CWE-311
High likelihoodMissing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
511 vulnerabilities with CWE-311
CVE-2021-32001
MEDIUM
SUSE Rancher K3s and RKE2 - Unprotected Sensitive Data Exposure via Datastore Access
CVSS 6.5
CVE-2021-33900
HIGH
Apache Directory Studio < 2.0.0.v20210717-M17 - Cleartext Transmission of Sensitive Information via StartTLS and SASL
CVSS 7.5
CVE-2021-22782
MEDIUM
EcoStruxure Control Expert < 15.0 SP1, EcoStruxure Process Expert, RemoteConnect - Missing Encryption of Sensitive Data
CVSS 5.5
CVE-2021-20567
MEDIUM
IBM Resilient SOAR <V38.0 - Info Disclosure
CVSS 4.4
CVE-2021-29248
MEDIUM
BTCPay Server <= 1.0.7.0 - Sensitive Information Exposure via Missing Secure Cookie Flag
CVSS 5.3
CVE-2020-15346
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Path Traversal
CVSS 5.3
CVE-2020-15345
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15344
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15343
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated API
CVSS 5.3
CVE-2020-15342
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15340
HIGH
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 7.5
CVE-2020-15331
CRITICAL
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 9.8
CVE-2020-15330
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 5.3
CVE-2020-35168
MEDIUM
Dell BSAFE <4.1.5-4.6 - Use After Free
CVSS 4.7
CVE-2020-9058
HIGH
Silicon Labs 500 Series Firmware - Missing Encryption of Sensitive Data
CVSS 8.1
CVE-2020-9057
HIGH
Linear Wadwaz-1 - Missing Encryption
CVSS 8.8
CVE-2020-29024
MEDIUM
Secomea GateManager <9.3 - Info Disclosure
CVSS 5.3
CVE-2020-26732
HIGH
SKYWORTH GN542VF 2.0.0.16 - Missing Secure Flag for Session Cookie
CVSS 7.5
CVE-2020-25842
HIGH
NHIServiSignAdapter - Unauthenticated Arbitrary File Access via Path Verification Bypass
CVSS 7.5
CVE-2020-35587
HIGH
Solstice Pod < 3.0.3 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-27055
HIGH
Android 11 - Remote Information Disclosure via WiFi Configuration Input Validation
CVSS 7.5
CVE-2020-28217
HIGH
Easergy T300 Firmware < 2.7 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-28216
HIGH
Easergy T300 Firmware < 2.7 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-4126
MEDIUM
HCL iNotes 9.0-10.0.1 - Unauthenticated Sensitive Cookie Exposure via HTTP Session Interception
CVSS 5.9
CVE-2020-7567
MEDIUM
Modicon M221 Firmware - Missing Encryption of Sensitive Data
CVSS 5.7
Details
Vulnerabilities
511
Exploit Likelihood
High