Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-325Missing Cryptographic Step61Base-
CWE-379Creation of Temporary File in Directory with Insecure Permissions61BaseLow
CWE-1285Improper Validation of Specified Index, Position, or Offset in Input60Base-
CWE-662Improper Synchronization60Class-
CWE-99Improper Control of Resource Identifiers ('Resource Injection')60ClassHigh
CWE-548Exposure of Information Through Directory Listing58Variant-
CWE-123Write-what-where Condition57BaseHigh
CWE-940Improper Verification of Source of a Communication Channel57Base-
CWE-300Channel Accessible by Non-Endpoint56Class-
CWE-805Buffer Access with Incorrect Length Value56BaseHigh
CWE-1391Use of Weak Credentials56Class-
CWE-87Improper Neutralization of Alternate XSS Syntax55Variant-
CWE-170Improper Null Termination53BaseMedium
CWE-340Generation of Predictable Numbers or Identifiers53Class-
CWE-405Asymmetric Resource Consumption (Amplification)50Class-
CWE-664Improper Control of a Resource Through its Lifetime48Pillar-
CWE-378Creation of Temporary File With Insecure Permissions47BaseHigh
CWE-385Covert Timing Channel45BaseMedium
CWE-183Permissive List of Allowed Inputs45Base-
CWE-636Not Failing Securely ('Failing Open')45Class-
CWE-273Improper Check for Dropped Privileges44BaseMedium
CWE-323Reusing a Nonce, Key Pair in Encryption44BaseHigh
CWE-353Missing Support for Integrity Check44BaseMedium
CWE-1393Use of Default Password44Base-
CWE-388CWE-38843--