Common Weakness Enumeration
Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.
779 CWEs
API response| CWE | Name | Mapping usage | Occurrences |
|---|---|---|---|
| CWE-257 | Storing Passwords in a Recoverable Format | Allowed | 77 |
| CWE-648 | Incorrect Use of Privileged APIs | Allowed | 76 |
| CWE-379 | Creation of Temporary File in Directory with Insecure Permissions | Allowed | 76 |
| CWE-614 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | Allowed | 72 |
| CWE-706 | Use of Incorrectly-Resolved Name or Reference | Allowed-with-Review | 71 |
| CWE-636 | Not Failing Securely ('Failing Open') | Allowed-with-Review | 71 |
| CWE-653 | Improper Isolation or Compartmentalization | Allowed | 70 |
| CWE-29 | Path Traversal: '\..\filename' | Allowed | 70 |
| CWE-405 | Asymmetric Resource Consumption (Amplification) | Allowed-with-Review | 69 |
| CWE-644 | Improper Neutralization of HTTP Headers for Scripting Syntax | Allowed | 67 |
| CWE-548 | Exposure of Information Through Directory Listing | Allowed | 66 |
| CWE-87 | Improper Neutralization of Alternate XSS Syntax | Allowed | 65 |
| CWE-340 | Generation of Predictable Numbers or Identifiers | Allowed-with-Review | 64 |
| CWE-325 | Missing Cryptographic Step | Allowed | 64 |
| CWE-267 | Privilege Defined With Unsafe Actions | Allowed | 63 |
| CWE-170 | Improper Null Termination | Allowed | 63 |
| CWE-1395 | Dependency on Vulnerable Third-Party Component | Allowed-with-Review | 63 |
| CWE-1285 | Improper Validation of Specified Index, Position, or Offset in Input | Allowed | 62 |
| CWE-672 | Operation on a Resource after Expiration or Release | Allowed-with-Review | 60 |
| CWE-123 | Write-what-where Condition | Allowed | 60 |
| CWE-277 | Insecure Inherited Permissions | Allowed | 57 |
| CWE-300 | Channel Accessible by Non-Endpoint | Discouraged | 56 |
| CWE-940 | Improper Verification of Source of a Communication Channel | Allowed | 55 |
| CWE-183 | Permissive List of Allowed Inputs | Allowed | 55 |
| CWE-1391 | Use of Weak Credentials | Allowed-with-Review | 55 |
| CWE-834 | Excessive Iteration | Discouraged | 54 |
| CWE-825 | Expired Pointer Dereference | Allowed | 54 |
| CWE-805 | Buffer Access with Incorrect Length Value | Allowed | 54 |
| CWE-440 | Expected Behavior Violation | Allowed | 54 |
| CWE-696 | Incorrect Behavior Order | Allowed-with-Review | 53 |
| CWE-378 | Creation of Temporary File With Insecure Permissions | Allowed | 52 |
| CWE-776 | Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | Allowed | 51 |
| CWE-302 | Authentication Bypass by Assumed-Immutable Data | Allowed | 51 |
| CWE-424 | Improper Protection of Alternate Path | Allowed-with-Review | 50 |
| CWE-353 | Missing Support for Integrity Check | Allowed | 50 |
| CWE-349 | Acceptance of Extraneous Untrusted Data With Trusted Data | Allowed | 50 |
| CWE-323 | Reusing a Nonce, Key Pair in Encryption | Allowed | 50 |
| CWE-304 | Missing Critical Step in Authentication | Allowed | 50 |
| CWE-917 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') | Allowed | 49 |
| CWE-667 | Improper Locking | Allowed-with-Review | 49 |
| CWE-565 | Reliance on Cookies without Validation and Integrity Checking | Allowed | 49 |
| CWE-664 | Improper Control of a Resource Through its Lifetime | Discouraged | 48 |
| CWE-1385 | Missing Origin Validation in WebSockets | Allowed | 48 |
| CWE-1004 | Sensitive Cookie Without 'HttpOnly' Flag | Allowed | 48 |
| CWE-791 | Incomplete Filtering of Special Elements | Allowed | 46 |