Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-611 Improper Restriction of XML External Entity Reference Allowed 614
CWE-126 Buffer Over-read Allowed 606
CWE-345 Insufficient Verification of Data Authenticity Discouraged 563
CWE-23 Relative Path Traversal Allowed 558
CWE-693 Protection Mechanism Failure Discouraged 542
CWE-613 Insufficient Session Expiration Allowed-with-Review 531
CWE-307 Improper Restriction of Excessive Authentication Attempts Allowed 527
CWE-319 Cleartext Transmission of Sensitive Information Allowed 517
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion') Allowed 516
CWE-290 Authentication Bypass by Spoofing Allowed 515
CWE-201 Insertion of Sensitive Information Into Sent Data Allowed 493
CWE-209 Generation of Error Message Containing Sensitive Information Allowed 469
CWE-754 Improper Check for Unusual or Exceptional Conditions Allowed-with-Review 456
CWE-191 Integer Underflow (Wrap or Wraparound) Allowed 453
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere Allowed 451
CWE-1333 Inefficient Regular Expression Complexity Allowed 430
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') Allowed 425
CWE-617 Reachable Assertion Allowed 420
CWE-312 Cleartext Storage of Sensitive Information Allowed 413
CWE-428 Unquoted Search Path or Element Allowed 410
CWE-327 Use of a Broken or Risky Cryptographic Algorithm Allowed-with-Review 407
CWE-321 Use of Hard-coded Cryptographic Key Allowed 402
CWE-250 Execution with Unnecessary Privileges Allowed 396
CWE-346 Origin Validation Error Allowed-with-Review 395
CWE-401 Missing Release of Memory after Effective Lifetime Allowed 394
CWE-674 Uncontrolled Recursion Allowed-with-Review 386
CWE-116 Improper Encoding or Escaping of Output Allowed-with-Review 363
CWE-248 Uncaught Exception Allowed 350
CWE-415 Double Free Allowed 338
CWE-426 Untrusted Search Path Allowed-with-Review 336
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') Allowed 334
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Allowed 331
CWE-789 Memory Allocation with Excessive Size Value Allowed 322
CWE-311 Missing Encryption of Sensitive Data Discouraged 322
CWE-129 Improper Validation of Array Index Allowed 321
CWE-1284 Improper Validation of Specified Quantity in Input Allowed 316
CWE-552 Files or Directories Accessible to External Parties Allowed 309
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') Allowed 307
CWE-822 Untrusted Pointer Dereference Allowed 297
CWE-707 Improper Neutralization Discouraged 295
CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine Allowed 280
CWE-908 Use of Uninitialized Resource Allowed 277
CWE-829 Inclusion of Functionality from Untrusted Control Sphere Allowed 265
CWE-755 Improper Handling of Exceptional Conditions Discouraged 256
CWE-184 Incomplete List of Disallowed Inputs Allowed 246
CWE-668 Exposure of Resource to Wrong Sphere Discouraged 237
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') Allowed 230
CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') Allowed 226
CWE-824 Access of Uninitialized Pointer Allowed 224