Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-791 Incomplete Filtering of Special Elements Allowed 39
CWE-420 Unprotected Alternate Channel Allowed 39
CWE-289 Authentication Bypass by Alternate Name Allowed 39
CWE-124 Buffer Underwrite ('Buffer Underflow') Allowed 39
CWE-272 Least Privilege Violation Allowed 38
CWE-202 Exposure of Sensitive Information Through Data Queries Allowed 37
CWE-1393 Use of Default Password Allowed 37
CWE-606 Unchecked Input for Loop Condition Allowed 36
CWE-540 Inclusion of Sensitive Information in Source Code Allowed 36
CWE-471 Modification of Assumed-Immutable Data (MAID) Allowed 36
CWE-180 Incorrect Behavior Order: Validate Before Canonicalize Allowed 36
CWE-1385 Missing Origin Validation in WebSockets Allowed 36
CWE-565 Reliance on Cookies without Validation and Integrity Checking Allowed 35
CWE-385 Covert Timing Channel Allowed 35
CWE-226 Sensitive Information in Resource Not Removed Before Reuse Allowed 35
CWE-1289 Improper Validation of Unsafe Equivalence in Input Allowed 35
CWE-92 DEPRECATED: Improper Sanitization of Custom Special Characters Prohibited 34
CWE-782 Exposed IOCTL with Insufficient Access Control Allowed 34
CWE-778 Insufficient Logging Allowed 34
CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') Allowed 34
CWE-214 Invocation of Process Using Visible Sensitive Information Allowed 34
CWE-316 Cleartext Storage of Sensitive Information in Memory Allowed 33
CWE-690 Unchecked Return Value to NULL Pointer Dereference Discouraged 32
CWE-41 Improper Resolution of Path Equivalence Allowed 32
CWE-313 Cleartext Storage in a File or on Disk Allowed 32
CWE-176 Improper Handling of Unicode Encoding Allowed 32
CWE-283 Unverified Ownership Allowed 31
CWE-241 Improper Handling of Unexpected Data Type Allowed 31
CWE-213 Exposure of Sensitive Information Due to Incompatible Policies Allowed 31
CWE-185 Incorrect Regular Expression Allowed-with-Review 31
CWE-525 Use of Web Browser Cache Containing Sensitive Information Allowed 30
CWE-763 Release of Invalid Pointer or Reference Allowed 29
CWE-691 Insufficient Control Flow Management Discouraged 29
CWE-501 Trust Boundary Violation Allowed 29
CWE-1275 Sensitive Cookie with Improper SameSite Attribute Allowed 29
CWE-83 Improper Neutralization of Script in Attributes in a Web Page Allowed 28
CWE-684 Incorrect Provision of Specified Functionality Allowed-with-Review 28
CWE-356 Product UI does not Warn User of Unsafe Actions Allowed 28
CWE-350 Reliance on Reverse DNS Resolution for a Security-Critical Action Allowed 28
CWE-322 Key Exchange without Entity Authentication Allowed 28
CWE-282 Improper Ownership Management Allowed-with-Review 28
CWE-115 Misinterpretation of Input Allowed 28
CWE-195 Signed to Unsigned Conversion Error Allowed 27
CWE-1104 Use of Unmaintained Third Party Components Allowed 27
CWE-391 Unchecked Error Condition Prohibited 26
CWE-270 Privilege Context Switching Error Allowed 26
CWE-158 Improper Neutralization of Null Byte or NUL Character Allowed 26
CWE-1327 Binding to an Unrestricted IP Address Allowed 26
CWE-1288 Improper Validation of Consistency within Input Allowed 26
CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Allowed 25