CWE-311— Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.— MITRE CWE catalog
564 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-311page 11 of 12
- CVE-2024-35061HIGHCVSS 7.3EG 7.32024-05-21
NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, …
- CVE-2024-38283MEDIUMCVSS 5.1EG 5.12024-06-13
Sensitive customer information is stored in the device without encryption.
- CVE-2024-38302MEDIUMCVSS 6.8EG 6.82024-07-18
Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading …
- CVE-2024-38325MEDIUMCVSS 5.9EG 5.92025-01-27
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerabi…
- CVE-2024-39746MEDIUMCVSS 5.9EG 5.92024-08-22
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerab…
- CVE-2024-40620HIGHCVSS 7.5EG 7.52024-08-14
CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be s…
- CVE-2024-41124MEDIUMCVSS 6.3EG 6.32024-07-19
Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can lead to issues like Eavesdropping, Data Tampering, Unauthorized Data Access & MITM Attacks…
- CVE-2024-41757MEDIUMCVSS 5.9EG 5.92025-01-24
IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive i…
- CVE-2024-41980LOWCVSS 3.1EG 3.12025-08-12
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application do not encry…
- CVE-2024-41982MEDIUMCVSS 4.8EG 4.82025-08-12
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not hav…
- CVE-2024-42495MEDIUMCVSS 6.5EG 6.52024-09-05
Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.
- CVE-2024-42657HIGHCVSS 7.5EG 7.52024-08-19
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
- CVE-2024-47871CRITICALCVSS 9.1EG 9.12024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is used. HTTPS is not e…
- CVE-2024-56439HIGHCVSS 7.5EG 7.52025-01-08
Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-5731MEDIUMCVSS 6.8EG 6.82024-06-14
A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating the parameter, thereby leveraging sensitive information.
- CVE-2024-7142MEDIUMCVSS 4.6EG 4.62025-01-10
On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured …
- CVE-2024-7396HIGHCVSS 7.1EG 7.12024-08-05
Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2.
- CVE-2025-10227MEDIUMCVSS 4.6EG 4.62025-09-10
Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract…
- CVE-2025-1243LOWCVSS 2.0EG 2.02025-02-12
The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC proxy prior to transmission. This resulted in information …
- CVE-2025-13053LOWCVSS 3.7EG 3.72025-12-12
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MI…
- CVE-2025-13453MEDIUMCVSS 4.6EG 6.82026-01-14
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.
- CVE-2025-15065MEDIUMCVSS 6.3EG 6.32025-12-29
Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co. KESS Enterprise on Windows allows Privil…
- CVE-2025-15548MEDIUMCVSS 6.5EG 6.52026-01-29
Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to intercept this traffic and compromise its confidentiality.
- CVE-2025-24008MEDIUMCVSS 6.5EG 6.52025-05-13
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not encrypt data in transit. An attacker with network access could eavesdrop t…
- CVE-2025-29314HIGHCVSS 8.1EG 8.12025-03-24
Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to access sensitive information via a man-in-the-middle attack.
- CVE-2025-31728MEDIUMCVSS 5.5EG 5.52025-04-02
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
- CVE-2025-31977MEDIUMCVSS 5.3EG 5.32025-08-28
HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms. An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.
- CVE-2025-32875CRITICALCVSS 5.7EG 9.82025-06-20
An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any …
- CVE-2025-33020MEDIUMCVSS 5.9EG 5.92025-07-23
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to obtain highly sensitive information.
- CVE-2025-36062MEDIUMCVSS 5.9EG 5.92025-07-21
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic.
- CVE-2025-36751CRITICALCVSS 9.4EG 9.42025-12-13
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its …
- CVE-2025-40680MEDIUMCVSS 6.9EG 6.92025-07-24
Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT session token in plain text within different registry keys on the Windows operating system. Any authenticated l…
- CVE-2025-43274MEDIUMCVSS 4.4EG 4.42025-07-30
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to circumvent sandbox restrictions.
- CVE-2025-45768HIGHCVSS 7.0EG 7.02025-07-31
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mec…
- CVE-2025-47274LOWCVSS 2.4EG 2.42025-05-12
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to the ordering of code used to start an MCP server container, versions of ToolHive prior to 0.0.33 inadvertently store s…
- CVE-2025-48862HIGHCVSS 7.1EG 7.12025-08-14
Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, whi…
- CVE-2025-48981HIGHCVSS 8.6EG 8.62025-10-08
An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.
- CVE-2025-53653MEDIUMCVSS 4.3EG 4.32025-07-09
Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the …
- CVE-2025-53659MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the J…
- CVE-2025-53663MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the …
- CVE-2025-53666MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller fi…
- CVE-2025-53668MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file …
- CVE-2025-53673MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller …
- CVE-2025-53676MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
- CVE-2025-53678MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
- CVE-2025-59410LOWCVSS 3.7EG 3.72025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an atta…
- CVE-2025-63579HIGHCVSS 7.5EG 7.52026-07-09
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypt…
- CVE-2025-64143MEDIUMCVSS 4.3EG 4.32025-10-29
Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins c…
- CVE-2025-64144MEDIUMCVSS 4.3EG 4.32025-10-29
Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file syste…
- CVE-2025-64145MEDIUMCVSS 4.3EG 4.32025-10-29
Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Map vulnerabilities like CWE-311 to your infrastructure
EchelonGraph correlates every CVE — across CWE-311 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →