CWE-311

High likelihood

Missing Encryption of Sensitive Data

Parent: CWE-693 - Protection Mechanism Failure

The product does not encrypt sensitive or critical information before storage or transmission.

508 vulnerabilities with CWE-311
CVE-2021-20567 MEDIUM
IBM Resilient SOAR <V38.0 - Info Disclosure
CVSS 4.4
CVE-2021-29248 MEDIUM
BTCPay Server <= 1.0.7.0 - Sensitive Information Exposure via Missing Secure Cookie Flag
CVSS 5.3
CVE-2020-15346 MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Path Traversal
CVSS 5.3
CVE-2020-15345 MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15344 MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15343 MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated API
CVSS 5.3
CVE-2020-15342 MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated RCE
CVSS 5.3
CVE-2020-15340 HIGH
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 7.5
CVE-2020-15331 CRITICAL
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 9.8
CVE-2020-15330 MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 5.3
CVE-2020-35168 MEDIUM
Dell BSAFE <4.1.5-4.6 - Use After Free
CVSS 4.7
CVE-2020-9058 HIGH
Silicon Labs 500 Series Firmware - Missing Encryption of Sensitive Data
CVSS 8.1
CVE-2020-9057 HIGH
Linear Wadwaz-1 - Missing Encryption
CVSS 8.8
CVE-2020-29024 MEDIUM
Secomea GateManager <9.3 - Info Disclosure
CVSS 5.3
CVE-2020-26732 HIGH
SKYWORTH GN542VF 2.0.0.16 - Missing Secure Flag for Session Cookie
CVSS 7.5
CVE-2020-25842 HIGH
NHIServiSignAdapter - Unauthenticated Arbitrary File Access via Path Verification Bypass
CVSS 7.5
CVE-2020-35587 HIGH
Solstice Pod < 3.0.3 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-27055 HIGH
Android 11 - Remote Information Disclosure via WiFi Configuration Input Validation
CVSS 7.5
CVE-2020-28217 HIGH
Easergy T300 Firmware < 2.7 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-28216 HIGH
Easergy T300 Firmware < 2.7 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2020-4126 MEDIUM
HCL iNotes 9.0-10.0.1 - Unauthenticated Sensitive Cookie Exposure via HTTP Session Interception
CVSS 5.9
CVE-2020-7567 MEDIUM
Modicon M221 Firmware - Missing Encryption of Sensitive Data
CVSS 5.7
CVE-2020-8150 MEDIUM
Nextcloud Server 19.0.1 - Info Disclosure
CVSS 4.1
CVE-2020-8173 LOW
Nextcloud Server <18.0.4 - Info Disclosure
CVSS 2.2
CVE-2020-27651 MEDIUM
Synology Router Manager <1.2.4-8081 - Info Disclosure
CVSS 5.8
Details
Vulnerabilities 508
Exploit Likelihood High