Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')46,379BaseHigh
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')20,398BaseHigh
CWE-787Out-of-bounds Write14,658BaseHigh
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer14,178ClassHigh
CWE-20Improper Input Validation13,074ClassHigh
CWE-200Exposure of Sensitive Information to an Unauthorized Actor10,799ClassHigh
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9,956BaseHigh
CWE-352Cross-Site Request Forgery (CSRF)9,593CompoundMedium
CWE-125Out-of-bounds Read9,410Base-
CWE-862Missing Authorization9,325ClassHigh
CWE-416Use After Free8,273VariantHigh
CWE-284Improper Access Control7,186Pillar-
CWE-94Improper Control of Generation of Code ('Code Injection')6,945BaseMedium
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6,501BaseHigh
CWE-476NULL Pointer Dereference5,560BaseMedium
CWE-264CWE-2645,493--
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')5,188ClassHigh
CWE-287Improper Authentication4,716ClassHigh
CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4,392BaseHigh
CWE-434Unrestricted Upload of File with Dangerous Type4,329BaseMedium
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')3,748ClassHigh
CWE-121Stack-based Buffer Overflow3,678VariantHigh
CWE-863Incorrect Authorization3,669ClassHigh
CWE-400Uncontrolled Resource Consumption3,515ClassHigh
CWE-190Integer Overflow or Wraparound3,449BaseMedium