Common Weakness Enumeration

Browse CWEs ranked by the number of vulnerabilities referencing them, and pivot to weakness details, mitigations, and related attack patterns.

Reset

779 CWEs

API response
CWE Name Mapping usage Occurrences
CWE-488 Exposure of Data Element to Wrong Session Allowed 46
CWE-420 Unprotected Alternate Channel Allowed 46
CWE-274 Improper Handling of Insufficient Privileges Discouraged 46
CWE-261 Weak Encoding for Password Allowed 46
CWE-226 Sensitive Information in Resource Not Removed Before Reuse Allowed 45
CWE-124 Buffer Underwrite ('Buffer Underflow') Allowed 45
CWE-606 Unchecked Input for Loop Condition Allowed 44
CWE-385 Covert Timing Channel Allowed 44
CWE-180 Incorrect Behavior Order: Validate Before Canonicalize Allowed 44
CWE-471 Modification of Assumed-Immutable Data (MAID) Allowed 43
CWE-289 Authentication Bypass by Alternate Name Allowed 43
CWE-214 Invocation of Process Using Visible Sensitive Information Allowed 43
CWE-202 Exposure of Sensitive Information Through Data Queries Allowed 43
CWE-1289 Improper Validation of Unsafe Equivalence in Input Allowed 43
CWE-778 Insufficient Logging Allowed 42
CWE-272 Least Privilege Violation Allowed 42
CWE-92 DEPRECATED: Improper Sanitization of Custom Special Characters Prohibited 41
CWE-540 Inclusion of Sensitive Information in Source Code Allowed 41
CWE-1393 Use of Default Password Allowed 41
CWE-782 Exposed IOCTL with Insufficient Access Control Allowed 40
CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') Allowed 40
CWE-313 Cleartext Storage in a File or on Disk Allowed 38
CWE-185 Incorrect Regular Expression Allowed-with-Review 38
CWE-41 Improper Resolution of Path Equivalence Allowed 37
CWE-283 Unverified Ownership Allowed 37
CWE-176 Improper Handling of Unicode Encoding Allowed 37
CWE-691 Insufficient Control Flow Management Discouraged 36
CWE-690 Unchecked Return Value to NULL Pointer Dereference Discouraged 36
CWE-1104 Use of Unmaintained Third Party Components Allowed 36
CWE-684 Incorrect Provision of Specified Functionality Allowed-with-Review 35
CWE-316 Cleartext Storage of Sensitive Information in Memory Allowed 35
CWE-241 Improper Handling of Unexpected Data Type Allowed 35
CWE-115 Misinterpretation of Input Allowed 35
CWE-763 Release of Invalid Pointer or Reference Allowed 34
CWE-525 Use of Web Browser Cache Containing Sensitive Information Allowed 34
CWE-501 Trust Boundary Violation Allowed 34
CWE-322 Key Exchange without Entity Authentication Allowed 34
CWE-213 Exposure of Sensitive Information Due to Incompatible Policies Allowed 34
CWE-1288 Improper Validation of Consistency within Input Allowed 34
CWE-1275 Sensitive Cookie with Improper SameSite Attribute Allowed 34
CWE-83 Improper Neutralization of Script in Attributes in a Web Page Allowed 33
CWE-603 Use of Client-Side Authentication Allowed 33
CWE-350 Reliance on Reverse DNS Resolution for a Security-Critical Action Allowed 33
CWE-282 Improper Ownership Management Allowed-with-Review 33
CWE-270 Privilege Context Switching Error Allowed 33
CWE-460 Improper Cleanup on Thrown Exception Allowed 32
CWE-356 Product UI does not Warn User of Unsafe Actions Allowed 32
CWE-27 Path Traversal: 'dir/../../filename' Allowed 32
CWE-195 Signed to Unsigned Conversion Error Allowed 32
CWE-391 Unchecked Error Condition Prohibited 31