Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-918Server-Side Request Forgery (SSRF)3,310Base-
CWE-269Improper Privilege Management3,249ClassMedium
CWE-502Deserialization of Untrusted Data3,121BaseMedium
CWE-306Missing Authentication for Critical Function2,991BaseHigh
CWE-122Heap-based Buffer Overflow2,777VariantHigh
CWE-399CWE-3992,695--
CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2,592ClassMedium
CWE-310CWE-3102,518--
CWE-639Authorization Bypass Through User-Controlled Key2,390BaseHigh
CWE-770Allocation of Resources Without Limits or Throttling2,233BaseHigh
CWE-401Missing Release of Memory after Effective Lifetime1,889VariantMedium
CWE-798Use of Hard-coded Credentials1,793BaseHigh
CWE-732Incorrect Permission Assignment for Critical Resource1,736ClassHigh
CWE-59Improper Link Resolution Before File Access ('Link Following')1,688BaseMedium
CWE-601URL Redirection to Untrusted Site ('Open Redirect')1,672BaseLow
CWE-276Incorrect Default Permissions1,549BaseMedium
CWE-285Improper Authorization1,536ClassHigh
CWE-295Improper Certificate Validation1,509Base-
CWE-522Insufficiently Protected Credentials1,447Class-
CWE-98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1,294VariantHigh
CWE-611Improper Restriction of XML External Entity Reference1,291Base-
CWE-189CWE-1891,249--
CWE-427Uncontrolled Search Path Element1,216Base-
CWE-532Insertion of Sensitive Information into Log File1,205BaseMedium
CWE-266Incorrect Privilege Assignment1,094Base-