İçeriğe atla
Noroxi

CWE-311 · 458 kayıt

Missing Encryption of Sensitive Data

Bu sınıftaki CVE’ler

458 kayıt

  • CVE-2026-34486
    62Bu hafta

    Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %7

    apache · tomcat9 Nis 2026

  • CVE-2019-11367
    40Planlayın

    An issue was discovered in AUO Solar Data Recorder before 1.3.0.

    KritikCVSS 9,8İstismar yokEPSS %3

    auo · solar data recorder3 Haz 2019

  • CVE-2018-10698
    40Planlayın

    An issue was discovered on Moxa AWK-3121 1.14 devices.

    KritikCVSS 9,8İstismar yokEPSS %2

    moxa · awk-3121 firmware7 Haz 2019

  • CVE-2017-9854
    39İzleyin

    An issue was discovered in SMA Solar Technology products.

    KritikCVSS 9,8İstismar yokEPSS %1

    sma · sunny boy 3600 firmware5 Ağu 2017

  • CVE-2018-13992
    39İzleyin

    The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by

    KritikCVSS 9,8İstismar yokEPSS %1

    phoenixcontact · fl switch 3005 firmware7 May 2019

  • CVE-2018-16879
    39İzleyin

    Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for mess

    KritikCVSS 9,8İstismar yokEPSS %1

    redhat · ansible tower3 Oca 2019

  • CVE-2018-17915
    39İzleyin

    All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication.

    KritikCVSS 9,8İstismar yokEPSS %1

    xiongmaitech · xmeye p2p cloud server10 Eki 2018

  • CVE-2019-6526
    39İzleyin

    Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A se

    KritikCVSS 9,8İstismar yokEPSS %1

    moxa · iks-g6824a firmware15 Nis 2019

  • CVE-2019-12924
    39İzleyin

    MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthentica

    KritikCVSS 9,8İstismar yokEPSS %1

    mailenable · mailenable8 Tem 2019

  • CVE-2020-15331
    39İzleyin

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.

    KritikCVSS 9,8İstismar yokEPSS %1

    zyxel · cloudcnm secumanager28 Eyl 2022

  • CVE-2018-20100
    39İzleyin

    An issue was discovered on August Connect devices.

    KritikCVSS 9,8İstismar yokEPSS %1

    august · august connect2 Oca 2019

  • CVE-2018-7498
    39İzleyin

    In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrity

    KritikCVSS 9,8İstismar yokEPSS %1

    philips · alice 6 firmware28 Mar 2018

  • CVE-2020-35168
    39İzleyin

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim

    KritikCVSS 9,8İstismar yokEPSS %1

    dell · bsafe crypto-c-micro-edition11 Tem 2022

  • CVE-2017-9632
    39İzleyin

    A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, al

    KritikCVSS 9,8İstismar yokEPSS %0

    pdqinc · laserwash g5 firmware7 Ağu 2017

  • CVE-2019-3431
    39İzleyin

    All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %0

    zte · zxcloud goldendata vap23 Ara 2019

  • CVE-2026-20157
    39İzleyin

    Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %0

    cisco · roomos15 Tem 2026

  • CVE-2023-6339
    39İzleyin

    Google Nest WiFi Pro root code-execution & user-data compromise

    KritikCVSS 9,8İstismar yokEPSS %0

    google · nest wifi pro firmware2 Oca 2024

  • CVE-2025-69969
    38İzleyin

    A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebb

    KritikCVSS 9,6İstismar yokEPSS %0

    pebblepower · pebble prism ultra firmware4 Mar 2026

  • CVE-2026-81681
    37İzleyin

    openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage

    KritikCVSS 9,3İstismar yokEPSS %0

    jahlives · openssl encrypt27 Ağu 2026

  • CVE-2026-77812
    37İzleyin

    Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE

    KritikCVSS 9,4Kavram kanıtıEPSS %0

    dji · neo21 Ağu 2026

  • CVE-2025-36751
    37İzleyin

    Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-X

    KritikCVSS 9,4İstismar yokEPSS %0

    growatt · shinelan-x13 Ara 2025

  • CVE-2020-12032
    36İzleyin

    Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in

    KritikCVSS 9,1İstismar yokEPSS %1

    baxter · em2400 firmware29 Haz 2020

  • CVE-2021-27779
    36İzleyin

    A Security Misconfiguration vulnerability affects HCL VersionVault Express

    KritikCVSS 9,1İstismar yokEPSS %1

    hcltech · versionvault express25 May 2022

  • CVE-2024-29151
    36İzleyin

    Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.

    KritikCVSS 9,1İstismar yokEPSS %0

    18 Mar 2024

  • CVE-2019-18800
    35İzleyin

    Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Vi

    YüksekCVSS 8,8İstismar yokEPSS %2

    rakuten · viber6 Kas 2019

Tüm zafiyet sınıfları