Skip to main content

CWE archive

CWE-311 CVEs

Programmatic archive

511 CVEs tagged with CWE-31128 Critical, 269 High, 192 Medium, 22 Low, 0 Unrated.

CVE-2026-20157

Published Jul 15, 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This rev…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2025-63579

Published Jul 9, 2026

Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed wi…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54784

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proo…

CVSS 7.4 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-55568

Published Jun 23, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. P…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53442

Published Jun 10, 2026

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xm…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34486

Published Apr 9, 2026

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tom…

CVSS 7.5 · High
evidence mentions
19
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-34992

Published Apr 6, 2026

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encryption vulnerability affects inter-Node Pod traffic. In Antrea…

CVSS 7.1 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-32891

Published Mar 20, 2026

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulne…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-27944

Published Mar 5, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-15548

Published Jan 29, 2026

Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-13453

Published Jan 14, 2026

A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-15065

Published Dec 29, 2025

Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Inform…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-36751

Published Dec 13, 2025

Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manip…

CVSS 9.4 · Critical

CVE-2025-13053

Published Dec 12, 2025

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic betwe…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-64147

Published Oct 29, 2025

Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64146

Published Oct 29, 2025

Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read per…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64145

Published Oct 29, 2025

Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64144

Published Oct 29, 2025

Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Rea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64143

Published Oct 29, 2025

Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users wi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48981

Published Oct 8, 2025

An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because enc…

CVSS 8.6 · High

CVE-2025-59410

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 511 CVEsPage 1 of 21