Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/CWEs
Weakness Classes

CWE Index

1460 Common Weakness Enumeration classes tracked across the Gold vulnerability database.

CWE-400Uncontrolled Resource Consumption
282
CWE-1333Inefficient Regular Expression (ReDoS)
202
CWE-20Improper Input Validation
180
CWE-1321Prototype Pollution
177
CWE-79Cross-site Scripting (XSS)
163
CWE-770Allocation of Resources Without Limits
137
CWE-835Infinite Loop
131
CWE-22Path Traversal
129
CWE-787Out-of-bounds Write
112
CWE-200Exposure of Sensitive Information
107
CWE-94Code Injection
91
CWE-416Use After Free
78
CWE-476NULL Pointer Dereference
72
CWE-502Deserialization of Untrusted Data
65
CWE-122Heap-based Buffer Overflow
64
CWE-125Out-of-bounds Read
61
CWE-119Improper Restriction of Memory Buffer Operations
59
CWE-78OS Command Injection
56
CWE-295Improper Certificate Validation
49
CWE-74Injection
49
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')
44
CWE-190Integer Overflow or Wraparound
43
CWE-601Open Redirect
43
CWE-918Server-Side Request Forgery (SSRF)
42
CWE-407Inefficient Algorithmic Complexity
41
CWE-399Resource Management Errors
40
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
40
CWE-264Permissions, Privileges, and Access Controls
38
CWE-59Link Following
35
CWE-352Cross-Site Request Forgery (CSRF)
34
CWE-310Cryptographic Issues
33
CWE-362Race Condition
33
CWE-347Improper Verification of Cryptographic Signature
31
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
31
CWE-674Uncontrolled Recursion
31
CWE-754Improper Check for Unusual or Exceptional Conditions
31
CWE-120Classic Buffer Overflow
29
CWE-284Improper Access Control
29
CWE-116Improper Encoding or Escaping of Output
28
CWE-908Use of Uninitialized Resource
27
CWE-843Type Confusion
26
CWE-287Improper Authentication
25
CWE-89SQL Injection
23
CWE-436Interpretation Conflict
20
CWE-862Missing Authorization
20
CWE-415Double Free
19
CWE-189Numeric Errors
18
CWE-704Incorrect Type Conversion or Cast
18
CWE-1284Improper Validation of Specified Quantity in Input
16
CWE-327Broken or Risky Cryptographic Algorithm
16
CWE-346Origin Validation Error
16
CWE-606Unchecked Input for Loop Condition
16
CWE-77Command Injection
15
CWE-1289Improper Validation of Unsafe Equivalence in Input
14
CWE-212Improper Removal of Sensitive Information Before Storage or Transfer
14
CWE-354Improper Validation of Integrity Check Value
14
CWE-434Unrestricted Upload of Dangerous File Type
14
CWE-330Use of Insufficiently Random Values
13
CWE-409Improper Handling of Highly Compressed Data (Data Amplification)
13
CWE-823Use of Out-of-range Pointer Offset
13
CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
12
CWE-201Insertion of Sensitive Information Into Sent Data
12
CWE-306Missing Authentication for Critical Function
12
CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition
12
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
12
CWE-471Modification of Assumed-Immutable Data (MAID)
12
CWE-61UNIX Symbolic Link (Symlink) Following
12
CWE-668Exposure of Resource to Wrong Sphere
11
CWE-67Improper Handling of Windows Device Names
11
CWE-863Incorrect Authorization
11
CWE-1021Improper Restriction of Rendered UI Layers
10
CWE-126Buffer Over-read
10
CWE-131Incorrect Calculation of Buffer Size
10
CWE-680Integer Overflow to Buffer Overflow
10
CWE-697Incorrect Comparison
10
CWE-185Incorrect Regular Expression
9
CWE-203Observable Discrepancy
9
CWE-276Incorrect Default Permissions
9
CWE-670Always-Incorrect Control Flow Implementation
9
CWE-1050Excessive Platform Resource Consumption within a Loop
8
CWE-121Stack-based Buffer Overflow
8
CWE-140Improper Neutralization of Delimiters
8
CWE-183Permissive List of Allowed Inputs
8
CWE-248Uncaught Exception
8
CWE-338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
8
CWE-665Improper Initialization
8
CWE-755Improper Handling of Exceptional Conditions
8
CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
8
CWE-184Incomplete List of Disallowed Inputs
7
CWE-281Improper Preservation of Permissions
7
CWE-345Insufficient Verification of Data Authenticity
7
CWE-359Exposure of Private Personal Information to an Unauthorized Actor
7
CWE-494Download of Code Without Integrity Check
7
CWE-672Operation on a Resource after Expiration or Release
7
CWE-178Improper Handling of Case Sensitivity
6
CWE-180Incorrect Behavior Order: Validate Before Canonicalize
6
CWE-524Use of Cache Containing Sensitive Information
6
CWE-551Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
6
CWE-611XML External Entity (XXE)
6
CWE-706Use of Incorrectly-Resolved Name or Reference
6
CWE-772Missing Release of Resource after Effective Lifetime
6
CWE-829Inclusion of Functionality from Untrusted Control Sphere
6
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
6
CWE-917Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
6
CWE-129Improper Validation of Array Index
5
CWE-1385Missing Origin Validation in WebSockets
5
CWE-17DEPRECATED: Code
5
CWE-23Relative Path Traversal
5
CWE-2547PK - Security Features
5
CWE-732Incorrect Permission Assignment
5
CWE-824Access of Uninitialized Pointer
5
CWE-834Excessive Iteration
5
CWE-1220Insufficient Granularity of Access Control
4
CWE-1286Improper Validation of Syntactic Correctness of Input
4
CWE-130Improper Handling of Length Parameter Inconsistency
4
CWE-134Use of Externally-Controlled Format String
4
CWE-150Improper Neutralization of Escape, Meta, or Control Sequences
4
CWE-191Integer Underflow (Wrap or Wraparound)
4
CWE-285Improper Authorization
4
CWE-290Authentication Bypass by Spoofing
4
CWE-331Insufficient Entropy
4
CWE-350Reliance on Reverse DNS Resolution for a Security-Critical Action
4
CWE-384Session Fixation
4
CWE-401Missing Release of Memory after Effective Lifetime
4
CWE-472External Control of Assumed-Immutable Web Parameter
4
CWE-50Path Equivalence: '//multiple/leading/slash'
4
CWE-626Null Byte Interaction Error (Poison Null Byte)
4
CWE-639Authorization Bypass Through User-Controlled Key
4
CWE-669Incorrect Resource Transfer Between Spheres
4
CWE-749Exposed Dangerous Method or Function
4
CWE-798Use of Hard-coded Credentials
4
CWE-807Reliance on Untrusted Inputs in a Security Decision
4
CWE-1287Improper Validation of Specified Type of Input
3
CWE-141Improper Neutralization of Parameter/Argument Delimiters
3
CWE-176Improper Handling of Unicode Encoding
3
CWE-187Partial String Comparison
3
CWE-312Cleartext Storage of Sensitive Information
3
CWE-325Missing Cryptographic Step
3
CWE-369Divide By Zero
3
CWE-3887PK - Errors
3
CWE-405Asymmetric Resource Consumption (Amplification)
3
CWE-440Expected Behavior Violation
3
CWE-506Embedded Malicious Code
3
CWE-522Insufficiently Protected Credentials
3
CWE-539Use of Persistent Cookies Containing Sensitive Information
3
CWE-703Improper Check or Handling of Exceptional Conditions
3
CWE-924Improper Enforcement of Message Integrity During Transmission in a Communication Channel
3
CWE-1240Use of a Cryptographic Primitive with a Risky Implementation
2
CWE-193Off-by-one Error
2
CWE-289Authentication Bypass by Alternate Name
2
CWE-300Channel Accessible by Non-Endpoint
2
CWE-320Key Management Errors
2
CWE-326Inadequate Encryption Strength
2
CWE-348Use of Less Trusted Source
2
CWE-532Insertion of Sensitive Information into Log File
2
CWE-552Files or Directories Accessible to External Parties
2
CWE-613Insufficient Session Expiration
2
CWE-617Reachable Assertion
2
CWE-662Improper Synchronization
2
CWE-681Incorrect Conversion between Numeric Types
2
CWE-693Protection Mechanism Failure
2
CWE-789Memory Allocation with Excessive Size Value
2
CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
2
CWE-909Missing Initialization of Resource
2
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
2
CWE-1077Floating Point Comparison with Incorrect Operator
1
CWE-1113Inappropriate Comment Style
1
CWE-115Misinterpretation of Input
1
CWE-124Buffer Underwrite ('Buffer Underflow')
1
CWE-1259Improper Restriction of Security Token Assignment
1
CWE-128Wrap-around Error
1
CWE-1325Improperly Controlled Sequential Memory Allocation
1
CWE-135Incorrect Calculation of Multi-Byte String Length
1
CWE-144Improper Neutralization of Line Delimiters
1
CWE-177Improper Handling of URL Encoding (Hex Encoding)
1
CWE-208Observable Timing Discrepancy
1
CWE-219Storage of File with Sensitive Data Under Web Root
1
CWE-24Path Traversal: '../filedir'
1
CWE-266Incorrect Privilege Assignment
1
CWE-269Improper Privilege Management
1
CWE-303Incorrect Implementation of Authentication Algorithm
1
CWE-311Missing Encryption of Sensitive Data
1
CWE-319Cleartext Transmission of Sensitive Information
1
CWE-323Reusing a Nonce, Key Pair in Encryption
1
CWE-329Generation of Predictable IV with CBC Mode
1
CWE-377Insecure Temporary File
1
CWE-378Creation of Temporary File With Insecure Permissions
1
CWE-385Covert Timing Channel
1
CWE-414Missing Lock Check
1
CWE-425Direct Request ('Forced Browsing')
1
CWE-426Untrusted Search Path
1
CWE-427Uncontrolled Search Path Element
1
CWE-457Use of Uninitialized Variable
1
CWE-459Incomplete Cleanup
1
CWE-460Improper Cleanup on Thrown Exception
1
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
1
CWE-514Covert Channel
1
CWE-599Missing Validation of OpenSSL Certificate
1
CWE-625Permissive Regular Expression
1
CWE-640Weak Password Recovery Mechanism for Forgotten Password
1
CWE-647Use of Non-Canonical URL Paths for Authorization Decisions
1
CWE-667Improper Locking
1
CWE-684Incorrect Provision of Specified Functionality
1
CWE-757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
1
CWE-786Access of Memory Location Before Start of Buffer
1
CWE-805Buffer Access with Incorrect Length Value
1
CWE-825Expired Pointer Dereference
1
CWE-86Improper Neutralization of Invalid Characters in Identifiers in Web Pages
1
CWE-912Hidden Functionality
1
CWE-922Insecure Storage of Sensitive Information
1
CWE-940Improper Verification of Source of a Communication Channel
1
CWE-942Permissive Cross-domain Security Policy with Untrusted Domains
