Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-1250 | Improper Preservation of Consistency Between Independent Representations of Shared State | Allowed | 6 |
| CWE-1189 | Improper Isolation of Shared Resources on System-on-a-Chip (SoC) | Allowed | 6 |
| CWE-1038 | Insecure Automated Optimizations | Allowed-with-Review | 6 |
| CWE-97 | Improper Neutralization of Server-Side Includes (SSI) Within a Web Page | Allowed | 5 |
| CWE-794 | Incomplete Filtering of Multiple Instances of Special Elements | Allowed | 5 |
| CWE-777 | Regular Expression without Anchors | Allowed | 5 |
| CWE-649 | Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking | Allowed | 5 |
| CWE-627 | Dynamic Variable Evaluation | Allowed | 5 |
| CWE-599 | Missing Validation of OpenSSL Certificate | Allowed | 5 |
| CWE-550 | Server-generated Error Message Containing Sensitive Information | Allowed | 5 |
| CWE-544 | Missing Standardized Error Handling Mechanism | Allowed | 5 |
| CWE-40 | Path Traversal: '\\UNC\share\name\' (Windows UNC Share) | Allowed | 5 |
| CWE-343 | Predictable Value Range from Previous Values | Allowed | 5 |
| CWE-332 | Insufficient Entropy in PRNG | Allowed | 5 |
| CWE-278 | Insecure Preserved Inherited Permissions | Allowed | 5 |
| CWE-179 | Incorrect Behavior Order: Early Validation | Allowed | 5 |
| CWE-167 | Improper Handling of Additional Special Element | Allowed | 5 |
| CWE-153 | Improper Neutralization of Substitution Characters | Allowed | 5 |
| CWE-149 | Improper Neutralization of Quoting Syntax | Allowed | 5 |
| CWE-147 | Improper Neutralization of Input Terminators | Allowed | 5 |
| CWE-1303 | Non-Transparent Sharing of Microarchitectural Resources | Allowed | 5 |
| CWE-1281 | Sequence of Processor Instructions Leads to Unexpected Behavior | Allowed | 5 |
| CWE-1254 | Incorrect Comparison Logic Granularity | Allowed | 5 |
| CWE-1245 | Improper Finite State Machines (FSMs) in Hardware Logic | Allowed | 5 |
| CWE-1204 | Generation of Weak Initialization Vector (IV) | Allowed | 5 |
| CWE-1077 | Floating Point Comparison with Incorrect Operator | Allowed | 5 |
| CWE-839 | Numeric Range Comparison Without Minimum Check | Allowed | 4 |
| CWE-792 | Incomplete Filtering of One or More Instances of Special Elements | Allowed | 4 |
| CWE-786 | Access of Memory Location Before Start of Buffer | Discouraged | 4 |
| CWE-774 | Allocation of File Descriptors or Handles Without Limits or Throttling | Allowed | 4 |
| CWE-767 | Access to Critical Private Variable via Public Method | Allowed | 4 |
| CWE-733 | Compiler Optimization Removal or Modification of Security-critical Code | Allowed | 4 |
| CWE-686 | Function Call With Incorrect Argument Type | Allowed | 4 |
| CWE-683 | Function Call With Incorrect Order of Arguments | Allowed | 4 |
| CWE-520 | .NET Misconfiguration: Use of Impersonation | Allowed | 4 |
| CWE-473 | PHP External Variable Modification | Allowed | 4 |
| CWE-454 | External Initialization of Trusted Variables or Data Stores | Allowed | 4 |
| CWE-414 | Missing Lock Check | Allowed | 4 |
| CWE-368 | Context Switching Race Condition | Allowed | 4 |
| CWE-240 | Improper Handling of Inconsistent Structural Elements | Allowed | 4 |
| CWE-235 | Improper Handling of Extra Parameters | Allowed | 4 |
| CWE-231 | Improper Handling of Extra Values | Allowed | 4 |
| CWE-216 | DEPRECATED: Containment Errors (Container Errors) | Prohibited | 4 |
| CWE-210 | Self-generated Error Message Containing Sensitive Information | Allowed | 4 |
| CWE-194 | Unexpected Sign Extension | Allowed | 4 |
| CWE-156 | Improper Neutralization of Whitespace | Allowed | 4 |
| CWE-1421 | Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution | Allowed | 4 |
| CWE-1420 | Exposure of Sensitive Information during Transient Execution | Allowed-with-Review | 4 |
| CWE-1335 | Incorrect Bitwise Shift of Integer | Allowed | 4 |