Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-27Path Traversal: 'dir/../../filename'29Variant-
CWE-41Improper Resolution of Path Equivalence29Base-
CWE-778Insufficient Logging28BaseMedium
CWE-939Improper Authorization in Handler for Custom URL Scheme28Base-
CWE-1104Use of Unmaintained Third Party Components28Base-
CWE-758Reliance on Undefined, Unspecified, or Implementation-Defined Behavior27Class-
CWE-1275Sensitive Cookie with Improper SameSite Attribute27VariantMedium
CWE-279Incorrect Execution-Assigned Permissions26Variant-
CWE-270Privilege Context Switching Error26Base-
CWE-114Process Control26Class-
CWE-322Key Exchange without Entity Authentication26BaseHigh
CWE-180Incorrect Behavior Order: Validate Before Canonicalize26Variant-
CWE-1230Exposure of Sensitive Information Through Metadata26Base-
CWE-118Incorrect Access of Indexable Resource ('Range Error')25Class-
CWE-253Incorrect Check of Function Return Value25BaseLow
CWE-391Unchecked Error Condition25BaseMedium
CWE-523Unprotected Transport of Credentials25Base-
CWE-283Unverified Ownership25Base-
CWE-833Deadlock25Base-
CWE-592DEPRECATED: Authentication Bypass Issues24Class-
CWE-260Password in Configuration File24Base-
CWE-603Use of Client-Side Authentication24Base-
CWE-551Incorrect Behavior Order: Authorization Before Parsing and Canonicalization24Base-
CWE-402Transmission of Private Resources into a New Sphere ('Resource Leak')23Class-
CWE-460Improper Cleanup on Thrown Exception23BaseMedium