Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-424Improper Protection of Alternate Path35Class-
CWE-691Insufficient Control Flow Management35Pillar-
CWE-1300Improper Protection of Physical Side Channels35Base-
CWE-1289Improper Validation of Unsafe Equivalence in Input34Base-
CWE-488Exposure of Data Element to Wrong Session34Base-
CWE-92DEPRECATED: Improper Sanitization of Custom Special Characters34Base-
CWE-501Trust Boundary Violation33Base-
CWE-690Unchecked Return Value to NULL Pointer Dereference33Compound-
CWE-241Improper Handling of Unexpected Data Type33Base-
CWE-356Product UI does not Warn User of Unsafe Actions32Base-
CWE-213Exposure of Sensitive Information Due to Incompatible Policies32Base-
CWE-1288Improper Validation of Consistency within Input32Base-
CWE-115Misinterpretation of Input31Base-
CWE-313Cleartext Storage in a File or on Disk31Variant-
CWE-176Improper Handling of Unicode Encoding31Variant-
CWE-233Improper Handling of Parameters31Base-
CWE-540Inclusion of Sensitive Information in Source Code31Base-
CWE-286Incorrect User Management31Class-
CWE-525Use of Web Browser Cache Containing Sensitive Information31Variant-
CWE-214Invocation of Process Using Visible Sensitive Information30Base-
CWE-350Reliance on Reverse DNS Resolution for a Security-Critical Action29Variant-
CWE-282Improper Ownership Management29Class-
CWE-684Incorrect Provision of Specified Functionality29Class-
CWE-158Improper Neutralization of Null Byte or NUL Character29Variant-
CWE-83Improper Neutralization of Script in Attributes in a Web Page29Variant-