Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-96Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')23Base-
CWE-1327Binding to an Unrestricted IP Address23Base-
CWE-1191On-Chip Debug and Test Interface With Improper Access Control23Base-
CWE-195Signed to Unsigned Conversion Error22Variant-
CWE-268Privilege Chaining22BaseHigh
CWE-324Use of a Key Past its Expiration Date22BaseLow
CWE-1295Debug Messages Revealing Unnecessary Information22Base-
CWE-1325Improperly Controlled Sequential Memory Allocation22Base-
CWE-1240Use of a Cryptographic Primitive with a Risky Implementation22Base-
CWE-708Incorrect Ownership Assignment21Base-
CWE-229Improper Handling of Values21Base-
CWE-244Improper Clearing of Heap Memory Before Release ('Heap Inspection')21Variant-
CWE-526Cleartext Storage of Sensitive Information in an Environment Variable20Variant-
CWE-410Insufficient Resource Pool20Base-
CWE-657Violation of Secure Design Principles20Class-
CWE-228Improper Handling of Syntactically Invalid Structure20Class-
CWE-215Insertion of Sensitive Information Into Debugging Code20Base-
CWE-364Signal Handler Race Condition20BaseMedium
CWE-357Insufficient UI Warning of Dangerous Operations20Base-
CWE-590Free of Memory not on the Heap20Variant-
CWE-779Logging of Excessive Data20BaseLow
CWE-911Improper Update of Reference Count20BaseMedium
CWE-783Operator Precedence Logic Error20BaseLow
CWE-140Improper Neutralization of Delimiters20Base-
CWE-390Detection of Error Condition Without Action19BaseMedium