Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-824 Access of Uninitialized Pointer Allowed 186
CWE-256 Plaintext Storage of a Password Allowed 185
CWE-203 Observable Discrepancy Allowed 182
CWE-204 Observable Response Discrepancy Allowed 180
CWE-749 Exposed Dangerous Method or Function Allowed 179
CWE-208 Observable Timing Discrepancy Allowed 179
CWE-1188 Initialization of a Resource with an Insecure Default Allowed 179
CWE-640 Weak Password Recovery Mechanism for Forgotten Password Allowed-with-Review 176
CWE-259 Use of Hard-coded Password Allowed 176
CWE-35 Path Traversal: '.../...//' Allowed 174
CWE-407 Inefficient Algorithmic Complexity Allowed-with-Review 172
CWE-61 UNIX Symbolic Link (Symlink) Following Allowed 169
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor Allowed 168
CWE-294 Authentication Bypass by Capture-replay Allowed 165
CWE-369 Divide By Zero Allowed 163
CWE-305 Authentication Bypass by Primary Weakness Allowed 161
CWE-330 Use of Insufficiently Random Values Discouraged 160
CWE-1236 Improper Neutralization of Formula Elements in a CSV File Allowed 154
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes Allowed 149
CWE-494 Download of Code Without Integrity Check Allowed 147
CWE-326 Inadequate Encryption Strength Allowed-with-Review 145
CWE-134 Use of Externally-Controlled Format String Allowed 145
CWE-1287 Improper Validation of Specified Type of Input Allowed 145
CWE-788 Access of Memory Location After End of Buffer Discouraged 144
CWE-280 Improper Handling of Insufficient Permissions or Privileges Allowed 142
CWE-36 Absolute Path Traversal Allowed 141
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Allowed 137
CWE-131 Incorrect Calculation of Buffer Size Allowed 132
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification) Allowed 130
CWE-1021 Improper Restriction of Rendered UI Layers or Frames Allowed 127
CWE-457 Use of Uninitialized Variable Allowed 125
CWE-665 Improper Initialization Discouraged 122
CWE-602 Client-Side Enforcement of Server-Side Security Allowed-with-Review 122
CWE-521 Weak Password Requirements Allowed 121
CWE-922 Insecure Storage of Sensitive Information Allowed-with-Review 119
CWE-281 Improper Preservation of Permissions Allowed 119
CWE-703 Improper Check or Handling of Exceptional Conditions Discouraged 118
CWE-117 Improper Output Neutralization for Logs Allowed 118
CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains Allowed 116
CWE-943 Improper Neutralization of Special Elements in Data Query Logic Allowed-with-Review 114
CWE-193 Off-by-one Error Allowed 110
CWE-807 Reliance on Untrusted Inputs in a Security Decision Allowed 109
CWE-1392 Use of Default Credentials Allowed 109
CWE-24 Path Traversal: '../filedir' Allowed 108
CWE-680 Integer Overflow to Buffer Overflow Discouraged 106
CWE-425 Direct Request ('Forced Browsing') Allowed 106
CWE-354 Improper Validation of Integrity Check Value Allowed 103
CWE-1220 Insufficient Granularity of Access Control Allowed 103
CWE-823 Use of Out-of-range Pointer Offset Allowed 102