1
A01:2021Broken Access Control
A02:2021Cryptographic Failures
A03:2021Injection
A04:2021Insecure Design
A05:2021Security Misconfiguration
A06:2021Vulnerable and Outdated Components
A07:2021Identification and Authentication Failures
A08:2021Software and Data Integrity Failures
A09:2021Security Logging and Monitoring Failures
A10:2021Server-Side Request Forgery (SSRF)
CWE-1DEPRECATED: Location
CWE-10DEPRECATED: ASP.NET Environment Issues
CWE-100DEPRECATED: Technology-Specific Input Validation Problems
CWE-1000Research Concepts
CWE-1001SFP Secondary Cluster: Use of an Improper API
CWE-1002SFP Secondary Cluster: Unexpected Entry Points
CWE-1003Weaknesses for Simplified Mapping of Published Vulnerabilities
CWE-1004Sensitive Cookie Without 'HttpOnly' Flag
CWE-10057PK - Input Validation and Representation
CWE-1006Bad Coding Practices
CWE-1007Insufficient Visual Distinction of Homoglyphs Presented to User
CWE-1008Architectural Concepts
CWE-1009Audit
CWE-101DEPRECATED: Struts Validation Problems
CWE-1010Authenticate Actors
CWE-1011Authorize Actors
CWE-1012Cross Cutting
CWE-1013Encrypt Data
CWE-1014Identify Actors
CWE-1015Limit Access
CWE-1016Limit Exposure
CWE-1017Lock Computer
CWE-1018Manage User Sessions
CWE-1019Validate Inputs
CWE-102Struts: Duplicate Validation Forms
CWE-1020Verify Message Integrity
CWE-1022Use of Web Link to Untrusted Target with window.opener Access
CWE-1023Incomplete Comparison with Missing Factors
CWE-1024Comparison of Incompatible Types
CWE-1025Comparison Using Wrong Factors
CWE-1026Weaknesses in OWASP Top Ten (2017)
CWE-1027OWASP Top Ten 2017 Category A1 - Injection
CWE-1028OWASP Top Ten 2017 Category A2 - Broken Authentication
CWE-1029OWASP Top Ten 2017 Category A3 - Sensitive Data Exposure
CWE-103Struts: Incomplete validate() Method Definition
CWE-1030OWASP Top Ten 2017 Category A4 - XML External Entities (XXE)
CWE-1031OWASP Top Ten 2017 Category A5 - Broken Access Control
CWE-1032OWASP Top Ten 2017 Category A6 - Security Misconfiguration
CWE-1033OWASP Top Ten 2017 Category A7 - Cross-Site Scripting (XSS)
CWE-1034OWASP Top Ten 2017 Category A8 - Insecure Deserialization
CWE-1035OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
CWE-1036OWASP Top Ten 2017 Category A10 - Insufficient Logging & Monitoring
CWE-1037Processor Optimization Removal or Modification of Security-critical Code
CWE-1038Insecure Automated Optimizations
CWE-1039Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism
CWE-104Struts: Form Bean Does Not Extend Validation Class
CWE-1040Quality Weaknesses with Indirect Security Impacts
CWE-1041Use of Redundant Code
CWE-1042Static Member Data Element outside of a Singleton Class Element
CWE-1043Data Element Aggregating an Excessively Large Number of Non-Primitive Elements
CWE-1044Architecture with Number of Horizontal Layers Outside of Expected Range
CWE-1045Parent Class with a Virtual Destructor and a Child Class without a Virtual Destructor
CWE-1046Creation of Immutable Text Using String Concatenation
CWE-1047Modules with Circular Dependencies
CWE-1048Invokable Control Element with Large Number of Outward Calls
CWE-1049Excessive Data Query Operations in a Large Data Table
CWE-105Struts: Form Field Without Validator
CWE-1051Initialization with Hard-Coded Network Resource Configuration Data
CWE-1052Excessive Use of Hard-Coded Literals in Initialization
CWE-1053Missing Documentation for Design
CWE-1054Invocation of a Control Element at an Unnecessarily Deep Horizontal Layer
CWE-1055Multiple Inheritance from Concrete Classes
CWE-1056Invokable Control Element with Variadic Parameters
CWE-1057Data Access Operations Outside of Expected Data Manager Component
CWE-1058Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element
CWE-1059Insufficient Technical Documentation
CWE-106Struts: Plug-in Framework not in Use
CWE-1060Excessive Number of Inefficient Server-Side Data Accesses
CWE-1061Insufficient Encapsulation
CWE-1062Parent Class with References to Child Class
CWE-1063Creation of Class Instance within a Static Code Block
CWE-1064Invokable Control Element with Signature Containing an Excessive Number of Parameters
CWE-1065Runtime Resource Management Control Element in a Component Built to Run on Application Servers
CWE-1066Missing Serialization Control Element
CWE-1067Excessive Execution of Sequential Searches of Data Resource
CWE-1068Inconsistency Between Implementation and Documented Design
CWE-1069Empty Exception Block
CWE-107Struts: Unused Validation Form
CWE-1070Serializable Data Element Containing non-Serializable Item Elements
CWE-1071Empty Code Block
CWE-1072Data Resource Access without Use of Connection Pooling
CWE-1073Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses
CWE-1074Class with Excessively Deep Inheritance
CWE-1075Unconditional Control Flow Transfer outside of Switch Block
CWE-1076Insufficient Adherence to Expected Conventions
CWE-1078Inappropriate Source Code Style or Formatting
CWE-1079Parent Class without Virtual Destructor Method
