CWE-311: CWE-311

45
Total CVEs
5
Critical
16
High
6.6
Avg CVSS

Yearly Trend

2026
3
2025
21
2024
9
2023
5
2022
4

Top Affected Vendors

1 Jenkins 10
2 Synology 2
3 Hcltech 2
4 Siemens 2
5 Huawei 2
6 Lenovo 1
7 Bitcoin 1
8 Nasa 1
9 Google 1
10 Silabs 1

All CWE-311 CVEs (45)

CVE-2023-6339
10.0

CVE-2023-6339 is a critical vulnerability in Google Nest WiFi Pro routers that allows remote attackers to execute arbitrary code with root privileges ...

Jan 2, 2024
CVE-2025-69969
9.6

This critical vulnerability in Pebble Prism Ultra v2.9.2 allows attackers within Bluetooth range to execute arbitrary commands, intercept data, and hi...

Mar 4, 2026
CVE-2024-47871
9.1

This vulnerability allows attackers to intercept and read files uploaded to Gradio servers when using the share=True option, as HTTPS is not enforced....

Oct 10, 2024
CVE-2023-38699
9.1

MindsDB versions before 23.7.4.0 had disabled SSL certificate verification in requests, allowing man-in-the-middle attacks to intercept and potentiall...

Aug 4, 2023
CVE-2021-27779
9.1

CVE-2021-27779 is a critical information disclosure vulnerability in HCL VersionVault Express that exposes sensitive information. Attackers can exploi...

May 25, 2022
CVE-2025-48981
8.6

An insecure implementation of the proprietary DNET protocol in CGM MEDICO allows attackers on the same intranet to eavesdrop on and manipulate data tr...

Oct 8, 2025
CVE-2025-29314
8.1

This vulnerability allows attackers to intercept and access sensitive information transmitted via insecure Shiro cookies in OpenDaylight SFC. Attacker...

Mar 24, 2025
CVE-2020-9058
8.1

This CVE describes a vulnerability in Z-Wave devices using Silicon Labs 500 series chipsets that lack encryption and replay protection. Attackers can ...

Jan 10, 2022
CVE-2024-56439
7.5

This CVE describes an access control vulnerability in Huawei's identity authentication module that could allow unauthorized access to sensitive inform...

Jan 8, 2025
CVE-2024-40620
7.5

This vulnerability allows unencrypted transmission of sensitive data between Console and Dashboard components in Rockwell Automation products. Attacke...

Aug 14, 2024
CVE-2023-38688
7.5

This vulnerability in twitch-tui allows attackers to intercept unencrypted communications between the application and Twitch IRC servers. All users ru...

Aug 4, 2023
CVE-2023-31819
7.5

This vulnerability in KEISEI STORE's LIVRE KEISEI software version 13.6.1 allows remote attackers to access sensitive information through improper han...

Jul 13, 2023
CVE-2023-31822
7.5

This vulnerability in Entetsu Store v.13.4.1 allows remote attackers to access sensitive information through the channel access token in the miniapp f...

Jul 13, 2023
CVE-2023-37192
7.5

This vulnerability in Bitcoin Core allows attackers to manipulate memory to change transaction destination addresses, potentially redirecting Bitcoin ...

Jul 7, 2023
CVE-2022-26281
7.5

BigAnt Server v5.6.06 contains an incorrect access control vulnerability that allows unauthorized users to bypass authentication mechanisms. This affe...

Apr 5, 2022
CVE-2022-23116
7.5

This vulnerability in Jenkins Conjur Secrets Plugin allows attackers who control Jenkins agent processes to decrypt secrets stored in Jenkins that wer...

Jan 12, 2022
CVE-2021-37050
7.5

This CVE describes a missing sensitive data encryption vulnerability in Huawei smartphones running HarmonyOS. Attackers could potentially access unenc...

Dec 8, 2021
CVE-2021-33900
7.5

Apache Directory Studio versions 2.0.0.v20210213-M16 and earlier fail to apply StartTLS encryption when using SASL authentication mechanisms (DIGEST-M...

Jul 26, 2021
CVE-2021-40366
7.4

This vulnerability affects Climatix POL909 building automation controllers. It allows unauthenticated attackers to intercept unencrypted web traffic, ...

Nov 9, 2021
CVE-2024-35061
7.3

NASA AIT-Core v2.5.2 uses unencrypted network channels, enabling man-in-the-middle attacks. When combined with CVE-2024-35059, this allows unauthentic...

May 21, 2024
CVE-2025-48862
7.1

This vulnerability involves misleading interface wording in ctrlX OS backup functionality that suggests backup files are encrypted when a password is ...

Aug 14, 2025
CVE-2025-53676
6.5

The Jenkins Xooa Plugin 0.0.7 and earlier stores sensitive deployment tokens unencrypted in Jenkins configuration files. This allows attackers with fi...

