Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-384 Session Fixation Allowed 224
CWE-256 Plaintext Storage of a Password Allowed 221
CWE-1188 Initialization of a Resource with an Insecure Default Allowed 220
CWE-208 Observable Timing Discrepancy Allowed 218
CWE-749 Exposed Dangerous Method or Function Allowed 213
CWE-35 Path Traversal: '.../...//' Allowed 213
CWE-204 Observable Response Discrepancy Allowed 213
CWE-203 Observable Discrepancy Allowed 213
CWE-407 Inefficient Algorithmic Complexity Allowed-with-Review 211
CWE-640 Weak Password Recovery Mechanism for Forgotten Password Allowed-with-Review 205
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor Allowed 203
CWE-259 Use of Hard-coded Password Allowed 203
CWE-61 UNIX Symbolic Link (Symlink) Following Allowed 199
CWE-305 Authentication Bypass by Primary Weakness Allowed 199
CWE-369 Divide By Zero Allowed 194
CWE-294 Authentication Bypass by Capture-replay Allowed 193
CWE-1236 Improper Neutralization of Formula Elements in a CSV File Allowed 191
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes Allowed 184
CWE-330 Use of Insufficiently Random Values Discouraged 184
CWE-494 Download of Code Without Integrity Check Allowed 181
CWE-326 Inadequate Encryption Strength Allowed-with-Review 178
CWE-280 Improper Handling of Insufficient Permissions or Privileges Allowed 176
CWE-788 Access of Memory Location After End of Buffer Discouraged 175
CWE-134 Use of Externally-Controlled Format String Allowed 174
CWE-1287 Improper Validation of Specified Type of Input Allowed 173
CWE-36 Absolute Path Traversal Allowed 166
CWE-131 Incorrect Calculation of Buffer Size Allowed 164
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification) Allowed 160
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Allowed 160
CWE-1021 Improper Restriction of Rendered UI Layers or Frames Allowed 160
CWE-602 Client-Side Enforcement of Server-Side Security Allowed-with-Review 147
CWE-457 Use of Uninitialized Variable Allowed 147
CWE-117 Improper Output Neutralization for Logs Allowed 144
CWE-521 Weak Password Requirements Allowed 143
CWE-922 Insecure Storage of Sensitive Information Allowed-with-Review 141
CWE-281 Improper Preservation of Permissions Allowed 140
CWE-703 Improper Check or Handling of Exceptional Conditions Discouraged 134
CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains Allowed 132
CWE-665 Improper Initialization Discouraged 132
CWE-943 Improper Neutralization of Special Elements in Data Query Logic Allowed-with-Review 131
CWE-193 Off-by-one Error Allowed 130
CWE-807 Reliance on Untrusted Inputs in a Security Decision Allowed 128
CWE-680 Integer Overflow to Buffer Overflow Discouraged 128
CWE-1220 Insufficient Granularity of Access Control Allowed 127
CWE-24 Path Traversal: '../filedir' Allowed 126
CWE-1392 Use of Default Credentials Allowed 126
CWE-425 Direct Request ('Forced Browsing') Allowed 125
CWE-441 Unintended Proxy or Intermediary ('Confused Deputy') Allowed-with-Review 124