Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-257 Storing Passwords in a Recoverable Format Allowed 77
CWE-648 Incorrect Use of Privileged APIs Allowed 76
CWE-379 Creation of Temporary File in Directory with Insecure Permissions Allowed 76
CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute Allowed 72
CWE-706 Use of Incorrectly-Resolved Name or Reference Allowed-with-Review 71
CWE-636 Not Failing Securely ('Failing Open') Allowed-with-Review 71
CWE-653 Improper Isolation or Compartmentalization Allowed 70
CWE-29 Path Traversal: '\..\filename' Allowed 70
CWE-405 Asymmetric Resource Consumption (Amplification) Allowed-with-Review 69
CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax Allowed 67
CWE-548 Exposure of Information Through Directory Listing Allowed 66
CWE-87 Improper Neutralization of Alternate XSS Syntax Allowed 65
CWE-340 Generation of Predictable Numbers or Identifiers Allowed-with-Review 64
CWE-325 Missing Cryptographic Step Allowed 64
CWE-267 Privilege Defined With Unsafe Actions Allowed 63
CWE-170 Improper Null Termination Allowed 63
CWE-1395 Dependency on Vulnerable Third-Party Component Allowed-with-Review 63
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input Allowed 62
CWE-672 Operation on a Resource after Expiration or Release Allowed-with-Review 60
CWE-123 Write-what-where Condition Allowed 60
CWE-277 Insecure Inherited Permissions Allowed 57
CWE-300 Channel Accessible by Non-Endpoint Discouraged 56
CWE-940 Improper Verification of Source of a Communication Channel Allowed 55
CWE-183 Permissive List of Allowed Inputs Allowed 55
CWE-1391 Use of Weak Credentials Allowed-with-Review 55
CWE-834 Excessive Iteration Discouraged 54
CWE-825 Expired Pointer Dereference Allowed 54
CWE-805 Buffer Access with Incorrect Length Value Allowed 54
CWE-440 Expected Behavior Violation Allowed 54
CWE-696 Incorrect Behavior Order Allowed-with-Review 53
CWE-378 Creation of Temporary File With Insecure Permissions Allowed 52
CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') Allowed 51
CWE-302 Authentication Bypass by Assumed-Immutable Data Allowed 51
CWE-424 Improper Protection of Alternate Path Allowed-with-Review 50
CWE-353 Missing Support for Integrity Check Allowed 50
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data Allowed 50
CWE-323 Reusing a Nonce, Key Pair in Encryption Allowed 50
CWE-304 Missing Critical Step in Authentication Allowed 50
CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Allowed 49
CWE-667 Improper Locking Allowed-with-Review 49
CWE-565 Reliance on Cookies without Validation and Integrity Checking Allowed 49
CWE-664 Improper Control of a Resource Through its Lifetime Discouraged 48
CWE-1385 Missing Origin Validation in WebSockets Allowed 48
CWE-1004 Sensitive Cookie Without 'HttpOnly' Flag Allowed 48
CWE-791 Incomplete Filtering of Special Elements Allowed 46