Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-1390Weak Authentication88Class-
CWE-672Operation on a Resource after Expiration or Release88Class-
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')87Base-
CWE-912Hidden Functionality87Class-
CWE-943Improper Neutralization of Special Elements in Data Query Logic86Class-
CWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')79Base-
CWE-591Sensitive Data Storage in Improperly Locked Memory77Variant-
CWE-565Reliance on Cookies without Validation and Integrity Checking76Base-
CWE-150Improper Neutralization of Escape, Meta, or Control Sequences76Variant-
CWE-799Improper Control of Interaction Frequency76Class-
CWE-15External Control of System or Configuration Setting76Base-
CWE-653Improper Isolation or Compartmentalization72Class-
CWE-277Insecure Inherited Permissions71Variant-
CWE-297Improper Validation of Certificate with Host Mismatch69VariantHigh
CWE-923Improper Restriction of Communication Channel to Intended Endpoints67Class-
CWE-648Incorrect Use of Privileged APIs67BaseLow
CWE-197Numeric Truncation Error67BaseLow
CWE-841Improper Enforcement of Behavioral Workflow67Base-
CWE-524Use of Cache Containing Sensitive Information66Base-
CWE-267Privilege Defined With Unsafe Actions66Base-
CWE-257Storing Passwords in a Recoverable Format66BaseHigh
CWE-614Sensitive Cookie in HTTPS Session Without 'Secure' Attribute65Variant-
CWE-348Use of Less Trusted Source65Base-
CWE-29Path Traversal: '\..\filename'65Variant-
CWE-644Improper Neutralization of HTTP Headers for Scripting Syntax64VariantHigh