CWE-311 · 458 kayıt
Missing Encryption of Sensitive Data
Bu sınıftaki CVE’ler
458 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2026-34486Silahlaştırılmış | Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptorapache · tomcat · CWE-311 | Yüksek7,5 | KEV | %6,6 | 9 Nis 2026 |
40Planlayın | CVE-2019-11367İstismar yok | An issue was discovered in AUO Solar Data Recorder before 1.3.0.auo · solar data recorder · CWE-311 | Kritik9,8 | — | %2,8 | 3 Haz 2019 |
40Planlayın | CVE-2018-10698İstismar yok | An issue was discovered on Moxa AWK-3121 1.14 devices.moxa · awk-3121 firmware · CWE-311 | Kritik9,8 | — | %2,3 | 7 Haz 2019 |
39İzleyin | CVE-2017-9854İstismar yok | An issue was discovered in SMA Solar Technology products.sma · sunny boy 3600 firmware · CWE-311 | Kritik9,8 | — | %1,1 | 5 Ağu 2017 |
39İzleyin | CVE-2018-13992İstismar yok | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials byphoenixcontact · fl switch 3005 firmware · CWE-311 | Kritik9,8 | — | %1,1 | 7 May 2019 |
39İzleyin | CVE-2018-16879İstismar yok | Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messredhat · ansible tower · CWE-311 | Kritik9,8 | — | %1,1 | 3 Oca 2019 |
39İzleyin | CVE-2018-17915İstismar yok | All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication.xiongmaitech · xmeye p2p cloud server · CWE-311 | Kritik9,8 | — | %1,1 | 10 Eki 2018 |
39İzleyin | CVE-2019-6526İstismar yok | Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A semoxa · iks-g6824a firmware · CWE-311 | Kritik9,8 | — | %1,0 | 15 Nis 2019 |
39İzleyin | CVE-2019-12924İstismar yok | MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticamailenable · mailenable · CWE-311 | Kritik9,8 | — | %0,9 | 8 Tem 2019 |
39İzleyin | CVE-2020-15331İstismar yok | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.zyxel · cloudcnm secumanager · CWE-311 | Kritik9,8 | — | %0,9 | 28 Eyl 2022 |
39İzleyin | CVE-2018-20100İstismar yok | An issue was discovered on August Connect devices.august · august connect · CWE-311 | Kritik9,8 | — | %0,7 | 2 Oca 2019 |
39İzleyin | CVE-2018-7498İstismar yok | In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrityphilips · alice 6 firmware · CWE-311 | Kritik9,8 | — | %0,6 | 28 Mar 2018 |
39İzleyin | CVE-2020-35168İstismar yok | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timdell · bsafe crypto-c-micro-edition · CWE-311 | Kritik9,8 | — | %0,5 | 11 Tem 2022 |
39İzleyin | CVE-2017-9632İstismar yok | A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, alpdqinc · laserwash g5 firmware · CWE-311 | Kritik9,8 | — | %0,5 | 7 Ağu 2017 |
39İzleyin | CVE-2019-3431İstismar yok | All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability.zte · zxcloud goldendata vap · CWE-311 | Kritik9,8 | — | %0,4 | 23 Ara 2019 |
39İzleyin | CVE-2026-20157İstismar yok | Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilitiescisco · roomos · CWE-311 | Kritik9,8 | — | %0,2 | 15 Tem 2026 |
39İzleyin | CVE-2023-6339İstismar yok | Google Nest WiFi Pro root code-execution & user-data compromisegoogle · nest wifi pro firmware · CWE-311 | Kritik9,8 | — | %0,2 | 2 Oca 2024 |
38İzleyin | CVE-2025-69969İstismar yok | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebbpebblepower · pebble prism ultra firmware · CWE-311 | Kritik9,6 | — | %0,5 | 4 Mar 2026 |
37İzleyin | CVE-2026-81681İstismar yok | openssl_encrypt before 1.4.9 False Encryption via Cleartext Storagejahlives · openssl encrypt · CWE-311 | Kritik9,3 | — | %0,2 | 27 Ağu 2026 |
37İzleyin | CVE-2026-77812Kavram kanıtı | Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLEdji · neo · CWE-311 | Kritik9,4 | — | %0,1 | 21 Ağu 2026 |
37İzleyin | CVE-2025-36751İstismar yok | Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-Xgrowatt · shinelan-x · CWE-311 | Kritik9,4 | — | %0,1 | 13 Ara 2025 |
36İzleyin | CVE-2020-12032İstismar yok | Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in baxter · em2400 firmware · CWE-311 | Kritik9,1 | — | %0,9 | 29 Haz 2020 |
36İzleyin | CVE-2021-27779İstismar yok | A Security Misconfiguration vulnerability affects HCL VersionVault Expresshcltech · versionvault express · CWE-311 | Kritik9,1 | — | %0,6 | 25 May 2022 |
36İzleyin | CVE-2024-29151İstismar yok | Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.CWE-311 | Kritik9,1 | — | %0,3 | 18 Mar 2024 |
35İzleyin | CVE-2019-18800İstismar yok | Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Virakuten · viber · CWE-311 | Yüksek8,8 | — | %1,7 | 6 Kas 2019 |
- CVE-2026-3448662Bu hafta
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %7apache · tomcat9 Nis 2026
- CVE-2019-1136740Planlayın
An issue was discovered in AUO Solar Data Recorder before 1.3.0.
