Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-81 Improper Neutralization of Script in an Error Message Web Page Allowed 8
CWE-573 Improper Following of Specification by Caller Allowed-with-Review 8
CWE-466 Return of Pointer Value Outside of Expected Range Allowed 8
CWE-456 Missing Initialization of a Variable Allowed 8
CWE-372 Incomplete Internal State Distinction Discouraged 8
CWE-196 Unsigned to Signed Conversion Error Allowed 8
CWE-1282 Assumed-Immutable Data is Stored in Writable Memory Allowed 8
CWE-1270 Generation of Incorrect Security Tokens Allowed 8
CWE-127 Buffer Under-read Allowed 8
CWE-710 Improper Adherence to Coding Standards Discouraged 7
CWE-705 Incorrect Control Flow Scoping Allowed-with-Review 7
CWE-67 Improper Handling of Windows Device Names Allowed 7
CWE-662 Improper Synchronization Discouraged 7
CWE-65 Windows Hard Link Allowed 7
CWE-645 Overly Restrictive Account Lockout Mechanism Allowed 7
CWE-626 Null Byte Interaction Error (Poison Null Byte) Allowed 7
CWE-421 Race Condition During Access to Alternate Channel Allowed 7
CWE-408 Incorrect Behavior Order: Early Amplification Allowed 7
CWE-342 Predictable Exact Value from Previous Values Allowed 7
CWE-317 Cleartext Storage of Sensitive Information in GUI Allowed 7
CWE-192 Integer Coercion Error Allowed 7
CWE-1173 Improper Use of Validation Framework Allowed 7
CWE-112 Missing XML Validation Allowed 7
CWE-1088 Synchronous Access of Remote Resource without Timeout Allowed 7
CWE-914 Improper Control of Dynamically-Identified Variables Allowed 6
CWE-784 Reliance on Cookies without Validation and Integrity Checking in a Security Decision Allowed 6
CWE-783 Operator Precedence Logic Error Allowed 6
CWE-775 Missing Release of File Descriptor or Handle after Effective Lifetime Allowed 6
CWE-771 Missing Reference to Active Allocated Resource Allowed 6
CWE-671 Lack of Administrator Control over Security Allowed-with-Review 6
CWE-566 Authorization Bypass Through User-Controlled SQL Primary Key Allowed 6
CWE-562 Return of Stack Variable Address Allowed 6
CWE-539 Use of Persistent Cookies Containing Sensitive Information Allowed 6
CWE-412 Unrestricted Externally Accessible Lock Allowed 6
CWE-403 Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak') Allowed 6
CWE-37 Path Traversal: '/absolute/pathname/here' Allowed 6
CWE-315 Cleartext Storage of Sensitive Information in a Cookie Allowed 6
CWE-298 Improper Validation of Certificate Expiration Allowed 6
CWE-262 Not Using Password Aging Allowed 6
CWE-249 DEPRECATED: Often Misused: Path Manipulation Prohibited 6
CWE-219 Storage of File with Sensitive Data Under Web Root Allowed 6
CWE-173 Improper Handling of Alternate Encoding Allowed 6
CWE-1423 Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution Allowed 6
CWE-1389 Incorrect Parsing of Numbers with Different Radices Allowed 6
CWE-1329 Reliance on Component That is Not Updateable Allowed 6
CWE-1328 Security Version Number Mutable to Older Versions Allowed 6
CWE-1320 Improper Protection for Outbound Error Messages and Alert Signals Allowed 6
CWE-1274 Improper Access Control for Volatile Memory Containing Boot Code Allowed 6
CWE-1256 Improper Restriction of Software Interfaces to Hardware Features Allowed 6