CWE-311
High likelihoodMissing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
508 vulnerabilities with CWE-311
CVE-2022-22405
MEDIUM
IBM Aspera Faspex 5.0.5 - Info Disclosure
CVSS 5.9
CVE-2022-38458
MEDIUM
Netgear Orbi Router RBR750 4.6.8.5 - Info Disclosure
CVSS 6.5
CVE-2022-21940
HIGH
Johnson Controls SCT <14.2.3, 15.0.3 - Info Disclosure
CVSS 7.5
CVE-2022-47715
MEDIUM
Last Yard 22.09.8-1 - Missing Encryption of Sensitive Data
CVSS 5.3
CVE-2022-38658
HIGH
HCL BigFix Server Automation < 3.2.1 - Sensitive Data Exposure via SMTP Notification Service
CVSS 7.7
CVE-2022-4683
MEDIUM
GitHub usememos/memos <0.9.0 - Info Disclosure
CVSS 6.5
CVE-2022-4409
HIGH
thorsten/phpmyfaq <3.1.9 - Info Disclosure
CVSS 7.5
CVE-2022-3781
MEDIUM
Devolutions Server < 2022.3.2 and Remote Desktop Manager < 2022.2.27 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2022-40295
MEDIUM
php_point_of_sale - Authenticated Information Disclosure of Unsalted Password Hashes
CVSS 4.9
CVE-2022-41627
MEDIUM
AliveCor's KardiaMobile - Info Disclosure
CVSS 4.8
CVE-2022-35860
MEDIUM
Corsair K63 Wireless <3.1.3 - Info Disclosure
CVSS 6.8
CVE-2022-3251
MEDIUM
GitHub ikus060/minarca <4.2.2 - Info Disclosure
CVSS 5.3
CVE-2022-3250
MEDIUM
GitHub rdiffweb <2.4.6 - Info Disclosure
CVSS 5.3
CVE-2022-39014
MEDIUM
SAP BusinessObjects <4.30 - Info Disclosure
CVSS 5.3
CVE-2022-3174
HIGH
GitHub ikus060/rdiffweb <2.4.2 - Info Disclosure
CVSS 7.5
CVE-2022-26390
MEDIUM
Baxter Spectrum WBM - Info Disclosure
CVSS 4.2
CVE-2022-38194
MEDIUM
Esri Portal for ArcGIS <10.8.1 - Info Disclosure
CVSS 6.7
CVE-2022-34307
MEDIUM
IBM CICS TX 11.1 - Missing Encryption of Sensitive Data in Session Cookies
CVSS 4.3
CVE-2022-31085
MEDIUM
LDAP Account Manager <8.0 - Info Disclosure
CVSS 6.1
CVE-2022-30237
HIGH
Wiser Smart EER21000 and EER21001 < 4.5 - Missing Encryption of Sensitive Data
CVSS 8.2
CVE-2022-24045
MEDIUM
Desigo DXR2 < V01.21.142.5-22 - Info Disclosure
CVSS 6.5
CVE-2022-26281
HIGH
BigAnt Server <5.6.06 - Info Disclosure
CVSS 7.5
CVE-2022-27225
MEDIUM
Gradle Enterprise >=2020.1 <2021.4.3 - Session Hijacking via Insecure Keycloak Cookie Transmission
CVSS 6.5
CVE-2022-26157
MEDIUM
Cherwell Service Mgmt <10.2.3 - Info Disclosure
CVSS 5.3
CVE-2022-0183
MEDIUM
MIRUPASS PW10 and PW20 Firmware - Unprotected Password Exposure via Physical Access
CVSS 4.6
Details
Vulnerabilities
508
Exploit Likelihood
High