Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-830Inclusion of Web Functionality from an Untrusted Source13Variant-
CWE-1022Use of Web Link to Untrusted Target with window.opener Access13VariantMedium
CWE-1258Exposure of Sensitive System Information Due to Uncleared Debug Information13Base-
CWE-25Path Traversal: '/../filedir'13Variant-
CWE-762Mismatched Memory Management Routines13VariantLow
CWE-1263Improper Physical Access Control13Class-
CWE-392Missing Report of Error Condition12Base-
CWE-419Unprotected Primary Channel12Base-
CWE-271Privilege Dropping / Lowering Errors12ClassHigh
CWE-265CWE-26512--
CWE-187Partial String Comparison12Variant-
CWE-76Improper Neutralization of Equivalent Special Elements12BaseHigh
CWE-230Improper Handling of Missing Values12Variant-
CWE-701CWE-70112--
CWE-530Exposure of Backup File to an Unauthorized Control Sphere12Variant-
CWE-1341Multiple Releases of Same Resource or Handle12Base-
CWE-242Use of Inherently Dangerous Function11BaseHigh
CWE-363Race Condition Enabling Link Following11Base-
CWE-547Use of Hard-coded, Security-relevant Constants11Base-
CWE-941Incorrectly Specified Destination in a Communication Channel11Base-
CWE-656Reliance on Security Through Obscurity11Class-
CWE-299Improper Check for Certificate Revocation11BaseMedium
CWE-694Use of Multiple Resources with Duplicate Identifier11Base-
CWE-141Improper Neutralization of Parameter/Argument Delimiters11Variant-
CWE-232Improper Handling of Undefined Values11Variant-