← Back
CWE-311

519 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

JSON object

Loading...

CVEs (519)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Octopus
1Octopus Deploy
May 13, 2026
Oct 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offline Drop Targets.
1Kaspersky
1Internet Security
May 13, 2026
Aug 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
1Pdqinc
11Laserjet Firmware
Laserwash 360 FirmwareLaserwash 360 Plus Firmware+8 more
May 13, 2026
Aug 7, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and A...Show more
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions, ProTouch Tandem, all versions, ProTouch ICON, all versions, and ProTouch AutoGloss, all versions. The username and password are transmitted insecurely.Show less
1Sma
39Sunny Boy 1.5 Firmware
Sunny Boy 2.5 FirmwareSunny Boy 3.0 Firmware+36 more
May 13, 2026
Aug 5, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. These passwords can then...Show more
An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. These passwords can then be used to compromise the overall device. NOTE: the vendor reports that exploitation likelihood is low because these packets are usually sent only once during installation. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affectedShow less
1Ismartalarm
1Cubeone Firmware
May 13, 2026
Jul 11, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
1Dlink
1Dir 615
May 13, 2026
Jul 7, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker can simply monitor network traffic to stea...Show more
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker can simply monitor network traffic to steal a user's credentials and/or credentials of users being added while sniffing the traffic.Show less
1Acronis
1True Image
May 13, 2026
Jun 21, 2017
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
1Samsung
1Magician
May 13, 2026
Jun 21, 2017
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
1Kde
2Kmail
Messagelib
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote at...Show more
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.Show less
1Google
1Google I/o 2017
May 13, 2026
May 18, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule dat...Show more
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file.Show less
1Whatsapp
1Whatsapp
May 13, 2026
May 18, 2017
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There ma...Show more
Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expect file deletion to occur upon chat deletion, or who expect encryption (consistent with the application's use of an encrypted database to store chat text). NOTE: the vendor reportedly indicates that they do not "consider these to be security issues" because a user may legitimately want to preserve any file for use "in other apps like the Google Photos gallery" regardless of whether its associated chat is deletedShow less
1Postgresql
1Postgresql
May 13, 2026
May 12, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL ser...Show more
In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.Show less
1Wificam
1Wireless Ip Camera (p2p) Firmware
May 13, 2026
Apr 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote attackers to obtain sensi...Show more
Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote attackers to obtain sensitive information by sniffing the network.Show less
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
May 13, 2026
Apr 24, 2017
N/A· v4
5.7 MEDIUM· v3
3.3 LOW· v2
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connecti...Show more
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.Show less
1Openelec
1Openelec
May 13, 2026
Mar 5, 2017
N/A· v4
8.1 HIGH· v3
7.6 HIGH· v2
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packa...Show more
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.Show less
1Mikrotik
1Routeros
May 13, 2026
Feb 27, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks o...Show more
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.Show less
1Sensysnetworks
4Trafficdot
VdsVsn240 F+1 more
May 6, 2026
Sep 5, 2014
N/A· v4
N/A· v3
5.4 MEDIUM· v2
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to interfere with traffic control by replaying transmissions on a wireless...Show more
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to interfere with traffic control by replaying transmissions on a wireless network.Show less
1Wellintech
1Kingview
Apr 29, 2026
May 9, 2012
N/A· v4
N/A· v3
7.1 HIGH· v2
WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.
1Lindenlab
1Second Life
Apr 23, 2026
Sep 18, 2007
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows rem...Show more
The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows remote attackers to login to an account by sniffing the network and then sending this hash to a Second Life authentication server.Show less