VulnSea

CWE-311

CVEs classified under CWE-311, newest first.

13 CVEsRSS

CVE-2026-92757Medium· 5.5
5d ago

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

SunlitMongoDB Inc. · MongoDB Entity Framework Core ProviderEPSS 0.05%via NVD
CVE-2026-92756Medium· 5.5
5d ago

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…

SunlitMongoDB Inc. · MongoDB Entity Framework Core ProviderEPSS 0.05%via NVD
CVE-2026-19891Low· 3.7
1mo ago

A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02

A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing enc…

SunlitEPSS 0.12%via NVD
GHSA-464c-974j-9xm6Low· 3.3
2mo ago

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

Sunlitaws-cdk-lib · aws-cdk-libvia OSV
CVE-2026-20157High· 7.5
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

Twilightcisco · roomosEPSS 0.11%via NVD
CVE-2026-55568Medium· 5.9
3mo ago

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.15%via GHSA
CVE-2026-54784High· 7.4
3mo ago

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.27%via GHSA
CVE-2026-34486High· 7.5CISA KEVPoC
5mo ago

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

Abyssalapache · tomcatEPSS 99%via NVD
CVE-2023-28045Medium· 6.3
3y ago

Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability

Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data.

Sunlitdell · aiops_collectorEPSS 0.18%via NVD
CVE-2023-28841Medium· 6.8
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

Sunlitmobyproject · mobyEPSS 0.69%via NVD
CVE-2021-40650Medium· 6.5
4y ago

In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

Sunlitsoftwareag · connxEPSS 0.77%via NVD
CVE-2022-26281High· 7.5
4y ago

BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

Twilightbigantsoft · bigant_serverEPSS 0.95%via NVD
CVE-2017-6297Medium· 5.9
9y ago

The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server…

The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server…

Sunlitmikrotik · routerosEPSS 0.76%via NVD
CWE-311 vulnerabilities (CVEs) · VulnSea