Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-1342 | Information Exposure through Microarchitectural State after Transient Execution | Allowed | 3 |
| CWE-1300 | Improper Protection of Physical Side Channels | Allowed | 3 |
| CWE-1283 | Mutable Attestation or Measurement Reporting Data | Allowed | 3 |
| CWE-1280 | Access Control Check Implemented After Asset is Accessed | Allowed | 3 |
| CWE-1279 | Cryptographic Operations are run Before Supporting Units are Ready | Allowed | 3 |
| CWE-1269 | Product Released in Non-Release Configuration | Allowed | 3 |
| CWE-1233 | Security-Sensitive Hardware Controls with Missing Lock Bit Protection | Allowed | 3 |
| CWE-1231 | Improper Prevention of Lock Bit Modification | Allowed | 3 |
| CWE-1124 | Excessively Deep Nesting | Prohibited | 3 |
| CWE-1108 | Excessive Reliance on Global Variables | Allowed | 3 |
| CWE-1068 | Inconsistency Between Implementation and Documented Design | Prohibited | 3 |
| CWE-1059 | Insufficient Technical Documentation | Prohibited | 3 |
| CWE-1049 | Excessive Data Query Operations in a Large Data Table | Allowed | 3 |
| CWE-1039 | Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism | Allowed-with-Review | 3 |
| CWE-1007 | Insufficient Visual Distinction of Homoglyphs Presented to User | Allowed | 3 |
| CWE-910 | Use of Expired File Descriptor | Allowed | 2 |
| CWE-85 | Doubled Character XSS Manipulations | Allowed | 2 |
| CWE-769 | DEPRECATED: Uncontrolled File Descriptor Consumption | Prohibited | 2 |
| CWE-69 | Improper Handling of Windows ::DATA Alternate Data Stream | Allowed | 2 |
| CWE-689 | Permission Race Condition During Resource Copy | Allowed | 2 |
| CWE-685 | Function Call With Incorrect Number of Arguments | Allowed | 2 |
| CWE-624 | Executable Regular Expression Error | Allowed | 2 |
| CWE-622 | Improper Validation of Function Hook Arguments | Allowed | 2 |
| CWE-563 | Assignment to Variable without Use | Allowed | 2 |
| CWE-531 | Inclusion of Sensitive Information in Test Code | Allowed | 2 |
| CWE-528 | Exposure of Core Dump File to an Unauthorized Control Sphere | Allowed | 2 |
| CWE-50 | Path Equivalence: '//multiple/leading/slash' | Allowed | 2 |
| CWE-499 | Serializable Class Containing Sensitive Data | Allowed | 2 |
| CWE-479 | Signal Handler Use of a Non-reentrant Function | Allowed | 2 |
| CWE-455 | Non-exit on Failed Initialization | Allowed | 2 |
| CWE-450 | Multiple Interpretations of UI Input | Allowed | 2 |
| CWE-430 | Deployment of Wrong Handler | Allowed | 2 |
| CWE-422 | Unprotected Windows Messaging Channel ('Shatter') | Allowed | 2 |
| CWE-396 | Declaration of Catch for Generic Exception | Allowed | 2 |
| CWE-360 | Trust of System Event Data | Allowed | 2 |
| CWE-339 | Small Seed Space in PRNG | Allowed | 2 |
| CWE-32 | Path Traversal: '...' (Triple Dot) | Allowed | 2 |
| CWE-309 | Use of Password System for Primary Authentication | Allowed | 2 |
| CWE-236 | Improper Handling of Undefined Parameters | Allowed | 2 |
| CWE-205 | Observable Behavioral Discrepancy | Allowed | 2 |
| CWE-188 | Reliance on Data/Memory Layout | Allowed | 2 |
| CWE-186 | Overly Restrictive Regular Expression | Allowed | 2 |
| CWE-157 | Failure to Sanitize Paired Delimiters | Allowed | 2 |
| CWE-1422 | Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution | Allowed | 2 |
| CWE-135 | Incorrect Calculation of Multi-Byte String Length | Allowed | 2 |