Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | Allowed | 614 |
| CWE-126 | Buffer Over-read | Allowed | 606 |
| CWE-345 | Insufficient Verification of Data Authenticity | Discouraged | 563 |
| CWE-23 | Relative Path Traversal | Allowed | 558 |
| CWE-693 | Protection Mechanism Failure | Discouraged | 542 |
| CWE-613 | Insufficient Session Expiration | Allowed-with-Review | 531 |
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | Allowed | 527 |
| CWE-319 | Cleartext Transmission of Sensitive Information | Allowed | 517 |
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | Allowed | 516 |
| CWE-290 | Authentication Bypass by Spoofing | Allowed | 515 |
| CWE-201 | Insertion of Sensitive Information Into Sent Data | Allowed | 493 |
| CWE-209 | Generation of Error Message Containing Sensitive Information | Allowed | 469 |
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | Allowed-with-Review | 456 |
| CWE-191 | Integer Underflow (Wrap or Wraparound) | Allowed | 453 |
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | Allowed | 451 |
| CWE-1333 | Inefficient Regular Expression Complexity | Allowed | 430 |
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | Allowed | 425 |
| CWE-617 | Reachable Assertion | Allowed | 420 |
| CWE-312 | Cleartext Storage of Sensitive Information | Allowed | 413 |
| CWE-428 | Unquoted Search Path or Element | Allowed | 410 |
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | Allowed-with-Review | 407 |
| CWE-321 | Use of Hard-coded Cryptographic Key | Allowed | 402 |
| CWE-250 | Execution with Unnecessary Privileges | Allowed | 396 |
| CWE-346 | Origin Validation Error | Allowed-with-Review | 395 |
| CWE-401 | Missing Release of Memory after Effective Lifetime | Allowed | 394 |
| CWE-674 | Uncontrolled Recursion | Allowed-with-Review | 386 |
| CWE-116 | Improper Encoding or Escaping of Output | Allowed-with-Review | 363 |
| CWE-248 | Uncaught Exception | Allowed | 350 |
| CWE-415 | Double Free | Allowed | 338 |
| CWE-426 | Untrusted Search Path | Allowed-with-Review | 336 |
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | Allowed | 334 |
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | Allowed | 331 |
| CWE-789 | Memory Allocation with Excessive Size Value | Allowed | 322 |
| CWE-311 | Missing Encryption of Sensitive Data | Discouraged | 322 |
| CWE-129 | Improper Validation of Array Index | Allowed | 321 |
| CWE-1284 | Improper Validation of Specified Quantity in Input | Allowed | 316 |
| CWE-552 | Files or Directories Accessible to External Parties | Allowed | 309 |
| CWE-1321 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | Allowed | 307 |
| CWE-822 | Untrusted Pointer Dereference | Allowed | 297 |
| CWE-707 | Improper Neutralization | Discouraged | 295 |
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | Allowed | 280 |
| CWE-908 | Use of Uninitialized Resource | Allowed | 277 |
| CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | Allowed | 265 |
| CWE-755 | Improper Handling of Exceptional Conditions | Discouraged | 256 |
| CWE-184 | Incomplete List of Disallowed Inputs | Allowed | 246 |
| CWE-668 | Exposure of Resource to Wrong Sphere | Discouraged | 237 |
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | Allowed | 230 |
| CWE-95 | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') | Allowed | 226 |
| CWE-824 | Access of Uninitialized Pointer | Allowed | 224 |