CWE-108Struts: Unvalidated Action Form
CWE-1080Source Code File with Excessive Number of Lines of Code
CWE-1081Entries with Maintenance Notes
CWE-1082Class Instance Self Destruction Control Element
CWE-1083Data Access from Outside Expected Data Manager Component
CWE-1084Invokable Control Element with Excessive File or Data Access Operations
CWE-1085Invokable Control Element with Excessive Volume of Commented-out Code
CWE-1086Class with Excessive Number of Child Classes
CWE-1087Class with Virtual Method without a Virtual Destructor
CWE-1088Synchronous Access of Remote Resource without Timeout
CWE-1089Large Data Table with Excessive Number of Indices
CWE-109Struts: Validator Turned Off
CWE-1090Method Containing Access of a Member Element from Another Class
CWE-1091Use of Object without Invoking Destructor Method
CWE-1092Use of Same Invokable Control Element in Multiple Architectural Layers
CWE-1093Excessively Complex Data Representation
CWE-1094Excessive Index Range Scan for a Data Resource
CWE-1095Loop Condition Value Update within the Loop
CWE-1096Singleton Class Instance Creation without Proper Locking or Synchronization
CWE-1097Persistent Storable Data Element without Associated Comparison Control Element
CWE-1098Data Element containing Pointer Item without Proper Copy Control Element
CWE-1099Inconsistent Naming Conventions for Identifiers
CWE-11ASP.NET Misconfiguration: Creating Debug Binary
CWE-110Struts: Validator Without Form Field
CWE-1100Insufficient Isolation of System-Dependent Functions
CWE-1101Reliance on Runtime Component in Generated Code
CWE-1102Reliance on Machine-Dependent Data Representation
CWE-1103Use of Platform-Dependent Third Party Components
CWE-1104Use of Unmaintained Third Party Components
CWE-1105Insufficient Encapsulation of Machine-Dependent Functionality
CWE-1106Insufficient Use of Symbolic Constants
CWE-1107Insufficient Isolation of Symbolic Constant Definitions
CWE-1108Excessive Reliance on Global Variables
CWE-1109Use of Same Variable for Multiple Purposes
CWE-111Direct Use of Unsafe JNI
CWE-1110Incomplete Design Documentation
CWE-1111Incomplete I/O Documentation
CWE-1112Incomplete Documentation of Program Execution
CWE-1114Inappropriate Whitespace Style
CWE-1115Source Code Element without Standard Prologue
CWE-1116Inaccurate Source Code Comments
CWE-1117Callable with Insufficient Behavioral Summary
CWE-1118Insufficient Documentation of Error Handling Techniques
CWE-1119Excessive Use of Unconditional Branching
CWE-112Missing XML Validation
CWE-1120Excessive Code Complexity
CWE-1121Excessive McCabe Cyclomatic Complexity
CWE-1122Excessive Halstead Complexity
CWE-1123Excessive Use of Self-Modifying Code
CWE-1124Excessively Deep Nesting
CWE-1125Excessive Attack Surface
CWE-1126Declaration of Variable with Unnecessarily Wide Scope
CWE-1127Compilation with Insufficient Warnings or Errors
CWE-1128CISQ Quality Measures (2016)
CWE-1129CISQ Quality Measures (2016) - Reliability
CWE-1130CISQ Quality Measures (2016) - Maintainability
CWE-1131CISQ Quality Measures (2016) - Security
CWE-1132CISQ Quality Measures (2016) - Performance Efficiency
CWE-1133Weaknesses Addressed by the SEI CERT Oracle Coding Standard for Java
CWE-1134SEI CERT Oracle Secure Coding Standard for Java - Guidelines 00. Input Validation and Data Sanitization (IDS)
CWE-1135SEI CERT Oracle Secure Coding Standard for Java - Guidelines 01. Declarations and Initialization (DCL)
CWE-1136SEI CERT Oracle Secure Coding Standard for Java - Guidelines 02. Expressions (EXP)
CWE-1137SEI CERT Oracle Secure Coding Standard for Java - Guidelines 03. Numeric Types and Operations (NUM)
CWE-1138SEI CERT Oracle Secure Coding Standard for Java - Guidelines 04. Characters and Strings (STR)
CWE-1139SEI CERT Oracle Secure Coding Standard for Java - Guidelines 05. Object Orientation (OBJ)
CWE-114Process Control
CWE-1140SEI CERT Oracle Secure Coding Standard for Java - Guidelines 06. Methods (MET)
CWE-1141SEI CERT Oracle Secure Coding Standard for Java - Guidelines 07. Exceptional Behavior (ERR)
CWE-1142SEI CERT Oracle Secure Coding Standard for Java - Guidelines 08. Visibility and Atomicity (VNA)
CWE-1143SEI CERT Oracle Secure Coding Standard for Java - Guidelines 09. Locking (LCK)
CWE-1144SEI CERT Oracle Secure Coding Standard for Java - Guidelines 10. Thread APIs (THI)
CWE-1145SEI CERT Oracle Secure Coding Standard for Java - Guidelines 11. Thread Pools (TPS)
CWE-1146SEI CERT Oracle Secure Coding Standard for Java - Guidelines 12. Thread-Safety Miscellaneous (TSM)
CWE-1147SEI CERT Oracle Secure Coding Standard for Java - Guidelines 13. Input Output (FIO)
CWE-1148SEI CERT Oracle Secure Coding Standard for Java - Guidelines 14. Serialization (SER)
CWE-1149SEI CERT Oracle Secure Coding Standard for Java - Guidelines 15. Platform Security (SEC)
CWE-1150SEI CERT Oracle Secure Coding Standard for Java - Guidelines 16. Runtime Environment (ENV)
CWE-1151SEI CERT Oracle Secure Coding Standard for Java - Guidelines 17. Java Native Interface (JNI)
CWE-1152SEI CERT Oracle Secure Coding Standard for Java - Guidelines 49. Miscellaneous (MSC)
CWE-1153SEI CERT Oracle Secure Coding Standard for Java - Guidelines 50. Android (DRD)
CWE-1154Weaknesses Addressed by the SEI CERT C Coding Standard
CWE-1155SEI CERT C Coding Standard - Guidelines 01. Preprocessor (PRE)
CWE-1156SEI CERT C Coding Standard - Guidelines 02. Declarations and Initialization (DCL)
CWE-1157SEI CERT C Coding Standard - Guidelines 03. Expressions (EXP)
CWE-1158SEI CERT C Coding Standard - Guidelines 04. Integers (INT)
CWE-1159SEI CERT C Coding Standard - Guidelines 05. Floating Point (FLP)
CWE-1160SEI CERT C Coding Standard - Guidelines 06. Arrays (ARR)
CWE-1161SEI CERT C Coding Standard - Guidelines 07. Characters and Strings (STR)
CWE-1162SEI CERT C Coding Standard - Guidelines 08. Memory Management (MEM)
CWE-1163SEI CERT C Coding Standard - Guidelines 09. Input Output (FIO)
CWE-1164Irrelevant Code
CWE-1165SEI CERT C Coding Standard - Guidelines 10. Environment (ENV)
CWE-1166SEI CERT C Coding Standard - Guidelines 11. Signals (SIG)
CWE-1167SEI CERT C Coding Standard - Guidelines 12. Error Handling (ERR)
CWE-1168SEI CERT C Coding Standard - Guidelines 13. Application Programming Interfaces (API)
CWE-1169SEI CERT C Coding Standard - Guidelines 14. Concurrency (CON)
CWE-117Improper Output Neutralization for Logs
CWE-1170SEI CERT C Coding Standard - Guidelines 48. Miscellaneous (MSC)
CWE-1171SEI CERT C Coding Standard - Guidelines 50. POSIX (POS)
CWE-1172SEI CERT C Coding Standard - Guidelines 51. Microsoft Windows (WIN)
CWE-1173Improper Use of Validation Framework
CWE-1174ASP.NET Misconfiguration: Improper Model Validation
CWE-1175SEI CERT Oracle Secure Coding Standard for Java - Guidelines 18. Concurrency (CON)
CWE-1176Inefficient CPU Computation
CWE-1177Use of Prohibited Code
CWE-1178Weaknesses Addressed by the SEI CERT Perl Coding Standard
CWE-1179SEI CERT Perl Coding Standard - Guidelines 01. Input Validation and Data Sanitization (IDS)
CWE-118Incorrect Access of Indexable Resource ('Range Error')
CWE-1180SEI CERT Perl Coding Standard - Guidelines 02. Declarations and Initialization (DCL)
CWE-1181SEI CERT Perl Coding Standard - Guidelines 03. Expressions (EXP)
CWE-1182SEI CERT Perl Coding Standard - Guidelines 04. Integers (INT)
CWE-1183SEI CERT Perl Coding Standard - Guidelines 05. Strings (STR)
CWE-1184SEI CERT Perl Coding Standard - Guidelines 06. Object-Oriented Programming (OOP)
CWE-1185SEI CERT Perl Coding Standard - Guidelines 07. File Input and Output (FIO)
CWE-1186SEI CERT Perl Coding Standard - Guidelines 50. Miscellaneous (MSC)
CWE-1187DEPRECATED: Use of Uninitialized Resource
CWE-1188Initialization of a Resource with an Insecure Default
CWE-1189Improper Isolation of Shared Resources on System-on-a-Chip (SoC)
CWE-1190DMA Device Enabled Too Early in Boot Phase
CWE-1191On-Chip Debug and Test Interface With Improper Access Control
CWE-1192Improper Identifier for IP Block used in System-On-Chip (SOC)
CWE-1193Power-On of Untrusted Execution Core Before Enabling Fabric Access Control
CWE-1194Hardware Design
CWE-1195Manufacturing and Life Cycle Management Concerns
CWE-1196Security Flow Issues
CWE-1197Integration Issues
CWE-1198Privilege Separation and Access Control Issues
CWE-1199General Circuit and Logic Design Concerns
CWE-12ASP.NET Misconfiguration: Missing Custom Error Page
CWE-1200Weaknesses in the 2019 CWE Top 25 Most Dangerous Software Errors
CWE-1201Core and Compute Issues
CWE-1202Memory and Storage Issues
CWE-1203Peripherals, On-chip Fabric, and Interface/IO Problems
CWE-1204Generation of Weak Initialization Vector (IV)
CWE-1205Security Primitives and Cryptography Issues
CWE-1206Power, Clock, Thermal, and Reset Concerns
CWE-1207Debug and Test Problems
CWE-1208Cross-Cutting Problems
CWE-1209Failure to Disable Reserved Bits
CWE-1210Audit / Logging Errors
CWE-1211Authentication Errors
CWE-1212Authorization Errors
CWE-1213Random Number Issues
CWE-1214Data Integrity Issues
CWE-1215Data Validation Issues
CWE-1216Lockout Mechanism Errors
CWE-1217User Session Errors
CWE-1218Memory Buffer Errors
CWE-1219File Handling Issues
CWE-1221Incorrect Register Defaults or Module Parameters
CWE-1222Insufficient Granularity of Address Regions Protected by Register Locks
CWE-1223Race Condition for Write-Once Attributes
CWE-1224Improper Restriction of Write-Once Bit Fields
CWE-1225Documentation Issues
CWE-1226Complexity Issues
CWE-1227Encapsulation Issues
CWE-1228API / Function Errors
CWE-1229Creation of Emergent Resource
CWE-123Write-what-where Condition
CWE-1230Exposure of Sensitive Information Through Metadata
CWE-1231Improper Prevention of Lock Bit Modification
CWE-1232Improper Lock Behavior After Power State Transition
CWE-1233Security-Sensitive Hardware Controls with Missing Lock Bit Protection
CWE-1234Hardware Internal or Debug Modes Allow Override of Locks
CWE-1235Incorrect Use of Autoboxing and Unboxing for Performance Critical Operations
CWE-1236Improper Neutralization of Formula Elements in a CSV File
CWE-1237SFP Primary Cluster: Faulty Resource Release
CWE-1238SFP Primary Cluster: Failure to Release Memory
CWE-1239Improper Zeroization of Hardware Register
CWE-1241Use of Predictable Algorithm in Random Number Generator
CWE-1242Inclusion of Undocumented Features or Chicken Bits
CWE-1243Sensitive Non-Volatile Information Not Protected During Debug
CWE-1244Internal Asset Exposed to Unsafe Debug Access Level or State
CWE-1245Improper Finite State Machines (FSMs) in Hardware Logic
CWE-1246Improper Write Handling in Limited-write Non-Volatile Memories
CWE-1247Improper Protection Against Voltage and Clock Glitches
CWE-1248Semiconductor Defects in Hardware Logic with Security-Sensitive Implications
CWE-1249Application-Level Admin Tool with Inconsistent View of Underlying Operating System
CWE-1250Improper Preservation of Consistency Between Independent Representations of Shared State
CWE-1251Mirrored Regions with Different Values
CWE-1252CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations
CWE-1253Incorrect Selection of Fuse Values
CWE-1254Incorrect Comparison Logic Granularity
CWE-1255Comparison Logic is Vulnerable to Power Side-Channel Attacks
CWE-1256Improper Restriction of Software Interfaces to Hardware Features
CWE-1257Improper Access Control Applied to Mirrored or Aliased Memory Regions
CWE-1258Exposure of Sensitive System Information Due to Uncleared Debug Information
CWE-1260Improper Handling of Overlap Between Protected Memory Ranges
CWE-1261Improper Handling of Single Event Upsets
CWE-1262Improper Access Control for Register Interface
CWE-1263Improper Physical Access Control
CWE-1264Hardware Logic with Insecure De-Synchronization between Control and Data Channels
CWE-1265Unintended Reentrant Invocation of Non-reentrant Code Via Nested Calls
CWE-1266Improper Scrubbing of Sensitive Data from Decommissioned Device
CWE-1267Policy Uses Obsolete Encoding
CWE-1268Policy Privileges are not Assigned Consistently Between Control and Data Agents
CWE-1269Product Released in Non-Release Configuration
CWE-127Buffer Under-read
CWE-1270Generation of Incorrect Security Tokens
CWE-1271Uninitialized Value on Reset for Registers Holding Security Settings
CWE-1272Sensitive Information Uncleared Before Debug/Power State Transition
CWE-1273Device Unlock Credential Sharing
CWE-1274Improper Access Control for Volatile Memory Containing Boot Code
CWE-1275Sensitive Cookie with Improper SameSite Attribute
CWE-1276Hardware Child Block Incorrectly Connected to Parent System
CWE-1277Firmware Not Updateable
CWE-1278Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques
CWE-1279Cryptographic Operations are run Before Supporting Units are Ready
CWE-1280Access Control Check Implemented After Asset is Accessed
CWE-1281Sequence of Processor Instructions Leads to Unexpected Behavior
CWE-1282Assumed-Immutable Data is Stored in Writable Memory
CWE-1283Mutable Attestation or Measurement Reporting Data
CWE-1285Improper Validation of Specified Index, Position, or Offset in Input
CWE-1288Improper Validation of Consistency within Input
CWE-1290Incorrect Decoding of Security Identifiers
CWE-1291Public Key Re-Use for Signing both Debug and Production Code
CWE-1292Incorrect Conversion of Security Identifiers
CWE-1293Missing Source Correlation of Multiple Independent Data
CWE-1294Insecure Security Identifier Mechanism
CWE-1295Debug Messages Revealing Unnecessary Information
CWE-1296Incorrect Chaining or Granularity of Debug Components
CWE-1297Unprotected Confidential Information on Device is Accessible by OSAT Vendors
CWE-1298Hardware Logic Contains Race Conditions
CWE-1299Missing Protection Mechanism for Alternate Hardware Interface
CWE-13ASP.NET Misconfiguration: Password in Configuration File
CWE-1300Improper Protection of Physical Side Channels
CWE-1301Insufficient or Incomplete Data Removal within Hardware Component
CWE-1302Missing Source Identifier in Entity Transactions on a System-On-Chip (SOC)
CWE-1303Non-Transparent Sharing of Microarchitectural Resources
CWE-1304Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation
CWE-1305CISQ Quality Measures (2020)
CWE-1306CISQ Quality Measures - Reliability
CWE-1307CISQ Quality Measures - Maintainability
CWE-1308CISQ Quality Measures - Security
CWE-1309CISQ Quality Measures - Efficiency
CWE-1310Missing Ability to Patch ROM Code
CWE-1311Improper Translation of Security Attributes by Fabric Bridge
CWE-1312Missing Protection for Mirrored Regions in On-Chip Fabric Firewall
CWE-1313Hardware Allows Activation of Test or Debug Logic at Runtime
CWE-1314Missing Write Protection for Parametric Data Values
CWE-1315Improper Setting of Bus Controlling Capability in Fabric End-point
CWE-1316Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges
CWE-1317Improper Access Control in Fabric Bridge
CWE-1318Missing Support for Security Features in On-chip Fabrics or Buses
CWE-1319Improper Protection against Electromagnetic Fault Injection (EM-FI)
CWE-132DEPRECATED: Miscalculated Null Termination
CWE-1320Improper Protection for Outbound Error Messages and Alert Signals
CWE-1322Use of Blocking Code in Single-threaded, Non-blocking Context
CWE-1323Improper Management of Sensitive Trace Data
CWE-1324DEPRECATED: Sensitive Information Accessible by Physical Probing of JTAG Interface
CWE-1326Missing Immutable Root of Trust in Hardware
CWE-1327Binding to an Unrestricted IP Address
CWE-1328Security Version Number Mutable to Older Versions
CWE-1329Reliance on Component That is Not Updateable
CWE-133String Errors
CWE-1330Remanent Data Readable after Memory Erase
CWE-1331Improper Isolation of Shared Resources in Network On Chip (NoC)
CWE-1332Improper Handling of Faults that Lead to Instruction Skips
CWE-1334Unauthorized Error Injection Can Degrade Hardware Redundancy
CWE-1335Incorrect Bitwise Shift of Integer
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
CWE-1337Weaknesses in the 2021 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1338Improper Protections Against Hardware Overheating
CWE-1339Insufficient Precision or Accuracy of a Real Number
CWE-1340CISQ Data Protection Measures
CWE-1341Multiple Releases of Same Resource or Handle
CWE-1342Information Exposure through Microarchitectural State after Transient Execution
CWE-1343Weaknesses in the 2021 CWE Most Important Hardware Weaknesses List
CWE-1344Weaknesses in OWASP Top Ten (2021)
CWE-1345OWASP Top Ten 2021 Category A01:2021 - Broken Access Control
CWE-1346OWASP Top Ten 2021 Category A02:2021 - Cryptographic Failures
CWE-1347OWASP Top Ten 2021 Category A03:2021 - Injection
CWE-1348OWASP Top Ten 2021 Category A04:2021 - Insecure Design
CWE-1349OWASP Top Ten 2021 Category A05:2021 - Security Misconfiguration
CWE-1350Weaknesses in the 2020 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1351Improper Handling of Hardware Behavior in Exceptionally Cold Environments
CWE-1352OWASP Top Ten 2021 Category A06:2021 - Vulnerable and Outdated Components
CWE-1353OWASP Top Ten 2021 Category A07:2021 - Identification and Authentication Failures
CWE-1354OWASP Top Ten 2021 Category A08:2021 - Software and Data Integrity Failures
CWE-1355OWASP Top Ten 2021 Category A09:2021 - Security Logging and Monitoring Failures
CWE-1356OWASP Top Ten 2021 Category A10:2021 - Server-Side Request Forgery (SSRF)
CWE-1357Reliance on Insufficiently Trustworthy Component
CWE-1358Weaknesses in SEI ETF Categories of Security Vulnerabilities in ICS
CWE-1359ICS Communications
CWE-136Type Errors
CWE-1360ICS Dependencies (& Architecture)
CWE-1361ICS Supply Chain
CWE-1362ICS Engineering (Constructions/Deployment)
CWE-1363ICS Operations (& Maintenance)
CWE-1364ICS Communications: Zone Boundary Failures
CWE-1365ICS Communications: Unreliability
CWE-1366ICS Communications: Frail Security in Protocols
CWE-1367ICS Dependencies (& Architecture): External Physical Systems
CWE-1368ICS Dependencies (& Architecture): External Digital Systems
CWE-1369ICS Supply Chain: IT/OT Convergence/Expansion
CWE-137Data Neutralization Issues
CWE-1370ICS Supply Chain: Common Mode Frailties
CWE-1371ICS Supply Chain: Poorly Documented or Undocumented Features
CWE-1372ICS Supply Chain: OT Counterfeit and Malicious Corruption
CWE-1373ICS Engineering (Construction/Deployment): Trust Model Problems
CWE-1374ICS Engineering (Construction/Deployment): Maker Breaker Blindness
CWE-1375ICS Engineering (Construction/Deployment): Gaps in Details/Data
CWE-1376ICS Engineering (Construction/Deployment): Security Gaps in Commissioning
CWE-1377ICS Engineering (Construction/Deployment): Inherent Predictability in Design
CWE-1378ICS Operations (& Maintenance): Gaps in obligations and training
CWE-1379ICS Operations (& Maintenance): Human factors in ICS environments
CWE-138Improper Neutralization of Special Elements
CWE-1380ICS Operations (& Maintenance): Post-analysis changes
CWE-1381ICS Operations (& Maintenance): Exploitable Standard Operational Procedures
CWE-1382ICS Operations (& Maintenance): Emerging Energy Technologies
CWE-1383ICS Operations (& Maintenance): Compliance/Conformance with Regulatory Requirements
CWE-1384Improper Handling of Physical or Environmental Conditions
CWE-1386Insecure Operation on Windows Junction / Mount Point
CWE-1387Weaknesses in the 2022 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1388Physical Access Issues and Concerns
CWE-1389Incorrect Parsing of Numbers with Different Radices
CWE-139DEPRECATED: General Special Element Problems
CWE-1390Weak Authentication
CWE-1391Use of Weak Credentials
CWE-1392Use of Default Credentials
CWE-1393Use of Default Password
CWE-1394Use of Default Cryptographic Key
CWE-1395Dependency on Vulnerable Third-Party Component
CWE-1396Comprehensive Categorization: Access Control
CWE-1397Comprehensive Categorization: Comparison
CWE-1398Comprehensive Categorization: Component Interaction
CWE-1399Comprehensive Categorization: Memory Safety
CWE-14Compiler Removal of Code to Clear Buffers
CWE-1400Comprehensive Categorization for Software Assurance Trends
