Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Allowed 29829
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Allowed 12775
CWE-862 Missing Authorization Allowed-with-Review 9414
CWE-352 Cross-Site Request Forgery (CSRF) Allowed 6331
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Allowed-with-Review 5975
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Discouraged 5557
CWE-20 Improper Input Validation Discouraged 5086
CWE-125 Out-of-bounds Read Allowed 4665
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Allowed 4616
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor Discouraged 4319
CWE-284 Improper Access Control Discouraged 4101
CWE-94 Improper Control of Generation of Code ('Code Injection') Allowed-with-Review 4023
CWE-121 Stack-based Buffer Overflow Allowed 3708
CWE-416 Use After Free Allowed 3691
CWE-787 Out-of-bounds Write Allowed-with-Review 3607
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Discouraged 3379
CWE-122 Heap-based Buffer Overflow Allowed 3348
CWE-918 Server-Side Request Forgery (SSRF) Allowed 3300
CWE-434 Unrestricted Upload of File with Dangerous Type Allowed 2983
CWE-863 Incorrect Authorization Allowed-with-Review 2917
CWE-502 Deserialization of Untrusted Data Allowed 2788
CWE-639 Authorization Bypass Through User-Controlled Key Allowed 2589
CWE-400 Uncontrolled Resource Consumption Discouraged 2525
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Allowed-with-Review 2387
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Allowed-with-Review 2322
CWE-306 Missing Authentication for Critical Function Allowed 2267
CWE-287 Improper Authentication Discouraged 2212
CWE-770 Allocation of Resources Without Limits or Throttling Allowed 1874
CWE-476 NULL Pointer Dereference Allowed 1777
CWE-285 Improper Authorization Discouraged 1747
CWE-269 Improper Privilege Management Discouraged 1694
CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Allowed 1548
CWE-190 Integer Overflow or Wraparound Allowed 1543
CWE-266 Incorrect Privilege Assignment Allowed 1336
CWE-601 URL Redirection to Untrusted Site ('Open Redirect') Allowed 1145
CWE-427 Uncontrolled Search Path Element Allowed-with-Review 940
CWE-532 Insertion of Sensitive Information into Log File Allowed 900
CWE-798 Use of Hard-coded Credentials Allowed-with-Review 876
CWE-295 Improper Certificate Validation Allowed 869
CWE-59 Improper Link Resolution Before File Access ('Link Following') Allowed 854
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Allowed-with-Review 801
CWE-404 Improper Resource Shutdown or Release Allowed-with-Review 748
CWE-73 External Control of File Name or Path Allowed 745
CWE-732 Incorrect Permission Assignment for Critical Resource Allowed-with-Review 722
CWE-288 Authentication Bypass Using an Alternate Path or Channel Allowed 722
CWE-347 Improper Verification of Cryptographic Signature Allowed 703
CWE-276 Incorrect Default Permissions Allowed 693
CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Allowed 654
CWE-522 Insufficiently Protected Credentials Allowed-with-Review 647
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition Allowed 647