Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-1334 | Unauthorized Error Injection Can Degrade Hardware Redundancy | Allowed | 2 |
| CWE-1332 | Improper Handling of Faults that Lead to Instruction Skips | Allowed | 2 |
| CWE-1323 | Improper Management of Sensitive Trace Data | Allowed | 2 |
| CWE-1304 | Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation | Allowed | 2 |
| CWE-1301 | Insufficient or Incomplete Data Removal within Hardware Component | Allowed | 2 |
| CWE-1298 | Hardware Logic Contains Race Conditions | Allowed | 2 |
| CWE-1257 | Improper Access Control Applied to Mirrored or Aliased Memory Regions | Allowed | 2 |
| CWE-1251 | Mirrored Regions with Different Values | Allowed | 2 |
| CWE-1221 | Incorrect Register Defaults or Module Parameters | Allowed | 2 |
| CWE-1176 | Inefficient CPU Computation | Allowed-with-Review | 2 |
| CWE-1119 | Excessive Use of Unconditional Branching | Prohibited | 2 |
| CWE-1112 | Incomplete Documentation of Program Execution | Prohibited | 2 |
| CWE-111 | Direct Use of Unsafe JNI | Allowed | 2 |
| CWE-1107 | Insufficient Isolation of Symbolic Constant Definitions | Prohibited | 2 |
| CWE-1103 | Use of Platform-Dependent Third Party Components | Prohibited | 2 |
| CWE-1100 | Insufficient Isolation of System-Dependent Functions | Allowed | 2 |
| CWE-11 | ASP.NET Misconfiguration: Creating Debug Binary | Allowed | 2 |
| CWE-1076 | Insufficient Adherence to Expected Conventions | Prohibited | 2 |
| CWE-920 | Improper Restriction of Power Consumption | Allowed | 1 |
| CWE-828 | Signal Handler with Functionality that is not Asynchronous-Safe | Allowed | 1 |
| CWE-768 | Incorrect Short Circuit Evaluation | Allowed | 1 |
| CWE-765 | Multiple Unlocks of a Critical Resource | Allowed | 1 |
| CWE-761 | Free of Pointer not at Start of Buffer | Allowed | 1 |
| CWE-695 | Use of Low-Level Functionality | Allowed | 1 |
| CWE-673 | External Influence of Sphere Definition | Allowed-with-Review | 1 |
| CWE-663 | Use of a Non-reentrant Function in a Concurrent Context | Allowed | 1 |
| CWE-66 | Improper Handling of File Names that Identify Virtual Resources | Allowed | 1 |
| CWE-655 | Insufficient Psychological Acceptability | Allowed-with-Review | 1 |
| CWE-654 | Reliance on a Single Factor in a Security Decision | Allowed | 1 |
| CWE-638 | Not Using Complete Mediation | Allowed-with-Review | 1 |
| CWE-637 | Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism') | Allowed-with-Review | 1 |
| CWE-621 | Variable Extraction Error | Allowed | 1 |
| CWE-618 | Exposed Unsafe ActiveX Method | Allowed | 1 |
| CWE-600 | Uncaught Exception in Servlet | Allowed | 1 |
| CWE-6 | J2EE Misconfiguration: Insufficient Session-ID Length | Allowed | 1 |
| CWE-587 | Assignment of a Fixed Address to a Pointer | Allowed | 1 |
| CWE-571 | Expression is Always True | Allowed | 1 |
| CWE-570 | Expression is Always False | Allowed | 1 |
| CWE-555 | J2EE Misconfiguration: Plaintext Password in Configuration File | Allowed | 1 |
| CWE-553 | Command Shell in Externally Accessible Directory | Allowed | 1 |
| CWE-55 | Path Equivalence: '/./' (Single Dot Directory) | Allowed | 1 |
| CWE-541 | Inclusion of Sensitive Information in an Include File | Allowed | 1 |
| CWE-533 | DEPRECATED: Information Exposure Through Server Log Files | Prohibited | 1 |
| CWE-529 | Exposure of Access Control List Files to an Unauthorized Control Sphere | Allowed | 1 |