KritikCVSS 9,8İstismar yokEPSS %3auo · solar data recorder3 Haz 2019
- CVE-2018-1069840Planlayın
An issue was discovered on Moxa AWK-3121 1.14 devices.
KritikCVSS 9,8İstismar yokEPSS %2moxa · awk-3121 firmware7 Haz 2019
- CVE-2017-985439İzleyin
An issue was discovered in SMA Solar Technology products.
KritikCVSS 9,8İstismar yokEPSS %1sma · sunny boy 3600 firmware5 Ağu 2017
- CVE-2018-1399239İzleyin
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by
KritikCVSS 9,8İstismar yokEPSS %1phoenixcontact · fl switch 3005 firmware7 May 2019
- CVE-2018-1687939İzleyin
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for mess
KritikCVSS 9,8İstismar yokEPSS %1redhat · ansible tower3 Oca 2019
- CVE-2018-1791539İzleyin
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication.
KritikCVSS 9,8İstismar yokEPSS %1xiongmaitech · xmeye p2p cloud server10 Eki 2018
- CVE-2019-652639İzleyin
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A se
KritikCVSS 9,8İstismar yokEPSS %1moxa · iks-g6824a firmware15 Nis 2019
- CVE-2019-1292439İzleyin
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthentica
KritikCVSS 9,8İstismar yokEPSS %1mailenable · mailenable8 Tem 2019
- CVE-2020-1533139İzleyin
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
KritikCVSS 9,8İstismar yokEPSS %1zyxel · cloudcnm secumanager28 Eyl 2022
- CVE-2018-2010039İzleyin
An issue was discovered on August Connect devices.
KritikCVSS 9,8İstismar yokEPSS %1august · august connect2 Oca 2019
- CVE-2018-749839İzleyin
In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrity
KritikCVSS 9,8İstismar yokEPSS %1philips · alice 6 firmware28 Mar 2018
- CVE-2020-3516839İzleyin
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim
KritikCVSS 9,8İstismar yokEPSS %1dell · bsafe crypto-c-micro-edition11 Tem 2022
- CVE-2017-963239İzleyin
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, al
KritikCVSS 9,8İstismar yokEPSS %0pdqinc · laserwash g5 firmware7 Ağu 2017
- CVE-2019-343139İzleyin
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability.
KritikCVSS 9,8İstismar yokEPSS %0zte · zxcloud goldendata vap23 Ara 2019
- CVE-2026-2015739İzleyin
Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %0cisco · roomos15 Tem 2026
- CVE-2023-633939İzleyin
Google Nest WiFi Pro root code-execution & user-data compromise
KritikCVSS 9,8İstismar yokEPSS %0google · nest wifi pro firmware2 Oca 2024
- CVE-2025-6996938İzleyin
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebb
KritikCVSS 9,6İstismar yokEPSS %0pebblepower · pebble prism ultra firmware4 Mar 2026
- CVE-2026-8168137İzleyin
openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage
KritikCVSS 9,3İstismar yokEPSS %0jahlives · openssl encrypt27 Ağu 2026
- CVE-2026-7781237İzleyin
Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE
KritikCVSS 9,4Kavram kanıtıEPSS %0dji · neo21 Ağu 2026
- CVE-2025-3675137İzleyin
Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-X
KritikCVSS 9,4İstismar yokEPSS %0growatt · shinelan-x13 Ara 2025
- CVE-2020-1203236İzleyin
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in
KritikCVSS 9,1İstismar yokEPSS %1baxter · em2400 firmware29 Haz 2020
- CVE-2021-2777936İzleyin
A Security Misconfiguration vulnerability affects HCL VersionVault Express
KritikCVSS 9,1İstismar yokEPSS %1hcltech · versionvault express25 May 2022
- CVE-2024-2915136İzleyin
Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.
KritikCVSS 9,1İstismar yokEPSS %018 Mar 2024
- CVE-2019-1880035İzleyin
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Vi
YüksekCVSS 8,8İstismar yokEPSS %2rakuten · viber6 Kas 2019