CWE-311
High likelihoodMissing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
508 vulnerabilities with CWE-311
CVE-2021-20567
MEDIUM
IBM Resilient SOAR <V38.0 - Info Disclosure
CVSS 4.4
CVE-2021-29248
MEDIUM
BTCPay Server <= 1.0.7.0 - Sensitive Information Exposure via Missing Secure Cookie Flag
CVSS 5.3
CVE-2020-15346
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Path Traversal
CVSS 5.3
CVE-2020-15345
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15344
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15343
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated API
CVSS 5.3
CVE-2020-15342
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15340
HIGH
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 7.5
CVE-2020-15331
CRITICAL
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 9.8
CVE-2020-15330
MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 5.3
CVE-2020-35168
MEDIUM
Dell BSAFE <4.1.5-4.6 - Use After Free
CVSS 4.7
CVE-2020-9058
HIGH
Silicon Labs 500 Series Firmware - Missing Encryption of Sensitive Data
CVSS 8.1
CVE-2020-9057
HIGH
Linear Wadwaz-1 - Missing Encryption
CVSS 8.8
CVE-2020-29024
MEDIUM
Secomea GateManager <9.3 - Info Disclosure
CVSS 5.3
CVE-2020-26732
HIGH
SKYWORTH GN542VF 2.0.0.16 - Missing Secure Flag for Session Cookie
CVSS 7.5
CVE-2020-25842
HIGH
NHIServiSignAdapter - Unauthenticated Arbitrary File Access via Path Verification Bypass
CVSS 7.5
CVE-2020-35587
HIGH
Solstice Pod < 3.0.3 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-27055
HIGH
Android 11 - Remote Information Disclosure via WiFi Configuration Input Validation
CVSS 7.5
CVE-2020-28217
HIGH
Easergy T300 Firmware < 2.7 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-28216
HIGH
Easergy T300 Firmware < 2.7 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-4126
MEDIUM
HCL iNotes 9.0-10.0.1 - Unauthenticated Sensitive Cookie Exposure via HTTP Session Interception
CVSS 5.9
CVE-2020-7567
MEDIUM
Modicon M221 Firmware - Missing Encryption of Sensitive Data
CVSS 5.7
CVE-2020-8150
MEDIUM
Nextcloud Server 19.0.1 - Info Disclosure
CVSS 4.1
CVE-2020-8173
LOW
Nextcloud Server <18.0.4 - Info Disclosure
CVSS 2.2
CVE-2020-27651
MEDIUM
Synology Router Manager <1.2.4-8081 - Info Disclosure
CVSS 5.8
Details
Vulnerabilities
508
Exploit Likelihood
High