexadecimal format.) Finally, the attacker starts Viber again and enters the pin from SMS.Show less
1Apache
1Impala
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
4.6 MEDIUM· v2
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query IDs are unique and random, but have not been documented or consistently treated as sensitive secrets. Therefore they may be exposed in logs or interfaces. They were also not generated with a cryptographically secure random number generator, so are vulnerable to random number generator attacks that predict future IDs based on past IDs. Impala deployments with Apache Sentry or Apache Ranger authorization enabled may be vulnerable to privilege escalation if an authenticated attacker is able to hijack a session or query from another authenticated user with privileges not assigned to the attacker. Impala deployments with audit logging enabled may be vulnerable to incorrect audit logging as a user could undertake actions that were logged under the name of a different authenticated user. Constructing an attack requires a high degree of technical sophistication and access to the Impala system as an authenticated user.Show less
1Microfocus
1Service Manager
Jun 17, 2026
Sep 18, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive d...Show more
Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.Show less
1Microfocus
1Service Manager
Jun 17, 2026
Sep 18, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could...Show more
Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.Show less
1Ibm
1Cognos Controller
Jun 17, 2026
Sep 17, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle...Show more
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 158876.Show less
1Dahuasecurity
9Ipc Hdbw4x2x Firmware
Ipc Hdw1x2x FirmwareIpc Hdw2x2x Firmware+6 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-...Show more
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.Show less
1Siemens
1Sinema Remote Connect Server
Jun 17, 2026
Sep 13, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability c...Show more
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attacker with network access to the SINEMA Remote Connect Server and administrative privileges. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Search Guard
1Search Guard
Jun 17, 2026
Aug 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
1Search Guard
1Search Guard
Jun 17, 2026
Aug 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.
1Yarnpkg
1Yarn
Jun 17, 2026
Jul 30, 2019
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
1Mailenable
1Mailenable
Jun 17, 2026
Jul 8, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configur...Show more
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host system. Because all credentials were stored in a cleartext file, it was possible to steal all users' credentials (including the highest privileged users).Show less
1Jetbrains
1Kotlin
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in...Show more
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.Show less