← Back
CWE-311

511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

JSON object

Loading...

CVEs (511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Websphere Deployer
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins WebSphere Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Ftp Publisher
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Jira Issue Updater
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Hockeyapp
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins HockeyApp Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Aws Elastic Beanstalk Publisher
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Irc
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins IRC Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Nov 21, 2024
Apr 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
1Jenkins
1Prqa
Jun 17, 2026
Mar 28, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the unencrypted password from the plugin configuration.
1Abus
3Secvest Wireless Alarm System Fuaa50000 Firmware
Secvest Wireless Remote Control Fube50014 FirmwareSecvest Wireless Remote Control Fube50015 Firmware
Jun 17, 2026
Mar 27, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able t...Show more
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensitive data as cleartext (for instance, the current rolling code state).Show less
1Moxa
4Eds 405a Firmware
Eds 408a FirmwareEds 510a Firmware+1 more
Jun 17, 2026
Mar 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.
1Ibm
1Cloud Private
Nov 21, 2024
Mar 5, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153318.
1Ibm
1Cloud Private
Nov 21, 2024
Mar 5, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153317.
1Netapp
1Snapcenter Server
Jun 17, 2026
Mar 4, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.
1Apache
1Guacamole
Nov 21, 2024
Feb 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's...Show more
Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.Show less
1Codesys
12Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+9 more
Nov 21, 2024
Jan 29, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device...Show more
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.Show less
1Netapp
1Oncommand Unified Manager
Jun 17, 2026
Jan 7, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
OnCommand Unified Manager for 7-Mode (core package) prior to 5.2.4 uses cookies that lack the secure attribute in certain circumstances making it vulnerable to impersonation via man-in-the-middle (MITM) attacks.
1Redhat
1Ansible Tower
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive in...Show more
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.Show less
1August
2August Connect
August Connect Firmware
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an une...Show more
An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes them in an HTTP POST, using the AugustWifiDevice class, with data encrypted with a fixed key found obfuscated in the app.Show less
1Craftcms
1Craft Cms
Nov 21, 2024
Dec 25, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.pa...Show more
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.Show less
1Medtronic
329901 Encore Programmer Firmware
Carelink 2090 Programmer FirmwareCarelink 9790 Programmer Firmware
May 22, 2025
Dec 14, 2018
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .