Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-1342 Information Exposure through Microarchitectural State after Transient Execution Allowed 3
CWE-1300 Improper Protection of Physical Side Channels Allowed 3
CWE-1283 Mutable Attestation or Measurement Reporting Data Allowed 3
CWE-1280 Access Control Check Implemented After Asset is Accessed Allowed 3
CWE-1279 Cryptographic Operations are run Before Supporting Units are Ready Allowed 3
CWE-1269 Product Released in Non-Release Configuration Allowed 3
CWE-1233 Security-Sensitive Hardware Controls with Missing Lock Bit Protection Allowed 3
CWE-1231 Improper Prevention of Lock Bit Modification Allowed 3
CWE-1124 Excessively Deep Nesting Prohibited 3
CWE-1108 Excessive Reliance on Global Variables Allowed 3
CWE-1068 Inconsistency Between Implementation and Documented Design Prohibited 3
CWE-1059 Insufficient Technical Documentation Prohibited 3
CWE-1049 Excessive Data Query Operations in a Large Data Table Allowed 3
CWE-1039 Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism Allowed-with-Review 3
CWE-1007 Insufficient Visual Distinction of Homoglyphs Presented to User Allowed 3
CWE-910 Use of Expired File Descriptor Allowed 2
CWE-85 Doubled Character XSS Manipulations Allowed 2
CWE-769 DEPRECATED: Uncontrolled File Descriptor Consumption Prohibited 2
CWE-69 Improper Handling of Windows ::DATA Alternate Data Stream Allowed 2
CWE-689 Permission Race Condition During Resource Copy Allowed 2
CWE-685 Function Call With Incorrect Number of Arguments Allowed 2
CWE-624 Executable Regular Expression Error Allowed 2
CWE-622 Improper Validation of Function Hook Arguments Allowed 2
CWE-563 Assignment to Variable without Use Allowed 2
CWE-531 Inclusion of Sensitive Information in Test Code Allowed 2
CWE-528 Exposure of Core Dump File to an Unauthorized Control Sphere Allowed 2
CWE-50 Path Equivalence: '//multiple/leading/slash' Allowed 2
CWE-499 Serializable Class Containing Sensitive Data Allowed 2
CWE-479 Signal Handler Use of a Non-reentrant Function Allowed 2
CWE-455 Non-exit on Failed Initialization Allowed 2
CWE-450 Multiple Interpretations of UI Input Allowed 2
CWE-430 Deployment of Wrong Handler Allowed 2
CWE-422 Unprotected Windows Messaging Channel ('Shatter') Allowed 2
CWE-396 Declaration of Catch for Generic Exception Allowed 2
CWE-360 Trust of System Event Data Allowed 2
CWE-339 Small Seed Space in PRNG Allowed 2
CWE-32 Path Traversal: '...' (Triple Dot) Allowed 2
CWE-309 Use of Password System for Primary Authentication Allowed 2
CWE-236 Improper Handling of Undefined Parameters Allowed 2
CWE-205 Observable Behavioral Discrepancy Allowed 2
CWE-188 Reliance on Data/Memory Layout Allowed 2
CWE-186 Overly Restrictive Regular Expression Allowed 2
CWE-157 Failure to Sanitize Paired Delimiters Allowed 2
CWE-1422 Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution Allowed 2
CWE-135 Incorrect Calculation of Multi-Byte String Length Allowed 2