Jul 9, 2025
CVE-2025-53678
6.5

The Jenkins User1st uTester Plugin 1.1 and earlier stores JWT tokens unencrypted in global configuration files on the Jenkins controller. This allows ...

Jul 9, 2025
CVE-2025-53666
6.5

The Jenkins Dead Man's Snitch Plugin 0.1 stores sensitive authentication tokens unencrypted in job configuration files. This allows users with Item/Ex...

Jul 9, 2025
CVE-2025-53668
6.5

The Jenkins VAddy Plugin 1.2.8 and earlier stores VAddy API authentication keys unencrypted in job configuration files. This allows users with Item/Ex...

Jul 9, 2025
CVE-2025-24008
6.5

This vulnerability allows attackers to eavesdrop on unencrypted network communications of Siemens SIRIUS safety systems. Attackers with network access...

May 13, 2025
CVE-2024-20515
6.5

An authenticated attacker with Read-Only Administrator privileges in Cisco Identity Services Engine (ISE) can exploit improper data protection mechani...

Oct 2, 2024
CVE-2024-42495
6.5

This vulnerability allows attackers to intercept credentials transmitted via unencrypted protocols, granting read-only access to network and terminal ...

Sep 5, 2024
CVE-2025-36062
5.9

IBM Cognos Analytics Mobile for iOS versions 1.1.0 through 1.1.22 transmits data over unencrypted network connections, potentially exposing sensitive ...

Jul 21, 2025
CVE-2025-31977
5.3

HCL BigFix SM has a cryptographic weakness due to weak or outdated encryption algorithms, allowing attackers with network access to potentially decryp...

Aug 28, 2025
CVE-2023-52950
5.3

This vulnerability allows attackers on the same network segment to intercept unencrypted login credentials for Synology Active Backup for Business Age...

Sep 26, 2024
CVE-2023-49927
5.3

A vulnerability in Samsung Exynos baseband software allows improper format type checking in RRC (Radio Resource Control) messages, potentially leading...

Jun 5, 2024
CVE-2023-52948
5.0

This vulnerability allows local users on systems running Synology Active Backup for Business Agent to access unencrypted user credentials stored in se...

Sep 26, 2024
CVE-2024-41982
4.8

This vulnerability in Siemens SmartClient modules allows authenticated attackers to access sensitive information due to inadequate encryption. Affecte...

Aug 12, 2025
CVE-2025-13453
4.6

A physical security vulnerability in certain ThinkPlus USB drives allows unauthorized data access when an attacker has physical possession of the devi...

Jan 14, 2026
CVE-2025-65825
4.6

The Meatmeet device's firmware lacks encryption, allowing attackers with physical access to extract Wi-Fi credentials via UART interface. This exposes...

Dec 10, 2025
CVE-2024-7142
4.6

This vulnerability affects Arista CloudVision Appliance (CVA) DCA-350E-CV models where hardware disk encryption fails to activate properly, leaving da...

Jan 10, 2025
CVE-2025-64144
4.3

The Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens in plaintext within job configuration files, allowing users with Item/Extended Read p...

Oct 29, 2025
CVE-2025-64145
4.3

The Jenkins ByteGuard Build Actions Plugin 1.0 fails to mask API tokens in the job configuration form, potentially exposing sensitive credentials to u...

Oct 29, 2025
CVE-2025-64146
4.3

The Jenkins Curseforge Publisher Plugin 1.0 stores API keys in plaintext within job configuration files, allowing users with Item/Extended Read permis...

Oct 29, 2025
CVE-2025-64147
4.3

The Jenkins Curseforge Publisher Plugin 1.0 displays API keys in plain text on job configuration forms instead of masking them. This allows attackers ...

Oct 29, 2025
CVE-2025-64143
4.3

The Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job configuration files, allowing users with Item/...

Oct 29, 2025
CVE-2025-13053
3.7

This vulnerability allows man-in-the-middle attackers to intercept and potentially modify communications between ASUSTOR NAS devices and UPS servers d...

Dec 12, 2025
CVE-2025-15548
N/A

The TP-Link VX800v v1.0 web interface transmits sensitive information over unencrypted HTTP connections due to missing application layer encryption. T...

Jan 29, 2026
CVE-2025-36751
N/A

Growatt ShineLan-X and MIC 3300TL-X inverters lack encryption on their configuration interface, allowing network-accessible attackers to intercept and...

Dec 13, 2025

About CWE-311 (CWE-311)

Our database tracks 45 CVEs classified as CWE-311, with 5 rated critical and 16 rated high severity. The average CVSS score for CWE-311 vulnerabilities is 6.6.

External reference: View CWE-311 on MITRE CWE →

Monitor CWE-311 Vulnerabilities

Get alerted when new CWE-311 CVEs affect your infrastructure.

Start Monitoring Free