Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-319Cleartext Transmission of Sensitive Information915BaseHigh
CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')912Base-
CWE-843Access of Resource Using Incompatible Type ('Type Confusion')884Base-
CWE-908Use of Uninitialized Resource854BaseMedium
CWE-312Cleartext Storage of Sensitive Information846Base-
CWE-415Double Free842VariantHigh
CWE-617Reachable Assertion810Base-
CWE-347Improper Verification of Cryptographic Signature804Base-
CWE-255CWE-255782--
CWE-203Observable Discrepancy780Base-
CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition775BaseMedium
CWE-404Improper Resource Shutdown or Release763ClassMedium
CWE-668Exposure of Resource to Wrong Sphere740Class-
CWE-346Origin Validation Error732Class-
CWE-667Improper Locking725Class-
CWE-345Insufficient Verification of Data Authenticity722Class-
CWE-693Protection Mechanism Failure716Pillar-
CWE-327Use of a Broken or Risky Cryptographic Algorithm698ClassHigh
CWE-426Untrusted Search Path674BaseHigh
CWE-290Authentication Bypass by Spoofing671Base-
CWE-288Authentication Bypass Using an Alternate Path or Channel651Base-
CWE-307Improper Restriction of Excessive Authentication Attempts639Base-
CWE-754Improper Check for Unusual or Exceptional Conditions625ClassMedium
CWE-129Improper Validation of Array Index623VariantHigh
CWE-209Generation of Error Message Containing Sensitive Information599BaseHigh