CWE-311
CVEs classified under CWE-311, newest first.
13 CVEsRSS
CVE-2026-92757Medium· 5.5Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
CVE-2026-92756Medium· 5.5Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…
CVE-2026-19891Low· 3.7A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02
A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing enc…
GHSA-464c-974j-9xm6Low· 3.3AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
CVE-2026-20157High· 7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…
CVE-2026-55568Medium· 5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-54784High· 7.4CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVE-2026-34486High· 7.5CISA KEVPoCMissing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …
CVE-2023-28045Medium· 6.3Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability
Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data.
CVE-2023-28841Medium· 6.8Moby is an open source container framework developed by Docker Inc
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…
CVE-2021-40650Medium· 6.5In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
CVE-2022-26281High· 7.5BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
CVE-2017-6297Medium· 5.9The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server…
The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server…