Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-193Off-by-one Error224Base-
CWE-494Download of Code Without Integrity Check222BaseMedium
CWE-789Memory Allocation with Excessive Size Value219Variant-
CWE-131Incorrect Calculation of Buffer Size218BaseHigh
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')218Base-
CWE-256Plaintext Storage of a Password216BaseHigh
CWE-338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)211BaseMedium
CWE-459Incomplete Cleanup208Base-
CWE-917Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')206Base-
CWE-359Exposure of Private Personal Information to an Unauthorized Actor202Base-
CWE-259Use of Hard-coded Password200VariantHigh
CWE-749Exposed Dangerous Method or Function184BaseLow
CWE-184Incomplete List of Disallowed Inputs184Base-
CWE-204Observable Response Discrepancy182Base-
CWE-208Observable Timing Discrepancy181Base-
CWE-35Path Traversal: '.../...//'180Variant-
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')180VariantMedium
CWE-354Improper Validation of Integrity Check Value179BaseMedium
CWE-252Unchecked Return Value178BaseLow
CWE-602Client-Side Enforcement of Server-Side Security169ClassMedium
CWE-61UNIX Symbolic Link (Symlink) Following167CompoundHigh
CWE-697Incorrect Comparison166Pillar-
CWE-17CWE-17166--
CWE-703Improper Check or Handling of Exceptional Conditions162Pillar-
CWE-305Authentication Bypass by Primary Weakness162Base-