Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-392 | Missing Report of Error Condition | Allowed | 12 |
| CWE-363 | Race Condition Enabling Link Following | Allowed | 12 |
| CWE-271 | Privilege Dropping / Lowering Errors | Allowed-with-Review | 12 |
| CWE-223 | Omission of Security-relevant Information | Allowed | 12 |
| CWE-1244 | Internal Asset Exposed to Unsafe Debug Access Level or State | Allowed | 12 |
| CWE-118 | Incorrect Access of Indexable Resource ('Range Error') | Discouraged | 12 |
| CWE-612 | Improper Authorization of Index Containing Sensitive Information | Allowed | 11 |
| CWE-567 | Unsynchronized Access to Shared Data in a Multithreaded Context | Allowed | 11 |
| CWE-547 | Use of Hard-coded, Security-relevant Constants | Allowed | 11 |
| CWE-419 | Unprotected Primary Channel | Allowed | 11 |
| CWE-395 | Use of NullPointerException Catch to Detect NULL Pointer Dereference | Allowed | 11 |
| CWE-364 | Signal Handler Race Condition | Allowed | 11 |
| CWE-258 | Empty Password in Configuration File | Allowed | 11 |
| CWE-242 | Use of Inherently Dangerous Function | Allowed | 11 |
| CWE-232 | Improper Handling of Undefined Values | Allowed | 11 |
| CWE-230 | Improper Handling of Missing Values | Allowed | 11 |
| CWE-141 | Improper Neutralization of Parameter/Argument Delimiters | Allowed | 11 |
| CWE-86 | Improper Neutralization of Invalid Characters in Identifiers in Web Pages | Allowed | 10 |
| CWE-830 | Inclusion of Web Functionality from an Untrusted Source | Allowed | 10 |
| CWE-762 | Mismatched Memory Management Routines | Allowed | 10 |
| CWE-760 | Use of a One-Way Hash with a Predictable Salt | Allowed | 10 |
| CWE-656 | Reliance on Security Through Obscurity | Allowed-with-Review | 10 |
| CWE-646 | Reliance on File Name or Extension of Externally-Supplied File | Allowed | 10 |
| CWE-329 | Generation of Predictable IV with CBC Mode | Allowed | 10 |
| CWE-172 | Encoding Error | Allowed-with-Review | 10 |
| CWE-146 | Improper Neutralization of Expression/Command Delimiters | Allowed | 10 |
| CWE-14 | Compiler Removal of Code to Clear Buffers | Allowed | 10 |
| CWE-1299 | Missing Protection Mechanism for Alternate Hardware Interface | Allowed | 10 |
| CWE-1259 | Improper Restriction of Security Token Assignment | Allowed | 10 |
| CWE-1241 | Use of Predictable Algorithm in Random Number Generator | Allowed | 10 |
| CWE-921 | Storage of Sensitive Data in a Mechanism without Access Control | Allowed | 9 |
| CWE-692 | Incomplete Denylist to Cross-Site Scripting | Discouraged | 9 |
| CWE-676 | Use of Potentially Dangerous Function | Allowed | 9 |
| CWE-64 | Windows Shortcut Following (.LNK) | Allowed | 9 |
| CWE-628 | Function Call with Incorrectly Specified Arguments | Allowed | 9 |
| CWE-561 | Dead Code | Allowed | 9 |
| CWE-480 | Use of Incorrect Operator | Allowed | 9 |
| CWE-291 | Reliance on IP Address for Authentication | Allowed | 9 |
| CWE-1419 | Incorrect Initialization of Resource | Allowed-with-Review | 9 |
| CWE-1357 | Reliance on Insufficiently Trustworthy Component | Allowed-with-Review | 9 |
| CWE-1326 | Missing Immutable Root of Trust in Hardware | Allowed | 9 |
| CWE-1263 | Improper Physical Access Control | Allowed-with-Review | 9 |
| CWE-1262 | Improper Access Control for Register Interface | Allowed | 9 |
| CWE-941 | Incorrectly Specified Destination in a Communication Channel | Allowed | 8 |
| CWE-838 | Inappropriate Encoding for Output Context | Allowed | 8 |
| CWE-826 | Premature Release of Resource During Expected Lifetime | Allowed | 8 |
| CWE-82 | Improper Neutralization of Script in Attributes of IMG Tags in a Web Page | Allowed | 8 |