Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-280Improper Handling of Insufficient Permissions or Privileges159Base-
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes155Base-
CWE-1287Improper Validation of Specified Type of Input151Base-
CWE-670Always-Incorrect Control Flow Implementation149Class-
CWE-788Access of Memory Location After End of Buffer147Base-
CWE-407Inefficient Algorithmic Complexity145ClassLow
CWE-472External Control of Assumed-Immutable Web Parameter145Base-
CWE-331Insufficient Entropy143Base-
CWE-436Interpretation Conflict138Class-
CWE-36Absolute Path Traversal138Base-
CWE-682Incorrect Calculation134PillarHigh
CWE-91XML Injection (aka Blind XPath Injection)133Base-
CWE-358Improperly Implemented Security Check for Standard133Base-
CWE-706Use of Incorrectly-Resolved Name or Reference129Class-
CWE-681Incorrect Conversion between Numeric Types128BaseHigh
CWE-916Use of Password Hash With Insufficient Computational Effort127Base-
CWE-942Permissive Cross-domain Policy with Untrusted Domains123Variant-
CWE-212Improper Removal of Sensitive Information Before Storage or Transfer120Base-
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')120Class-
CWE-24Path Traversal: '../filedir'117Variant-
CWE-275CWE-275114--
CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')112Variant-
CWE-834Excessive Iteration112Class-
CWE-130Improper Handling of Length Parameter Inconsistency111Base-
CWE-117Improper Output Neutralization for Logs111BaseMedium