CWE-311
High likelihoodMissing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
508 vulnerabilities with CWE-311
CVE-2018-1937
MEDIUM
IBM Cloud Private 3.1.1 - Info Disclosure
CVSS 4.4
CVE-2018-5482
MEDIUM
NetApp SnapCenter Server <4.1 - Info Disclosure
CVSS 5.3
CVE-2018-1340
HIGH
Apache Guacamole < 1.0.0 - Unauthenticated Session Token Exposure via Insecure Cookie
CVSS 7.5
CVE-2018-10612
CRITICAL
CODESYS Control V3 <3.5.14.0 - Info Disclosure
CVSS 9.8
CVE-2018-5481
HIGH
OnCommand Unified Manager - Info Disclosure
CVSS 7.4
CVE-2018-16879
CRITICAL
Ansible Tower <3.3.3 - DoS, Info Disclosure
CVSS 9.8
CVE-2018-20100
CRITICAL
August Connect - Unencrypted Wi-Fi Credential Exposure via HTTP POST
CVSS 9.8
CVE-2018-20465
HIGH
Craft CMS <= 3.0.34 - Authenticated Server-Side Template Injection via Site Settings URI Format
CVSS 7.2
CVE-2018-18984
MEDIUM
Medtronic CareLink and Encore Programmers - Cleartext Storage of Sensitive Information
CVSS 4.6
CVE-2018-16837
HIGH
Ansible 2.7.0a1-2.7.0 - Sensitive Information Exposure via ssh-keygen Parameter Leak
CVSS 7.8
CVE-2018-17915
CRITICAL
Xiongmai XMeye P2P Cloud Server - Missing Encryption of Sensitive Data
CVSS 9.8
CVE-2018-1683
MEDIUM
IBM WebSphere Application Server Liberty - Info Disclosure
CVSS 5.9
CVE-2018-3826
MEDIUM
Elasticsearch 6.0.0-beta1-6.2.4 - Exposure of Sensitive Information via _snapshot API
CVSS 6.5
CVE-2018-6976
MEDIUM
VMware Workspace ONE < 4.14 - Sensitive Data Exposure via Unencrypted SQLite Database
CVSS 5.3
CVE-2018-6975
MEDIUM
VMware Intelligent Hub < 5.8.1 - Unprotected Sensitive Data Exposure via Missing Encryption
CVSS 5.5
CVE-2018-14608
HIGH
Thomson Reuters UltraTax CS 2017 - Info Disclosure
CVSS 7.5
CVE-2018-14607
HIGH
Thomson Reuters UltraTax CS 2017 - Info Disclosure
CVSS 7.5
CVE-2018-7781
HIGH
Schneider Electric Pelco Sarix Professional 1st Gen < 3.29.69 - Authenticated Sensitive Data Exposure
CVSS 8.8
CVE-2018-4855
MEDIUM
SICLOCK TC100 and TC400 - Unencrypted Password Storage in Client Configuration
CVSS 6.5
CVE-2018-5185
MEDIUM
Thunderbird <52.8 - Info Disclosure
CVSS 6.5
CVE-2018-5162
HIGH
Thunderbird <52.8 - Info Disclosure
CVSS 7.5
CVE-2018-8864
LOW
ATI Systems - Info Disclosure
CVSS 3.1
CVE-2018-6674
MEDIUM
McAfee VirusScan Enterprise < 8.8 Patch 13 - Privilege Escalation via McTray.exe
CVSS 6.8
CVE-2018-8849
MEDIUM
Medtronic N'Vision - Info Disclosure
CVSS 4.6
CVE-2018-10825
MEDIUM
Mimo Baby 2 Firmware - Unauthenticated Fake Data Injection via BLE Replay or Spoofing
CVSS 5.3
Details
Vulnerabilities
508
Exploit Likelihood
High