CWE-311
511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
CVEs (511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Flient 1Smart Lock Advanced Firmware Jun 17, 2026 Jan 11, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original tags, which results in an attacker gaining access to the perimete...Show more |
Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to one of the original tags, which results in an attacker being able...Show more |
1Ibm 2Security Verify Access Security Verify Access DockerJun 17, 2026 Jan 11, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to s...Show more |
Google Nest WiFi Pro root code-execution & user-data compromise |
1Qualcomm 80Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+77 moreJun 17, 2026 Jan 2, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data. |
When saving HSTS data to an excessively long file name, curl could end up
removing all contents, making subsequent requests using that file unaware of
the HSTS status they should otherwise use. |
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161.
|
Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. |
1Solarwinds 1Network Configuration Manager Jun 17, 2026 Nov 1, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitiv...Show more |
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue...Show more |
Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue af...Show more |
IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020. |
1Ibm 1Security Verify Privilege On Premises Jun 17, 2026 Oct 17, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulne...Show more |
1Ibm 1Security Verify Privilege On Premises Jun 17, 2026 Oct 17, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulner...Show more |
1Ibm 4Security Directory Integrator Security Directory ServerSecurity Directory Suite+1 moreJun 17, 2026 Oct 14, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to...Show more |
A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via un...Show more |
An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message. |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Sep 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird <...Show more |
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567. |
IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensi...Show more |