CWE-311

High likelihood

Missing Encryption of Sensitive Data

Parent: CWE-693 - Protection Mechanism Failure

The product does not encrypt sensitive or critical information before storage or transmission.

508 vulnerabilities with CWE-311
CVE-2018-1937 MEDIUM
IBM Cloud Private 3.1.1 - Info Disclosure
CVSS 4.4
CVE-2018-5482 MEDIUM
NetApp SnapCenter Server <4.1 - Info Disclosure
CVSS 5.3
CVE-2018-1340 HIGH
Apache Guacamole < 1.0.0 - Unauthenticated Session Token Exposure via Insecure Cookie
CVSS 7.5
CVE-2018-10612 CRITICAL
CODESYS Control V3 <3.5.14.0 - Info Disclosure
CVSS 9.8
CVE-2018-5481 HIGH
OnCommand Unified Manager - Info Disclosure
CVSS 7.4
CVE-2018-16879 CRITICAL
Ansible Tower <3.3.3 - DoS, Info Disclosure
CVSS 9.8
CVE-2018-20100 CRITICAL
August Connect - Unencrypted Wi-Fi Credential Exposure via HTTP POST
CVSS 9.8
CVE-2018-20465 HIGH
Craft CMS <= 3.0.34 - Authenticated Server-Side Template Injection via Site Settings URI Format
CVSS 7.2
CVE-2018-18984 MEDIUM
Medtronic CareLink and Encore Programmers - Cleartext Storage of Sensitive Information
CVSS 4.6
CVE-2018-16837 HIGH
Ansible 2.7.0a1-2.7.0 - Sensitive Information Exposure via ssh-keygen Parameter Leak
CVSS 7.8
CVE-2018-17915 CRITICAL
Xiongmai XMeye P2P Cloud Server - Missing Encryption of Sensitive Data
CVSS 9.8
CVE-2018-1683 MEDIUM
IBM WebSphere Application Server Liberty - Info Disclosure
CVSS 5.9
CVE-2018-3826 MEDIUM
Elasticsearch 6.0.0-beta1-6.2.4 - Exposure of Sensitive Information via _snapshot API
CVSS 6.5
CVE-2018-6976 MEDIUM
VMware Workspace ONE < 4.14 - Sensitive Data Exposure via Unencrypted SQLite Database
CVSS 5.3
CVE-2018-6975 MEDIUM
VMware Intelligent Hub < 5.8.1 - Unprotected Sensitive Data Exposure via Missing Encryption
CVSS 5.5
CVE-2018-14608 HIGH
Thomson Reuters UltraTax CS 2017 - Info Disclosure
CVSS 7.5
CVE-2018-14607 HIGH
Thomson Reuters UltraTax CS 2017 - Info Disclosure
CVSS 7.5
CVE-2018-7781 HIGH
Schneider Electric Pelco Sarix Professional 1st Gen < 3.29.69 - Authenticated Sensitive Data Exposure
CVSS 8.8
CVE-2018-4855 MEDIUM
SICLOCK TC100 and TC400 - Unencrypted Password Storage in Client Configuration
CVSS 6.5
CVE-2018-5185 MEDIUM
Thunderbird <52.8 - Info Disclosure
CVSS 6.5
CVE-2018-5162 HIGH
Thunderbird <52.8 - Info Disclosure
CVSS 7.5
CVE-2018-8864 LOW
ATI Systems - Info Disclosure
CVSS 3.1
CVE-2018-6674 MEDIUM
McAfee VirusScan Enterprise < 8.8 Patch 13 - Privilege Escalation via McTray.exe
CVSS 6.8
CVE-2018-8849 MEDIUM
Medtronic N'Vision - Info Disclosure
CVSS 4.6
CVE-2018-10825 MEDIUM
Mimo Baby 2 Firmware - Unauthenticated Fake Data Injection via BLE Replay or Spoofing
CVSS 5.3
Details
Vulnerabilities 508
Exploit Likelihood High