Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-1250 Improper Preservation of Consistency Between Independent Representations of Shared State Allowed 6
CWE-1189 Improper Isolation of Shared Resources on System-on-a-Chip (SoC) Allowed 6
CWE-1038 Insecure Automated Optimizations Allowed-with-Review 6
CWE-97 Improper Neutralization of Server-Side Includes (SSI) Within a Web Page Allowed 5
CWE-794 Incomplete Filtering of Multiple Instances of Special Elements Allowed 5
CWE-777 Regular Expression without Anchors Allowed 5
CWE-649 Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking Allowed 5
CWE-627 Dynamic Variable Evaluation Allowed 5
CWE-599 Missing Validation of OpenSSL Certificate Allowed 5
CWE-550 Server-generated Error Message Containing Sensitive Information Allowed 5
CWE-544 Missing Standardized Error Handling Mechanism Allowed 5
CWE-40 Path Traversal: '\\UNC\share\name\' (Windows UNC Share) Allowed 5
CWE-343 Predictable Value Range from Previous Values Allowed 5
CWE-332 Insufficient Entropy in PRNG Allowed 5
CWE-278 Insecure Preserved Inherited Permissions Allowed 5
CWE-179 Incorrect Behavior Order: Early Validation Allowed 5
CWE-167 Improper Handling of Additional Special Element Allowed 5
CWE-153 Improper Neutralization of Substitution Characters Allowed 5
CWE-149 Improper Neutralization of Quoting Syntax Allowed 5
CWE-147 Improper Neutralization of Input Terminators Allowed 5
CWE-1303 Non-Transparent Sharing of Microarchitectural Resources Allowed 5
CWE-1281 Sequence of Processor Instructions Leads to Unexpected Behavior Allowed 5
CWE-1254 Incorrect Comparison Logic Granularity Allowed 5
CWE-1245 Improper Finite State Machines (FSMs) in Hardware Logic Allowed 5
CWE-1204 Generation of Weak Initialization Vector (IV) Allowed 5
CWE-1077 Floating Point Comparison with Incorrect Operator Allowed 5
CWE-839 Numeric Range Comparison Without Minimum Check Allowed 4
CWE-792 Incomplete Filtering of One or More Instances of Special Elements Allowed 4
CWE-786 Access of Memory Location Before Start of Buffer Discouraged 4
CWE-774 Allocation of File Descriptors or Handles Without Limits or Throttling Allowed 4
CWE-767 Access to Critical Private Variable via Public Method Allowed 4
CWE-733 Compiler Optimization Removal or Modification of Security-critical Code Allowed 4
CWE-686 Function Call With Incorrect Argument Type Allowed 4
CWE-683 Function Call With Incorrect Order of Arguments Allowed 4
CWE-520 .NET Misconfiguration: Use of Impersonation Allowed 4
CWE-473 PHP External Variable Modification Allowed 4
CWE-454 External Initialization of Trusted Variables or Data Stores Allowed 4
CWE-414 Missing Lock Check Allowed 4
CWE-368 Context Switching Race Condition Allowed 4
CWE-240 Improper Handling of Inconsistent Structural Elements Allowed 4
CWE-235 Improper Handling of Extra Parameters Allowed 4
CWE-231 Improper Handling of Extra Values Allowed 4
CWE-216 DEPRECATED: Containment Errors (Container Errors) Prohibited 4
CWE-210 Self-generated Error Message Containing Sensitive Information Allowed 4
CWE-194 Unexpected Sign Extension Allowed 4
CWE-156 Improper Neutralization of Whitespace Allowed 4
CWE-1421 Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution Allowed 4
CWE-1420 Exposure of Sensitive Information during Transient Execution Allowed-with-Review 4
CWE-1335 Incorrect Bitwise Shift of Integer Allowed 4