CWE-311
511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
CVEs (511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could us...Show more |
1Ibm 1Smartcloud Analytics Log Analysis Jun 17, 2026 Nov 22, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques....Show more |
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway. |
1Philips 1Taolight Smart Wi Fi Wiz Connected Led Bulb 9290022656 Firmware Jun 17, 2026 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness...Show more |
2Debian Rubyonrails2Debian Linux RailsNov 21, 2024 Nov 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks. |
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain conf...Show more |
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save. |
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive...Show more |
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victi...Show more |
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more |
1Microfocus 1Service Manager Jun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive d...Show more |
1Microfocus 1Service Manager Jun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could...Show more |
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle...Show more |
1Dahuasecurity 9Ipc Hdbw4x2x Firmware Ipc Hdw1x2x FirmwareIpc Hdw2x2x Firmware+6 moreJun 17, 2026 Sep 17, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Sep 13, 2019 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability c...Show more |
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked. |
Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized. |
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network. |
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configur...Show more |
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in...Show more |