Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-177Improper Handling of URL Encoding (Hex Encoding)15Variant-
CWE-413Improper Resource Locking15Base-
CWE-394Unexpected Status Code or Return Value15Base-
CWE-1050Excessive Platform Resource Consumption within a Loop15Base-
CWE-351Insufficient Type Distinction15Base-
CWE-1386Insecure Operation on Windows Junction / Mount Point15Base-
CWE-820Missing Synchronization15Base-
CWE-838Inappropriate Encoding for Output Context14Base-
CWE-625Permissive Regular Expression14Base-
CWE-329Generation of Predictable IV with CBC Mode14VariantMedium
CWE-334Small Space of Random Values14Base-
CWE-599Missing Validation of OpenSSL Certificate14Variant-
CWE-474Use of Function with Inconsistent Implementations14Base-
CWE-1023Incomplete Comparison with Missing Factors14Class-
CWE-790Improper Filtering of Special Elements14Class-
CWE-643Improper Neutralization of Data within XPath Expressions ('XPath Injection')14BaseHigh
CWE-821Incorrect Synchronization14Base-
CWE-308Use of Single-factor Authentication14BaseHigh
CWE-449The UI Performs the Wrong Action14Base-
CWE-1242Inclusion of Undocumented Features or Chicken Bits14Base-
CWE-1025Comparison Using Wrong Factors14Base-
CWE-138Improper Neutralization of Special Elements13Class-
CWE-159Improper Handling of Invalid Use of Special Elements13Class-
CWE-1244Internal Asset Exposed to Unsafe Debug Access Level or State13Base-
CWE-337Predictable Seed in Pseudo-Random Number Generator (PRNG)13Variant-