Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-177 Improper Handling of URL Encoding (Hex Encoding) Allowed 17
CWE-1427 Improper Neutralization of Input Used for LLM Prompting Allowed 17
CWE-927 Use of Implicit Intent for Sensitive Communication Allowed 16
CWE-804 Guessable CAPTCHA Allowed 16
CWE-477 Use of Obsolete Function Allowed 16
CWE-453 Insecure Default Variable Initialization Allowed 16
CWE-394 Unexpected Status Code or Return Value Allowed 16
CWE-366 Race Condition within a Thread Allowed 16
CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) Allowed 16
CWE-187 Partial String Comparison Allowed 16
CWE-647 Use of Non-Canonical URL Paths for Authorization Decisions Allowed 15
CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection') Allowed 15
CWE-551 Incorrect Behavior Order: Authorization Before Parsing and Canonicalization Allowed 15
CWE-413 Improper Resource Locking Allowed 15
CWE-341 Predictable from Observable State Allowed 15
CWE-229 Improper Handling of Values Allowed 15
CWE-1386 Insecure Operation on Windows Junction / Mount Point Allowed 15
CWE-1242 Inclusion of Undocumented Features or Chicken Bits Allowed 15
CWE-911 Improper Update of Reference Count Allowed 14
CWE-84 Improper Neutralization of Encoded URI Schemes in a Web Page Allowed 14
CWE-820 Missing Synchronization Allowed 14
CWE-76 Improper Neutralization of Equivalent Special Elements Allowed 14
CWE-642 External Control of Critical State Data Allowed-with-Review 14
CWE-337 Predictable Seed in Pseudo-Random Number Generator (PRNG) Allowed 14
CWE-334 Small Space of Random Values Allowed 14
CWE-308 Use of Single-factor Authentication Allowed 14
CWE-26 Path Traversal: '/dir/../filename' Allowed 14
CWE-1260 Improper Handling of Overlap Between Protected Memory Ranges Allowed 14
CWE-1258 Exposure of Sensitive System Information Due to Uncleared Debug Information Allowed 14
CWE-1050 Excessive Platform Resource Consumption within a Loop Allowed 14
CWE-909 Missing Initialization of Resource Allowed-with-Review 13
CWE-821 Incorrect Synchronization Allowed 13
CWE-790 Improper Filtering of Special Elements Allowed-with-Review 13
CWE-650 Trusting HTTP Permission Methods on the Server Side Allowed 13
CWE-549 Missing Password Field Masking Allowed 13
CWE-475 Undefined Behavior for Input to API Allowed 13
CWE-351 Insufficient Type Distinction Allowed 13
CWE-25 Path Traversal: '/../filedir' Allowed 13
CWE-159 Improper Handling of Invalid Use of Special Elements Allowed-with-Review 13
CWE-138 Improper Neutralization of Special Elements Discouraged 13
CWE-1022 Use of Web Link to Untrusted Target with window.opener Access Allowed 13
CWE-842 Placement of User into Incorrect Group Allowed 12
CWE-694 Use of Multiple Resources with Duplicate Identifier Allowed 12
CWE-564 SQL Injection: Hibernate Allowed 12
CWE-530 Exposure of Backup File to an Unauthorized Control Sphere Allowed 12
CWE-449 The UI Performs the Wrong Action Allowed 12
CWE-393 Return of Wrong Status Code Allowed 12