Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-1392Use of Default Credentials110Base-
CWE-680Integer Overflow to Buffer Overflow109Compound-
CWE-409Improper Handling of Highly Compressed Data (Data Amplification)105Base-
CWE-669Incorrect Resource Transfer Between Spheres104Class-
CWE-1220Insufficient Granularity of Access Control104Base-
CWE-377Insecure Temporary File104Class-
CWE-823Use of Out-of-range Pointer Offset103Base-
CWE-909Missing Initialization of Resource102ClassMedium
CWE-303Incorrect Implementation of Authentication Algorithm102Base-
CWE-763Release of Invalid Pointer or Reference100Base-
CWE-506Embedded Malicious Code99Class-
CWE-913Improper Control of Dynamically-Managed Code Resources98Class-
CWE-178Improper Handling of Case Sensitivity96Base-
CWE-538Insertion of Sensitive Information into Externally-Accessible File or Directory96Base-
CWE-840CWE-84095--
CWE-807Reliance on Untrusted Inputs in a Security Decision94BaseHigh
CWE-620Unverified Password Change93Base-
CWE-598Use of GET Request Method With Sensitive Query Strings92Variant-
CWE-1286Improper Validation of Syntactic Correctness of Input91Base-
CWE-320CWE-32091--
CWE-825Expired Pointer Dereference91Base-
CWE-328Use of Weak Hash90Base-
CWE-926Improper Export of Android Application Components90Variant-
CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')89BaseMedium
CWE-489Active Debug Code89Base-