Threats Tagged 'cwe-311'
View all threats tagged with 'cwe-311'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-311'
Click on any threat for detailed analysis and mitigation recommendations
0 Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption. Join the discussion | CVE Database V5 | 09/17/2026, 19:20:37 UTC Added: 09/17/2026, 19:32:32 UTC |
0 Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database. Join the discussion | CVE Database V5 | 09/17/2026, 19:04:51 UTC Added: 09/17/2026, 19:32:32 UTC |
CVE-2026-77812 is a critical vulnerability affecting multiple DJI drone models where sensitive Wi-Fi credentials are transmitted over Bluetooth Low Energy (BLE) without encryption. An attacker within BLE range can passively capture these credentials, including the Wi-Fi SSID, PSK, and session UUID, enabling unauthorized access to the drone's Wi-Fi network and services. The credentials remain valid indefinitely unless manually reset, and the attack leaves no indication of compromise. A firmware update from DJI is required to remediate this issue. Join the discussion | CVE Database V5 | 08/21/2026, 14:06:55 UTC Added: 08/21/2026, 14:23:35 UTC |
A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing encryption of sensitive data. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The vendor was contacted early about this disclosure. Join the discussion | GCVE Database | 08/15/2026, 11:00:08 UTC Added: 08/15/2026, 15:53:09 UTC |
0 CVE-2026-21079 is a vulnerability in Samsung Mobile Smart Switch where sensitive data transmitted by the application prior to version 3.7.72.6 is not encrypted. This allows adjacent attackers to intercept the transmitted data. The vulnerability has a high severity rating with a CVSS score of 7. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 08/10/2026, 07:43:27 UTC Added: 08/10/2026, 08:26:50 UTC |
0 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. Join the discussion | GCVE Database | 04/09/2026, 19:35:35 UTC Added: 07/16/2026, 10:39:08 UTC |
0 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. Join the discussion | CVE Database V5 | 04/09/2026, 19:35:35 UTC Added: 04/09/2026, 20:06:42 UTC |
CVE-2026-34992 is a vulnerability in antrea-io's Antrea Kubernetes networking solution affecting versions prior to 2.4.5 and between 2.5.0 and 2.5.2. In dual-stack Kubernetes clusters configured with IPsec encryption enabled, IPv6 Pod traffic is not encrypted and is transmitted in plaintext, while IPv4 traffic remains encrypted. This occurs because the IPv6 packets bypass the IPsec encryption layer despite being encapsulated. Single-stack IPv4 or IPv6 clusters are not affected. Join the discussion | CVE Database V5 | 04/06/2026, 16:31:39 UTC Added: 04/07/2026, 05:37:51 UTC |
0 Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows any account holder to execute arbitrary JavaScript in the Anchorr admin's browser session. The injected script calls the authenticated /api/config endpoint - which returns the full application configuration in plaintext. This allows the attacker to forge a valid Anchorr session token and gain full admin access to the dashboard with no knowledge of the admin password. The same response also exposes the API keys and tokens for every integrated service, resulting in simultaneous account takeover of the Jellyfin media server (via JELLYFIN_API_KEY), the Jellyseerr request manager (via JELLYSEERR_API_KEY), and the Discord bot (via DISCORD_TOKEN). This issue has been fixed in version 1.4.2. Join the discussion | CVE Database V5 | 03/20/2026, 02:38:43 UTC Added: 03/20/2026, 03:24:21 UTC |
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3. Join the discussion | CVE Database V5 | 03/05/2026, 16:28:13 UTC Added: 03/05/2026, 18:21:10 UTC |
Showing 1 to 10 of 28 results