Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-1284Improper Validation of Specified Quantity in Input385Base-
CWE-922Insecure Storage of Sensitive Information377Class-
CWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere376Base-
CWE-451User Interface (UI) Misrepresentation of Critical Information363Class-
CWE-665Improper Initialization357ClassMedium
CWE-250Execution with Unnecessary Privileges357BaseMedium
CWE-281Improper Preservation of Permissions339Base-
CWE-321Use of Hard-coded Cryptographic Key334VariantHigh
CWE-1188Initialization of a Resource with an Insecure Default322Base-
CWE-829Inclusion of Functionality from Untrusted Control Sphere319Base-
CWE-16CWE-16318--
CWE-640Weak Password Recovery Mechanism for Forgotten Password313BaseHigh
CWE-1236Improper Neutralization of Formula Elements in a CSV File305Base-
CWE-824Access of Uninitialized Pointer290Base-
CWE-704Incorrect Type Conversion or Cast280Class-
CWE-521Weak Password Requirements261Base-
CWE-248Uncaught Exception261Base-
CWE-294Authentication Bypass by Capture-replay260BaseHigh
CWE-707Improper Neutralization254Pillar-
CWE-610Externally Controlled Reference to a Resource in Another Sphere244Class-
CWE-425Direct Request ('Forced Browsing')240Base-
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine236Base-
CWE-19CWE-19235--
CWE-457Use of Uninitialized Variable234VariantHigh
CWE-822Untrusted Pointer Dereference226Base-