Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-1220 Insufficient Granularity of Access Control Allowed 103
CWE-441 Unintended Proxy or Intermediary ('Confused Deputy') Allowed-with-Review 102
CWE-506 Embedded Malicious Code Allowed-with-Review 101
CWE-252 Unchecked Return Value Allowed 100
CWE-436 Interpretation Conflict Allowed-with-Review 99
CWE-451 User Interface (UI) Misrepresentation of Critical Information Allowed-with-Review 97
CWE-303 Incorrect Implementation of Authentication Algorithm Allowed 96
CWE-697 Incorrect Comparison Discouraged 95
CWE-670 Always-Incorrect Control Flow Implementation Allowed-with-Review 93
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') Allowed 93
CWE-459 Incomplete Cleanup Allowed 93
CWE-377 Insecure Temporary File Allowed-with-Review 93
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') Allowed 93
CWE-772 Missing Release of Resource after Effective Lifetime Allowed 92
CWE-620 Unverified Password Change Allowed 92
CWE-489 Active Debug Code Allowed 91
CWE-358 Improperly Implemented Security Check for Standard Allowed 87
CWE-1390 Weak Authentication Allowed-with-Review 87
CWE-926 Improper Export of Android Application Components Allowed 86
CWE-598 Use of HTTP Request With Sensitive Query String Allowed 85
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory Allowed 85
CWE-331 Insufficient Entropy Allowed 85
CWE-328 Use of Weak Hash Allowed 85
CWE-913 Improper Control of Dynamically-Managed Code Resources Allowed-with-Review 82
CWE-348 Use of Less Trusted Source Allowed 82
CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences Allowed 82
CWE-1286 Improper Validation of Syntactic Correctness of Input Allowed 81
CWE-610 Externally Controlled Reference to a Resource in Another Sphere Discouraged 80
CWE-197 Numeric Truncation Error Allowed 80
CWE-799 Improper Control of Interaction Frequency Allowed-with-Review 79
CWE-178 Improper Handling of Case Sensitivity Allowed 79
CWE-704 Incorrect Type Conversion or Cast Allowed-with-Review 78
CWE-912 Hidden Functionality Allowed-with-Review 77
CWE-91 XML Injection (aka Blind XPath Injection) Allowed-with-Review 76
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') Allowed 76
CWE-591 Sensitive Data Storage in Improperly Locked Memory Allowed 75
CWE-923 Improper Restriction of Communication Channel to Intended Endpoints Allowed-with-Review 74
CWE-669 Incorrect Resource Transfer Between Spheres Allowed-with-Review 74
CWE-15 External Control of System or Configuration Setting Allowed 74
CWE-916 Use of Password Hash With Insufficient Computational Effort Allowed 73
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer Allowed 73
CWE-297 Improper Validation of Certificate with Host Mismatch Allowed 70
CWE-841 Improper Enforcement of Behavioral Workflow Allowed 68
CWE-682 Incorrect Calculation Discouraged 66
CWE-681 Incorrect Conversion between Numeric Types Allowed 66
CWE-257 Storing Passwords in a Recoverable Format Allowed 66
CWE-524 Use of Cache Containing Sensitive Information Allowed 65
CWE-648 Incorrect Use of Privileged APIs Allowed 64