Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-1220 | Insufficient Granularity of Access Control | Allowed | 103 |
| CWE-441 | Unintended Proxy or Intermediary ('Confused Deputy') | Allowed-with-Review | 102 |
| CWE-506 | Embedded Malicious Code | Allowed-with-Review | 101 |
| CWE-252 | Unchecked Return Value | Allowed | 100 |
| CWE-436 | Interpretation Conflict | Allowed-with-Review | 99 |
| CWE-451 | User Interface (UI) Misrepresentation of Critical Information | Allowed-with-Review | 97 |
| CWE-303 | Incorrect Implementation of Authentication Algorithm | Allowed | 96 |
| CWE-697 | Incorrect Comparison | Discouraged | 95 |
| CWE-670 | Always-Incorrect Control Flow Implementation | Allowed-with-Review | 93 |
| CWE-470 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | Allowed | 93 |
| CWE-459 | Incomplete Cleanup | Allowed | 93 |
| CWE-377 | Insecure Temporary File | Allowed-with-Review | 93 |
| CWE-113 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') | Allowed | 93 |
| CWE-772 | Missing Release of Resource after Effective Lifetime | Allowed | 92 |
| CWE-620 | Unverified Password Change | Allowed | 92 |
| CWE-489 | Active Debug Code | Allowed | 91 |
| CWE-358 | Improperly Implemented Security Check for Standard | Allowed | 87 |
| CWE-1390 | Weak Authentication | Allowed-with-Review | 87 |
| CWE-926 | Improper Export of Android Application Components | Allowed | 86 |
| CWE-598 | Use of HTTP Request With Sensitive Query String | Allowed | 85 |
| CWE-538 | Insertion of Sensitive Information into Externally-Accessible File or Directory | Allowed | 85 |
| CWE-331 | Insufficient Entropy | Allowed | 85 |
| CWE-328 | Use of Weak Hash | Allowed | 85 |
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | Allowed-with-Review | 82 |
| CWE-348 | Use of Less Trusted Source | Allowed | 82 |
| CWE-150 | Improper Neutralization of Escape, Meta, or Control Sequences | Allowed | 82 |
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | Allowed | 81 |
| CWE-610 | Externally Controlled Reference to a Resource in Another Sphere | Discouraged | 80 |
| CWE-197 | Numeric Truncation Error | Allowed | 80 |
| CWE-799 | Improper Control of Interaction Frequency | Allowed-with-Review | 79 |
| CWE-178 | Improper Handling of Case Sensitivity | Allowed | 79 |
| CWE-704 | Incorrect Type Conversion or Cast | Allowed-with-Review | 78 |
| CWE-912 | Hidden Functionality | Allowed-with-Review | 77 |
| CWE-91 | XML Injection (aka Blind XPath Injection) | Allowed-with-Review | 76 |
| CWE-90 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') | Allowed | 76 |
| CWE-591 | Sensitive Data Storage in Improperly Locked Memory | Allowed | 75 |
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | Allowed-with-Review | 74 |
| CWE-669 | Incorrect Resource Transfer Between Spheres | Allowed-with-Review | 74 |
| CWE-15 | External Control of System or Configuration Setting | Allowed | 74 |
| CWE-916 | Use of Password Hash With Insufficient Computational Effort | Allowed | 73 |
| CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer | Allowed | 73 |
| CWE-297 | Improper Validation of Certificate with Host Mismatch | Allowed | 70 |
| CWE-841 | Improper Enforcement of Behavioral Workflow | Allowed | 68 |
| CWE-682 | Incorrect Calculation | Discouraged | 66 |
| CWE-681 | Incorrect Conversion between Numeric Types | Allowed | 66 |
| CWE-257 | Storing Passwords in a Recoverable Format | Allowed | 66 |
| CWE-524 | Use of Cache Containing Sensitive Information | Allowed | 65 |
| CWE-648 | Incorrect Use of Privileged APIs | Allowed | 64 |