Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-1322 Use of Blocking Code in Single-threaded, Non-blocking Context Allowed 4
CWE-1319 Improper Protection against Electromagnetic Fault Injection (EM-FI) Allowed 4
CWE-128 Wrap-around Error Allowed 4
CWE-1247 Improper Protection Against Voltage and Clock Glitches Allowed 4
CWE-1234 Hardware Internal or Debug Modes Allow Override of Locks Allowed 4
CWE-1125 Excessive Attack Surface Prohibited 4
CWE-1037 Processor Optimization Removal or Modification of Security-critical Code Allowed 4
CWE-925 Improper Verification of Intent by Broadcast Receiver Allowed 3
CWE-827 Improper Control of Document Type Definition Allowed 3
CWE-780 Use of RSA Algorithm without OAEP Allowed 3
CWE-756 Missing Custom Error Page Allowed 3
CWE-688 Function Call With Incorrect Variable or Reference as Argument Allowed 3
CWE-687 Function Call With Incorrectly Specified Argument Value Allowed 3
CWE-675 Multiple Operations on Resource in Single-Operation Context Allowed-with-Review 3
CWE-666 Operation on Resource in Wrong Phase of Lifetime Discouraged 3
CWE-623 Unsafe ActiveX Control Marked Safe For Scripting Allowed 3
CWE-62 UNIX Hard Link Allowed 3
CWE-616 Incomplete Identification of Uploaded File Variables (PHP) Allowed 3
CWE-615 Inclusion of Sensitive Information in Source Code Comments Allowed 3
CWE-605 Multiple Binds to the Same Port Allowed 3
CWE-597 Use of Wrong Operator in String Comparison Allowed 3
CWE-588 Attempt to Access Child of a Non-structure Pointer Allowed 3
CWE-534 DEPRECATED: Information Exposure Through Debug Log Files Prohibited 3
CWE-527 Exposure of Version-Control Repository to an Unauthorized Control Sphere Allowed 3
CWE-474 Use of Function with Inconsistent Implementations Allowed 3
CWE-468 Incorrect Pointer Scaling Allowed 3
CWE-467 Use of sizeof() on a Pointer Type Allowed 3
CWE-448 Obsolete Feature in UI Allowed 3
CWE-447 Unimplemented or Unsupported Feature in UI Allowed 3
CWE-446 UI Discrepancy for Security Feature Allowed-with-Review 3
CWE-437 Incomplete Model of Endpoint Features Allowed 3
CWE-435 Improper Interaction Between Multiple Correctly-Behaving Entities Discouraged 3
CWE-344 Use of Invariant Value in Dynamically Changing Context Allowed 3
CWE-336 Same Seed in Pseudo-Random Number Generator (PRNG) Allowed 3
CWE-239 Failure to Handle Incomplete Element Allowed 3
CWE-237 Improper Handling of Structural Elements Allowed 3
CWE-182 Collapse of Data into Unsafe Value Allowed 3
CWE-174 Double Decoding of the Same Data Allowed 3
CWE-168 Improper Handling of Inconsistent Special Elements Allowed 3
CWE-166 Improper Handling of Missing Special Element Allowed 3
CWE-164 Improper Neutralization of Internal Special Elements Allowed 3
CWE-148 Improper Neutralization of Input Leaders Allowed 3
CWE-144 Improper Neutralization of Line Delimiters Allowed 3
CWE-1428 Reliance on HTTP instead of HTTPS Allowed 3
CWE-1426 Improper Validation of Generative AI Output Discouraged 3
CWE-142 Improper Neutralization of Value Delimiters Allowed 3
CWE-1384 Improper Handling of Physical or Environmental Conditions Allowed-with-Review 3