Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-177 | Improper Handling of URL Encoding (Hex Encoding) | Allowed | 17 |
| CWE-1427 | Improper Neutralization of Input Used for LLM Prompting | Allowed | 17 |
| CWE-927 | Use of Implicit Intent for Sensitive Communication | Allowed | 16 |
| CWE-804 | Guessable CAPTCHA | Allowed | 16 |
| CWE-477 | Use of Obsolete Function | Allowed | 16 |
| CWE-453 | Insecure Default Variable Initialization | Allowed | 16 |
| CWE-394 | Unexpected Status Code or Return Value | Allowed | 16 |
| CWE-366 | Race Condition within a Thread | Allowed | 16 |
| CWE-335 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) | Allowed | 16 |
| CWE-187 | Partial String Comparison | Allowed | 16 |
| CWE-647 | Use of Non-Canonical URL Paths for Authorization Decisions | Allowed | 15 |
| CWE-643 | Improper Neutralization of Data within XPath Expressions ('XPath Injection') | Allowed | 15 |
| CWE-551 | Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | Allowed | 15 |
| CWE-413 | Improper Resource Locking | Allowed | 15 |
| CWE-341 | Predictable from Observable State | Allowed | 15 |
| CWE-229 | Improper Handling of Values | Allowed | 15 |
| CWE-1386 | Insecure Operation on Windows Junction / Mount Point | Allowed | 15 |
| CWE-1242 | Inclusion of Undocumented Features or Chicken Bits | Allowed | 15 |
| CWE-911 | Improper Update of Reference Count | Allowed | 14 |
| CWE-84 | Improper Neutralization of Encoded URI Schemes in a Web Page | Allowed | 14 |
| CWE-820 | Missing Synchronization | Allowed | 14 |
| CWE-76 | Improper Neutralization of Equivalent Special Elements | Allowed | 14 |
| CWE-642 | External Control of Critical State Data | Allowed-with-Review | 14 |
| CWE-337 | Predictable Seed in Pseudo-Random Number Generator (PRNG) | Allowed | 14 |
| CWE-334 | Small Space of Random Values | Allowed | 14 |
| CWE-308 | Use of Single-factor Authentication | Allowed | 14 |
| CWE-26 | Path Traversal: '/dir/../filename' | Allowed | 14 |
| CWE-1260 | Improper Handling of Overlap Between Protected Memory Ranges | Allowed | 14 |
| CWE-1258 | Exposure of Sensitive System Information Due to Uncleared Debug Information | Allowed | 14 |
| CWE-1050 | Excessive Platform Resource Consumption within a Loop | Allowed | 14 |
| CWE-909 | Missing Initialization of Resource | Allowed-with-Review | 13 |
| CWE-821 | Incorrect Synchronization | Allowed | 13 |
| CWE-790 | Improper Filtering of Special Elements | Allowed-with-Review | 13 |
| CWE-650 | Trusting HTTP Permission Methods on the Server Side | Allowed | 13 |
| CWE-549 | Missing Password Field Masking | Allowed | 13 |
| CWE-475 | Undefined Behavior for Input to API | Allowed | 13 |
| CWE-351 | Insufficient Type Distinction | Allowed | 13 |
| CWE-25 | Path Traversal: '/../filedir' | Allowed | 13 |
| CWE-159 | Improper Handling of Invalid Use of Special Elements | Allowed-with-Review | 13 |
| CWE-138 | Improper Neutralization of Special Elements | Discouraged | 13 |
| CWE-1022 | Use of Web Link to Untrusted Target with window.opener Access | Allowed | 13 |
| CWE-842 | Placement of User into Incorrect Group | Allowed | 12 |
| CWE-694 | Use of Multiple Resources with Duplicate Identifier | Allowed | 12 |
| CWE-564 | SQL Injection: Hibernate | Allowed | 12 |
| CWE-530 | Exposure of Backup File to an Unauthorized Control Sphere | Allowed | 12 |
| CWE-449 | The UI Performs the Wrong Action | Allowed | 12 |
| CWE-393 | Return of Wrong Status Code | Allowed | 12 |