Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-354 Improper Validation of Integrity Check Value Allowed 123
CWE-436 Interpretation Conflict Allowed-with-Review 122
CWE-506 Embedded Malicious Code Allowed-with-Review 120
CWE-130 Improper Handling of Length Parameter Inconsistency Allowed 118
CWE-823 Use of Out-of-range Pointer Offset Allowed 117
CWE-252 Unchecked Return Value Allowed 117
CWE-451 User Interface (UI) Misrepresentation of Critical Information Allowed-with-Review 115
CWE-459 Incomplete Cleanup Allowed 114
CWE-697 Incorrect Comparison Discouraged 113
CWE-303 Incorrect Implementation of Authentication Algorithm Allowed 113
CWE-377 Insecure Temporary File Allowed-with-Review 110
CWE-620 Unverified Password Change Allowed 109
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') Allowed 109
CWE-670 Always-Incorrect Control Flow Implementation Allowed-with-Review 108
CWE-772 Missing Release of Resource after Effective Lifetime Allowed 107
CWE-489 Active Debug Code Allowed 107
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') Allowed 107
CWE-348 Use of Less Trusted Source Allowed 104
CWE-328 Use of Weak Hash Allowed 104
CWE-358 Improperly Implemented Security Check for Standard Allowed 103
CWE-598 Use of HTTP Request With Sensitive Query String Allowed 102
CWE-1390 Weak Authentication Allowed-with-Review 102
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory Allowed 101
CWE-331 Insufficient Entropy Allowed 99
CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences Allowed 99
CWE-926 Improper Export of Android Application Components Allowed 98
CWE-913 Improper Control of Dynamically-Managed Code Resources Allowed-with-Review 98
CWE-799 Improper Control of Interaction Frequency Allowed-with-Review 95
CWE-197 Numeric Truncation Error Allowed 94
CWE-1286 Improper Validation of Syntactic Correctness of Input Allowed 94
CWE-178 Improper Handling of Case Sensitivity Allowed 93
CWE-912 Hidden Functionality Allowed-with-Review 92
CWE-704 Incorrect Type Conversion or Cast Allowed-with-Review 91
CWE-591 Sensitive Data Storage in Improperly Locked Memory Allowed 91
CWE-610 Externally Controlled Reference to a Resource in Another Sphere Discouraged 90
CWE-15 External Control of System or Configuration Setting Allowed 89
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer Allowed 88
CWE-923 Improper Restriction of Communication Channel to Intended Endpoints Allowed-with-Review 87
CWE-916 Use of Password Hash With Insufficient Computational Effort Allowed 85
CWE-91 XML Injection (aka Blind XPath Injection) Allowed-with-Review 85
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') Allowed 85
CWE-669 Incorrect Resource Transfer Between Spheres Allowed-with-Review 85
CWE-524 Use of Cache Containing Sensitive Information Allowed 81
CWE-681 Incorrect Conversion between Numeric Types Allowed 80
CWE-297 Improper Validation of Certificate with Host Mismatch Allowed 80
CWE-99 Improper Control of Resource Identifiers ('Resource Injection') Allowed-with-Review 79
CWE-472 External Control of Assumed-Immutable Web Parameter Allowed 79
CWE-841 Improper Enforcement of Behavioral Workflow Allowed 78
CWE-682 Incorrect Calculation Discouraged 78