CWE-311: Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
272 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-34486 — Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
- CVE-2025-36751 — Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-X
- CVE-2026-32891 — Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
- CVE-2026-27944 — Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
- CVE-2025-24008 — A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2
- CVE-2025-15065 — Data Exposure in Kings Information & Network KESS Enterprise
- CVE-2024-47871 — Insecure communication between the FRP client and server in Gradio
- CVE-2026-77812 — Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE
- CVE-2026-81681 — openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage
- CVE-2024-56439 — Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability
- CVE-2025-65098 — Typebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization Bypass
- CVE-2026-81688 — openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256
- CVE-2025-48862 — Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup fi
- CVE-2024-42495 — Hughes Network Systems WL3000 Missing Encryption of Sensitive Data
- CVE-2025-13053 — A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
- CVE-2025-40680 — Encryption of sensitive data in CapillaryScope missing
- CVE-2024-5731 — A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to cont
- CVE-2024-38302 — Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (St
- CVE-2026-28678 — DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in
- CVE-2025-8763 — Ruijie EG306MG strongSwan strongswan.conf missing encryption
Recently published
- CVE-2026-81688 — openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256
- CVE-2026-81681 — openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage
- CVE-2026-77812 — Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE
- CVE-2026-19891 — TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption
- CVE-2026-20157 — Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
- CVE-2026-54784 — CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
- CVE-2026-55568 — Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
- CVE-2026-34486 — Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
- CVE-2026-34992 — Missing Encryption of Sensitive Data in antrea.io/antrea
- CVE-2026-32891 — Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
- CVE-2026-28678 — DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in
- CVE-2026-27944 — Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
- CVE-2025-15548 — Missing Application-Layer Encryption in Web Interface Endpoints on TP-Link VX800v
- CVE-2025-65098 — Typebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization Bypass
- CVE-2025-13453 — A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read
- CVE-2025-15065 — Data Exposure in Kings Information & Network KESS Enterprise
- CVE-2025-36751 — Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-X
- CVE-2025-13053 — A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
- CVE-2025-59410 — Dragonfly tiny file download uses hard coded HTTP protocol
- CVE-2025-10227 — Lack of Encryption in Object Archive in AxxonSoft Axxon One (C-Werk) before 2.0.8