Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-515 Covert Storage Channel Allowed 1
CWE-514 Covert Channel Allowed-with-Review 1
CWE-509 Replicating Malicious Code (Virus or Worm) Allowed 1
CWE-507 Trojan Horse Allowed 1
CWE-495 Private Data Structure Returned From A Public Method Allowed 1
CWE-484 Omitted Break Statement in Switch Allowed 1
CWE-482 Comparing instead of Assigning Allowed 1
CWE-478 Missing Default Case in Multiple Condition Expression Allowed 1
CWE-469 Use of Pointer Subtraction to Determine Size Allowed 1
CWE-463 Deletion of Data Structure Sentinel Allowed 1
CWE-462 Duplicate Key in Associative List (Alist) Allowed 1
CWE-46 Path Equivalence: 'filename ' (Trailing Space) Allowed 1
CWE-443 DEPRECATED: HTTP response splitting Prohibited 1
CWE-44 Path Equivalence: 'file.name' (Internal Dot) Allowed 1
CWE-433 Unparsed Raw Web Content Delivery Allowed 1
CWE-431 Missing Handler Allowed 1
CWE-43 Path Equivalence: 'filename....' (Multiple Trailing Dot) Allowed 1
CWE-42 Path Equivalence: 'filename.' (Trailing Dot) Allowed 1
CWE-39 Path Traversal: 'C:dirname' Allowed 1
CWE-38 Path Traversal: '\absolute\pathname\here' Allowed 1
CWE-333 Improper Handling of Insufficient Entropy in TRNG Allowed 1
CWE-318 Cleartext Storage of Sensitive Information in Executable Allowed 1
CWE-314 Cleartext Storage in the Registry Allowed 1
CWE-301 Reflection Attack in an Authentication Protocol Allowed 1
CWE-30 Path Traversal: '\dir\..\filename' Allowed 1
CWE-293 Using Referer Field for Authentication Allowed 1
CWE-28 Path Traversal: '..\filedir' Allowed 1
CWE-263 Password Aging with Long Expiration Discouraged 1
CWE-234 Failure to Handle Missing Parameter Discouraged 1
CWE-224 Obscured Security-relevant Information by Alternate Name Allowed 1
CWE-221 Information Loss or Omission Allowed-with-Review 1
CWE-207 Observable Behavioral Discrepancy With Equivalent Products Allowed 1
CWE-206 Observable Internal Behavioral Discrepancy Allowed 1
CWE-198 Use of Incorrect Byte Ordering Allowed 1
CWE-162 Improper Neutralization of Trailing Special Elements Allowed 1
CWE-154 Improper Neutralization of Variable Name Delimiters Allowed 1
CWE-145 Improper Neutralization of Section Delimiters Allowed 1
CWE-143 Improper Neutralization of Record Delimiters Allowed 1
CWE-1330 Remanent Data Readable after Memory Erase Allowed 1
CWE-1316 Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges Allowed 1
CWE-1314 Missing Write Protection for Parametric Data Values Allowed 1
CWE-1313 Hardware Allows Activation of Test or Debug Logic at Runtime Allowed 1
CWE-1312 Missing Protection for Mirrored Regions in On-Chip Fabric Firewall Allowed 1
CWE-1310 Missing Ability to Patch ROM Code Allowed 1
CWE-1294 Insecure Security Identifier Mechanism Allowed-with-Review 1