Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-603 Use of Client-Side Authentication Allowed 25
CWE-286 Incorrect User Management Allowed-with-Review 25
CWE-27 Path Traversal: 'dir/../../filename' Allowed 25
CWE-1230 Exposure of Sensitive Information Through Metadata Allowed 25
CWE-96 Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') Allowed 24
CWE-758 Reliance on Undefined, Unspecified, or Implementation-Defined Behavior Allowed-with-Review 24
CWE-523 Unprotected Transport of Credentials Allowed 24
CWE-460 Improper Cleanup on Thrown Exception Allowed 24
CWE-260 Password in Configuration File Allowed 24
CWE-1191 On-Chip Debug and Test Interface With Improper Access Control Allowed 24
CWE-833 Deadlock Allowed 23
CWE-390 Detection of Error Condition Without Action Allowed 23
CWE-279 Incorrect Execution-Assigned Permissions Allowed 23
CWE-253 Incorrect Check of Function Return Value Allowed 23
CWE-233 Improper Handling of Parameters Allowed 23
CWE-215 Insertion of Sensitive Information Into Debugging Code Allowed 23
CWE-592 DEPRECATED: Authentication Bypass Issues Prohibited 22
CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak') Allowed-with-Review 22
CWE-268 Privilege Chaining Allowed 22
CWE-114 Process Control Discouraged 22
CWE-939 Improper Authorization in Handler for Custom URL Scheme Allowed 21
CWE-759 Use of a One-Way Hash without a Salt Allowed 21
CWE-708 Incorrect Ownership Assignment Allowed 21
CWE-410 Insufficient Resource Pool Allowed 21
CWE-1295 Debug Messages Revealing Unnecessary Information Allowed 21
CWE-1240 Use of a Cryptographic Primitive with a Risky Implementation Allowed 21
CWE-590 Free of Memory not on the Heap Allowed 20
CWE-357 Insufficient UI Warning of Dangerous Operations Allowed 20
CWE-324 Use of a Key Past its Expiration Date Allowed 20
CWE-1325 Improperly Controlled Sequential Memory Allocation Allowed 20
CWE-1025 Comparison Using Wrong Factors Allowed 20
CWE-1023 Incomplete Comparison with Missing Factors Allowed-with-Review 20
CWE-75 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) Discouraged 19
CWE-698 Execution After Redirect (EAR) Allowed 19
CWE-273 Improper Check for Dropped Privileges Allowed 19
CWE-155 Improper Neutralization of Wildcards or Matching Symbols Allowed 19
CWE-837 Improper Enforcement of a Single, Unique Action Allowed 18
CWE-779 Logging of Excessive Data Allowed 18
CWE-625 Permissive Regular Expression Allowed 18
CWE-526 Cleartext Storage of Sensitive Information in an Environment Variable Allowed 18
CWE-406 Insufficient Control of Network Message Volume (Network Amplification) Allowed-with-Review 18
CWE-296 Improper Following of a Certificate's Chain of Trust Allowed 18
CWE-228 Improper Handling of Syntactically Invalid Structure Allowed-with-Review 18
CWE-140 Improper Neutralization of Delimiters Allowed 18
CWE-1394 Use of Default Cryptographic Key Allowed 18
CWE-836 Use of Password Hash Instead of Password for Authentication Allowed 17
CWE-657 Violation of Secure Design Principles Discouraged 17
CWE-641 Improper Restriction of Names for Files and Other Resources Allowed 17
CWE-299 Improper Check for Certificate Revocation Allowed 17
CWE-244 Improper Clearing of Heap Memory Before Release ('Heap Inspection') Allowed 17