CWE-311— Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.— MITRE CWE catalog
575 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-311page 1 of 12
- CVE-2026-34486CRITICALCVSS 7.5EG 9.0⚠ KEV2026-04-09
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to u…
- CVE-2023-6339CRITICALCVSS 9.8EG 10.02024-01-02
Google Nest WiFi Pro root code-execution & user-data compromise
- CVE-2026-20157CRITICALCVSS 9.8EG 9.82026-07-15
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses …
- CVE-2026-27944CRITICALCVSS 9.8EG 9.82026-03-05
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security resp…
- CVE-2023-0750CRITICALCVSS 9.8EG 9.82023-04-06
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the p…
- CVE-2020-15331CRITICALCVSS 9.8EG 9.82022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
- CVE-2019-14480CRITICALCVSS 9.8EG 9.82020-12-16
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
- CVE-2019-3431CRITICALCVSS 9.8EG 9.82019-12-23
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.
- CVE-2019-16672CRITICALCVSS 9.8EG 9.82019-12-06
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.
- CVE-2019-12924CRITICALCVSS 9.8EG 9.82019-07-08
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML pr…
- CVE-2018-10698CRITICALCVSS 9.8EG 9.82019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the u…
- CVE-2019-11523CRITICALCVSS 9.8EG 9.82019-06-06
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users li…
- CVE-2019-11367CRITICALCVSS 9.8EG 9.82019-06-03
An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login su…
- CVE-2019-6526CRITICALCVSS 9.8EG 9.82019-04-15
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext transmission of sensitive data, which may allow an attacke…
- CVE-2018-10612CRITICALCVSS 9.8EG 9.82019-01-29
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive info…
- CVE-2018-16879CRITICALCVSS 9.8EG 9.82019-01-03
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as p…
- CVE-2018-20100CRITICALCVSS 9.8EG 9.82019-01-02
An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access poi…
- CVE-2018-17915CRITICALCVSS 9.8EG 9.82018-10-10
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video fee…
- CVE-2017-3198CRITICALCVSS 9.8EG 9.82018-07-09
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without …
- CVE-2018-7498CRITICALCVSS 9.8EG 9.82018-03-28
In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrity, and accountability that properly implemented encryption conveys.
- CVE-2017-9632CRITICALCVSS 9.8EG 9.82017-08-07
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, al…
- CVE-2017-9854CRITICALCVSS 9.8EG 9.82017-08-05
An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. These passwords can then be used to comprom…
- CVE-2017-7406CRITICALCVSS 9.8EG 9.82017-07-07
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker can simply monitor network traffic to steal a user's credenti…
- CVE-2017-14852CRITICALCVSS 8.6EG 9.82019-06-03
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.
- CVE-2018-13992CRITICALCVSS 8.2EG 9.82019-05-07
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.
- CVE-2023-4420CRITICALCVSS 7.4EG 9.82023-08-24
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauth…
- CVE-2025-32875CRITICALCVSS 5.7EG 9.82025-06-20
An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any …
- CVE-2020-35168CRITICALCVSS 4.7EG 9.82022-07-11
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
- CVE-2025-69969CRITICALCVSS 9.6EG 9.62026-03-04
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary comma…
- CVE-2026-77812CRITICALCVSS 9.4EG 9.42026-08-21
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, …
- CVE-2025-36751CRITICALCVSS 9.4EG 9.42025-12-13
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its …
- CVE-2024-47871CRITICALCVSS 9.1EG 9.12024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is used. HTTPS is not e…
- CVE-2024-29151CRITICALCVSS 9.1EG 9.12024-03-18
Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.
- CVE-2023-41095CRITICALCVSS 9.1EG 9.12023-10-26
Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs …
- CVE-2023-38699CRITICALCVSS 9.1EG 9.12023-08-04
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certif…
- CVE-2021-27779CRITICALCVSS 9.1EG 9.12022-05-25
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
- CVE-2020-12032CRITICALCVSS 9.1EG 9.12020-06-29
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensiti…
- CVE-2019-17218CRITICALCVSS 9.1EG 9.12019-10-06
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An attacker is able to intercept and sniff communication to the we…
- CVE-2026-32891CRITICALCVSS 9.0EG 9.02026-03-20
Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows …
- CVE-2020-9057HIGHCVSS 8.8EG 8.82022-01-10
Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. An attacker can also capture …
- CVE-2020-12772HIGHCVSS 8.8EG 8.82020-05-12
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, th…
- CVE-2019-18800HIGHCVSS 8.8EG 8.82019-11-06
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains…
- CVE-2019-1003075HIGHCVSS 8.8EG 8.82019-04-04
Jenkins Audit to Database Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- CVE-2019-1003074HIGHCVSS 8.8EG 8.82019-04-04
Jenkins Hyper.sh Commons Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- CVE-2019-1003073HIGHCVSS 8.8EG 8.82019-04-04
Jenkins VS Team Services Continuous Deployment Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2019-1003072HIGHCVSS 8.8EG 8.82019-04-04
Jenkins WildFly Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2019-1003071HIGHCVSS 8.8EG 8.82019-04-04
Jenkins OctopusDeploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- CVE-2019-1003070HIGHCVSS 8.8EG 8.82019-04-04
Jenkins veracode-scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- CVE-2019-1003069HIGHCVSS 8.8EG 8.82019-04-04
Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- CVE-2019-1003068HIGHCVSS 8.8EG 8.82019-04-04
Jenkins VMware vRealize Automation Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Map vulnerabilities like CWE-311 to your infrastructure
EchelonGraph correlates every CVE — across CWE-311 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →