Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-366Race Condition within a Thread19BaseMedium
CWE-84Improper Neutralization of Encoded URI Schemes in a Web Page19Variant-
CWE-759Use of a One-Way Hash without a Salt19Variant-
CWE-453Insecure Default Variable Initialization19Variant-
CWE-698Execution After Redirect (EAR)19Base-
CWE-26Path Traversal: '/dir/../filename'18Variant-
CWE-296Improper Following of a Certificate's Chain of Trust18BaseLow
CWE-406Insufficient Control of Network Message Volume (Network Amplification)18Class-
CWE-804Guessable CAPTCHA18Base-
CWE-927Use of Implicit Intent for Sensitive Communication18Variant-
CWE-1394Use of Default Cryptographic Key18Base-
CWE-172Encoding Error17Class-
CWE-642External Control of Critical State Data17ClassHigh
CWE-341Predictable from Observable State17Base-
CWE-155Improper Neutralization of Wildcards or Matching Symbols17Variant-
CWE-1260Improper Handling of Overlap Between Protected Memory Ranges17Base-
CWE-641Improper Restriction of Names for Files and Other Resources17BaseLow
CWE-395Use of NullPointerException Catch to Detect NULL Pointer Dereference17Base-
CWE-1259Improper Restriction of Security Token Assignment17Base-
CWE-837Improper Enforcement of a Single, Unique Action17Base-
CWE-836Use of Password Hash Instead of Password for Authentication16Base-
CWE-477Use of Obsolete Function16Base-
CWE-475Undefined Behavior for Input to API16Base-
CWE-549Missing Password Field Masking16Base-
CWE-417CWE-41715--