The product does not encrypt sensitive or critical information before storage or transmission.
Volume of CVEs assigned to CWE-311 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
511 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27944CRITICAL Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys r | Mar 5, 2026 | 9.8 | 63 | NO | YES |
CVE-2026-34486HIGH Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomc | Apr 9, 2026 | 7.5 | 58 | NO | YES |
CVE-2017-8221HIGH Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which | Apr 25, 2017 | 7.5 | 35 | NO | YES |
CVE-2026-20157HIGH As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This revi | Jul 15, 2026 | 7.5 | 33 | NO | NO |
CVE-2025-63579HIGH Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed wit | Jul 9, 2026 | 7.5 | 32 | NO | NO |
CVE-2018-10698CRITICAL An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM positi | Jun 7, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-6526CRITICAL Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext | Apr 15, 2019 | 9.8 | 32 | NO | NO |
CVE-2026-54784HIGH CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof | Jul 8, 2026 | 7.4 | 31 | NO | NO |
CVE-2025-69969CRITICAL A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers t | Mar 4, 2026 | 9.6 | 31 | NO | NO |
CVE-2019-11523CRITICAL Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for e | Jun 6, 2019 | 9.8 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.