Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-1334 Unauthorized Error Injection Can Degrade Hardware Redundancy Allowed 2
CWE-1332 Improper Handling of Faults that Lead to Instruction Skips Allowed 2
CWE-1323 Improper Management of Sensitive Trace Data Allowed 2
CWE-1304 Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation Allowed 2
CWE-1301 Insufficient or Incomplete Data Removal within Hardware Component Allowed 2
CWE-1298 Hardware Logic Contains Race Conditions Allowed 2
CWE-1257 Improper Access Control Applied to Mirrored or Aliased Memory Regions Allowed 2
CWE-1251 Mirrored Regions with Different Values Allowed 2
CWE-1221 Incorrect Register Defaults or Module Parameters Allowed 2
CWE-1176 Inefficient CPU Computation Allowed-with-Review 2
CWE-1119 Excessive Use of Unconditional Branching Prohibited 2
CWE-1112 Incomplete Documentation of Program Execution Prohibited 2
CWE-111 Direct Use of Unsafe JNI Allowed 2
CWE-1107 Insufficient Isolation of Symbolic Constant Definitions Prohibited 2
CWE-1103 Use of Platform-Dependent Third Party Components Prohibited 2
CWE-1100 Insufficient Isolation of System-Dependent Functions Allowed 2
CWE-11 ASP.NET Misconfiguration: Creating Debug Binary Allowed 2
CWE-1076 Insufficient Adherence to Expected Conventions Prohibited 2
CWE-920 Improper Restriction of Power Consumption Allowed 1
CWE-828 Signal Handler with Functionality that is not Asynchronous-Safe Allowed 1
CWE-768 Incorrect Short Circuit Evaluation Allowed 1
CWE-765 Multiple Unlocks of a Critical Resource Allowed 1
CWE-761 Free of Pointer not at Start of Buffer Allowed 1
CWE-695 Use of Low-Level Functionality Allowed 1
CWE-673 External Influence of Sphere Definition Allowed-with-Review 1
CWE-663 Use of a Non-reentrant Function in a Concurrent Context Allowed 1
CWE-66 Improper Handling of File Names that Identify Virtual Resources Allowed 1
CWE-655 Insufficient Psychological Acceptability Allowed-with-Review 1
CWE-654 Reliance on a Single Factor in a Security Decision Allowed 1
CWE-638 Not Using Complete Mediation Allowed-with-Review 1
CWE-637 Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism') Allowed-with-Review 1
CWE-621 Variable Extraction Error Allowed 1
CWE-618 Exposed Unsafe ActiveX Method Allowed 1
CWE-600 Uncaught Exception in Servlet Allowed 1
CWE-6 J2EE Misconfiguration: Insufficient Session-ID Length Allowed 1
CWE-587 Assignment of a Fixed Address to a Pointer Allowed 1
CWE-571 Expression is Always True Allowed 1
CWE-570 Expression is Always False Allowed 1
CWE-555 J2EE Misconfiguration: Plaintext Password in Configuration File Allowed 1
CWE-553 Command Shell in Externally Accessible Directory Allowed 1
CWE-55 Path Equivalence: '/./' (Single Dot Directory) Allowed 1
CWE-541 Inclusion of Sensitive Information in an Include File Allowed 1
CWE-533 DEPRECATED: Information Exposure Through Server Log Files Prohibited 1
CWE-529 Exposure of Access Control List Files to an Unauthorized Control Sphere Allowed 1