Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-791 | Incomplete Filtering of Special Elements | Allowed | 39 |
| CWE-420 | Unprotected Alternate Channel | Allowed | 39 |
| CWE-289 | Authentication Bypass by Alternate Name | Allowed | 39 |
| CWE-124 | Buffer Underwrite ('Buffer Underflow') | Allowed | 39 |
| CWE-272 | Least Privilege Violation | Allowed | 38 |
| CWE-202 | Exposure of Sensitive Information Through Data Queries | Allowed | 37 |
| CWE-1393 | Use of Default Password | Allowed | 37 |
| CWE-606 | Unchecked Input for Loop Condition | Allowed | 36 |
| CWE-540 | Inclusion of Sensitive Information in Source Code | Allowed | 36 |
| CWE-471 | Modification of Assumed-Immutable Data (MAID) | Allowed | 36 |
| CWE-180 | Incorrect Behavior Order: Validate Before Canonicalize | Allowed | 36 |
| CWE-1385 | Missing Origin Validation in WebSockets | Allowed | 36 |
| CWE-565 | Reliance on Cookies without Validation and Integrity Checking | Allowed | 35 |
| CWE-385 | Covert Timing Channel | Allowed | 35 |
| CWE-226 | Sensitive Information in Resource Not Removed Before Reuse | Allowed | 35 |
| CWE-1289 | Improper Validation of Unsafe Equivalence in Input | Allowed | 35 |
| CWE-92 | DEPRECATED: Improper Sanitization of Custom Special Characters | Prohibited | 34 |
| CWE-782 | Exposed IOCTL with Insufficient Access Control | Allowed | 34 |
| CWE-778 | Insufficient Logging | Allowed | 34 |
| CWE-757 | Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') | Allowed | 34 |
| CWE-214 | Invocation of Process Using Visible Sensitive Information | Allowed | 34 |
| CWE-316 | Cleartext Storage of Sensitive Information in Memory | Allowed | 33 |
| CWE-690 | Unchecked Return Value to NULL Pointer Dereference | Discouraged | 32 |
| CWE-41 | Improper Resolution of Path Equivalence | Allowed | 32 |
| CWE-313 | Cleartext Storage in a File or on Disk | Allowed | 32 |
| CWE-176 | Improper Handling of Unicode Encoding | Allowed | 32 |
| CWE-283 | Unverified Ownership | Allowed | 31 |
| CWE-241 | Improper Handling of Unexpected Data Type | Allowed | 31 |
| CWE-213 | Exposure of Sensitive Information Due to Incompatible Policies | Allowed | 31 |
| CWE-185 | Incorrect Regular Expression | Allowed-with-Review | 31 |
| CWE-525 | Use of Web Browser Cache Containing Sensitive Information | Allowed | 30 |
| CWE-763 | Release of Invalid Pointer or Reference | Allowed | 29 |
| CWE-691 | Insufficient Control Flow Management | Discouraged | 29 |
| CWE-501 | Trust Boundary Violation | Allowed | 29 |
| CWE-1275 | Sensitive Cookie with Improper SameSite Attribute | Allowed | 29 |
| CWE-83 | Improper Neutralization of Script in Attributes in a Web Page | Allowed | 28 |
| CWE-684 | Incorrect Provision of Specified Functionality | Allowed-with-Review | 28 |
| CWE-356 | Product UI does not Warn User of Unsafe Actions | Allowed | 28 |
| CWE-350 | Reliance on Reverse DNS Resolution for a Security-Critical Action | Allowed | 28 |
| CWE-322 | Key Exchange without Entity Authentication | Allowed | 28 |
| CWE-282 | Improper Ownership Management | Allowed-with-Review | 28 |
| CWE-115 | Misinterpretation of Input | Allowed | 28 |
| CWE-195 | Signed to Unsigned Conversion Error | Allowed | 27 |
| CWE-1104 | Use of Unmaintained Third Party Components | Allowed | 27 |
| CWE-391 | Unchecked Error Condition | Prohibited | 26 |
| CWE-270 | Privilege Context Switching Error | Allowed | 26 |
| CWE-158 | Improper Neutralization of Null Byte or NUL Character | Allowed | 26 |
| CWE-1327 | Binding to an Unrestricted IP Address | Allowed | 26 |
| CWE-1288 | Improper Validation of Consistency within Input | Allowed | 26 |
| CWE-924 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel | Allowed | 25 |