Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-335Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)43Base-
CWE-302Authentication Bypass by Assumed-Immutable Data43Base-
CWE-440Expected Behavior Violation43Base-
CWE-1004Sensitive Cookie Without 'HttpOnly' Flag43VariantMedium
CWE-261Weak Encoding for Password42Base-
CWE-274Improper Handling of Insufficient Privileges42Base-
CWE-185Incorrect Regular Expression41Class-
CWE-791Incomplete Filtering of Special Elements41Base-
CWE-606Unchecked Input for Loop Condition41Base-
CWE-289Authentication Bypass by Alternate Name40Base-
CWE-124Buffer Underwrite ('Buffer Underflow')40BaseMedium
CWE-349Acceptance of Extraneous Untrusted Data With Trusted Data40Base-
CWE-696Incorrect Behavior Order40Class-
CWE-304Missing Critical Step in Authentication39Base-
CWE-471Modification of Assumed-Immutable Data (MAID)38Base-
CWE-924Improper Enforcement of Message Integrity During Transmission in a Communication Channel38Base-
CWE-202Exposure of Sensitive Information Through Data Queries38BaseMedium
CWE-420Unprotected Alternate Channel38Base-
CWE-782Exposed IOCTL with Insufficient Access Control38Variant-
CWE-272Least Privilege Violation38Base-
CWE-316Cleartext Storage of Sensitive Information in Memory37Variant-
CWE-75Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)36Class-
CWE-1385Missing Origin Validation in WebSockets36Variant-
CWE-757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')35Base-
CWE-226Sensitive Information in Resource Not Removed Before Reuse35Base-