Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-603 | Use of Client-Side Authentication | Allowed | 25 |
| CWE-286 | Incorrect User Management | Allowed-with-Review | 25 |
| CWE-27 | Path Traversal: 'dir/../../filename' | Allowed | 25 |
| CWE-1230 | Exposure of Sensitive Information Through Metadata | Allowed | 25 |
| CWE-96 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') | Allowed | 24 |
| CWE-758 | Reliance on Undefined, Unspecified, or Implementation-Defined Behavior | Allowed-with-Review | 24 |
| CWE-523 | Unprotected Transport of Credentials | Allowed | 24 |
| CWE-460 | Improper Cleanup on Thrown Exception | Allowed | 24 |
| CWE-260 | Password in Configuration File | Allowed | 24 |
| CWE-1191 | On-Chip Debug and Test Interface With Improper Access Control | Allowed | 24 |
| CWE-833 | Deadlock | Allowed | 23 |
| CWE-390 | Detection of Error Condition Without Action | Allowed | 23 |
| CWE-279 | Incorrect Execution-Assigned Permissions | Allowed | 23 |
| CWE-253 | Incorrect Check of Function Return Value | Allowed | 23 |
| CWE-233 | Improper Handling of Parameters | Allowed | 23 |
| CWE-215 | Insertion of Sensitive Information Into Debugging Code | Allowed | 23 |
| CWE-592 | DEPRECATED: Authentication Bypass Issues | Prohibited | 22 |
| CWE-402 | Transmission of Private Resources into a New Sphere ('Resource Leak') | Allowed-with-Review | 22 |
| CWE-268 | Privilege Chaining | Allowed | 22 |
| CWE-114 | Process Control | Discouraged | 22 |
| CWE-939 | Improper Authorization in Handler for Custom URL Scheme | Allowed | 21 |
| CWE-759 | Use of a One-Way Hash without a Salt | Allowed | 21 |
| CWE-708 | Incorrect Ownership Assignment | Allowed | 21 |
| CWE-410 | Insufficient Resource Pool | Allowed | 21 |
| CWE-1295 | Debug Messages Revealing Unnecessary Information | Allowed | 21 |
| CWE-1240 | Use of a Cryptographic Primitive with a Risky Implementation | Allowed | 21 |
| CWE-590 | Free of Memory not on the Heap | Allowed | 20 |
| CWE-357 | Insufficient UI Warning of Dangerous Operations | Allowed | 20 |
| CWE-324 | Use of a Key Past its Expiration Date | Allowed | 20 |
| CWE-1325 | Improperly Controlled Sequential Memory Allocation | Allowed | 20 |
| CWE-1025 | Comparison Using Wrong Factors | Allowed | 20 |
| CWE-1023 | Incomplete Comparison with Missing Factors | Allowed-with-Review | 20 |
| CWE-75 | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) | Discouraged | 19 |
| CWE-698 | Execution After Redirect (EAR) | Allowed | 19 |
| CWE-273 | Improper Check for Dropped Privileges | Allowed | 19 |
| CWE-155 | Improper Neutralization of Wildcards or Matching Symbols | Allowed | 19 |
| CWE-837 | Improper Enforcement of a Single, Unique Action | Allowed | 18 |
| CWE-779 | Logging of Excessive Data | Allowed | 18 |
| CWE-625 | Permissive Regular Expression | Allowed | 18 |
| CWE-526 | Cleartext Storage of Sensitive Information in an Environment Variable | Allowed | 18 |
| CWE-406 | Insufficient Control of Network Message Volume (Network Amplification) | Allowed-with-Review | 18 |
| CWE-296 | Improper Following of a Certificate's Chain of Trust | Allowed | 18 |
| CWE-228 | Improper Handling of Syntactically Invalid Structure | Allowed-with-Review | 18 |
| CWE-140 | Improper Neutralization of Delimiters | Allowed | 18 |
| CWE-1394 | Use of Default Cryptographic Key | Allowed | 18 |
| CWE-836 | Use of Password Hash Instead of Password for Authentication | Allowed | 17 |
| CWE-657 | Violation of Secure Design Principles | Discouraged | 17 |
| CWE-641 | Improper Restriction of Names for Files and Other Resources | Allowed | 17 |
| CWE-299 | Improper Check for Certificate Revocation | Allowed | 17 |
| CWE-244 | Improper Clearing of Heap Memory Before Release ('Heap Inspection') | Allowed | 17 |