Common Weakness Enumeration (CWE)

1,006 CWEs

CWENameCVEsAbstractionLikelihoodDetails
CWE-73External Control of File Name or Path598BaseHigh
CWE-613Insufficient Session Expiration596Base-
CWE-755Improper Handling of Exceptional Conditions585ClassMedium
CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)579VariantHigh
CWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')564Variant-
CWE-191Integer Underflow (Wrap or Wraparound)547Base-
CWE-311Missing Encryption of Sensitive Data518ClassHigh
CWE-674Uncontrolled Recursion515Class-
CWE-116Improper Encoding or Escaping of Output511ClassHigh
CWE-126Buffer Over-read498Variant-
CWE-552Files or Directories Accessible to External Parties496Base-
CWE-23Relative Path Traversal484Base-
CWE-772Missing Release of Resource after Effective Lifetime480BaseHigh
CWE-1333Inefficient Regular Expression Complexity479BaseHigh
CWE-369Divide By Zero470BaseMedium
CWE-326Inadequate Encryption Strength462Class-
CWE-428Unquoted Search Path or Element452Base-
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')422Base-
CWE-384Session Fixation418Compound-
CWE-254CWE-254413--
CWE-1021Improper Restriction of Rendered UI Layers or Frames411Base-
CWE-134Use of Externally-Controlled Format String405BaseHigh
CWE-201Insertion of Sensitive Information Into Sent Data394Base-
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')391Base-
CWE-330Use of Insufficiently Random Values391ClassHigh