CWE-1401Comprehensive Categorization: Concurrency
CWE-1402Comprehensive Categorization: Encryption
CWE-1403Comprehensive Categorization: Exposed Resource
CWE-1404Comprehensive Categorization: File Handling
CWE-1405Comprehensive Categorization: Improper Check or Handling of Exceptional Conditions
CWE-1406Comprehensive Categorization: Improper Input Validation
CWE-1407Comprehensive Categorization: Improper Neutralization
CWE-1408Comprehensive Categorization: Incorrect Calculation
CWE-1409Comprehensive Categorization: Injection
CWE-1410Comprehensive Categorization: Insufficient Control Flow Management
CWE-1411Comprehensive Categorization: Insufficient Verification of Data Authenticity
CWE-1412Comprehensive Categorization: Poor Coding Practices
CWE-1413Comprehensive Categorization: Protection Mechanism Failure
CWE-1414Comprehensive Categorization: Randomness
CWE-1415Comprehensive Categorization: Resource Control
CWE-1416Comprehensive Categorization: Resource Lifecycle Management
CWE-1417Comprehensive Categorization: Sensitive Information Exposure
CWE-1418Comprehensive Categorization: Violation of Secure Design Principles
CWE-1419Incorrect Initialization of Resource
CWE-142Improper Neutralization of Value Delimiters
CWE-1420Exposure of Sensitive Information during Transient Execution
CWE-1421Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
CWE-1422Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution
CWE-1423Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution
CWE-1424Weaknesses Addressed by ISA/IEC 62443 Requirements
CWE-1425Weaknesses in the 2023 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1426Improper Validation of Generative AI Output
CWE-1427Improper Neutralization of Input Used for LLM Prompting
CWE-1428Reliance on HTTP instead of HTTPS
CWE-1429Missing Security-Relevant Feedback for Unexecuted Operations in Hardware Interface
CWE-143Improper Neutralization of Record Delimiters
CWE-1430Weaknesses in the 2024 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1431Driving Intermediate Cryptographic State/Results to Hardware Module Outputs
CWE-1432Weaknesses in the 2025 CWE Most Important Hardware Weaknesses List
CWE-14332025 MIHW Supplement: Expert Insights
CWE-1434Insecure Setting of Generative AI/ML Model Inference Parameters
CWE-1435Weaknesses in the 2025 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1436OWASP Top Ten 2025 Category A01:2025 - Broken Access Control
CWE-1437OWASP Top Ten 2025 Category A02:2025 - Security Misconfiguration
CWE-1438OWASP Top Ten 2025 Category A03:2025 - Software Supply Chain Failures
CWE-1439OWASP Top Ten 2025 Category A04:2025 - Cryptographic Failures
CWE-1440OWASP Top Ten 2025 Category A05:2025 - Injection
CWE-1441OWASP Top Ten 2025 Category A06:2025 - Insecure Design
CWE-1442OWASP Top Ten 2025 Category A07:2025 - Authentication Failures
CWE-1443OWASP Top Ten 2025 Category A08:2025 - Software or Data Integrity Failures
CWE-1444OWASP Top Ten 2025 Category A09:2025 - Logging & Alerting Failures
CWE-1445OWASP Top Ten 2025 Category A10:2025 - Mishandling of Exceptional Conditions
CWE-1446Weaknesses That are Specific to AI/ML Technology
CWE-1447General Software Weaknesses that Appear in Products that Use or Support AI/ML Technology
CWE-1448Weaknesses Related to AI/ML Products
CWE-145Improper Neutralization of Section Delimiters
CWE-1450Weaknesses in OWASP Top Ten RC1 (2025)
CWE-146Improper Neutralization of Expression/Command Delimiters
CWE-147Improper Neutralization of Input Terminators
CWE-148Improper Neutralization of Input Leaders
CWE-149Improper Neutralization of Quoting Syntax
CWE-15External Control of System or Configuration Setting
CWE-151Improper Neutralization of Comment Delimiters
CWE-152Improper Neutralization of Macro Symbols
CWE-153Improper Neutralization of Substitution Characters
CWE-154Improper Neutralization of Variable Name Delimiters
CWE-155Improper Neutralization of Wildcards or Matching Symbols
CWE-156Improper Neutralization of Whitespace
CWE-157Failure to Sanitize Paired Delimiters
CWE-158Improper Neutralization of Null Byte or NUL Character
CWE-159Improper Handling of Invalid Use of Special Elements
CWE-16Configuration
CWE-160Improper Neutralization of Leading Special Elements
CWE-161Improper Neutralization of Multiple Leading Special Elements
CWE-162Improper Neutralization of Trailing Special Elements
CWE-163Improper Neutralization of Multiple Trailing Special Elements
CWE-164Improper Neutralization of Internal Special Elements
CWE-165Improper Neutralization of Multiple Internal Special Elements
CWE-166Improper Handling of Missing Special Element
CWE-167Improper Handling of Additional Special Element
CWE-168Improper Handling of Inconsistent Special Elements
CWE-169DEPRECATED: Technology-Specific Special Elements
CWE-170Improper Null Termination
CWE-171DEPRECATED: Cleansing, Canonicalization, and Comparison Errors
CWE-172Encoding Error
CWE-173Improper Handling of Alternate Encoding
CWE-174Double Decoding of the Same Data
CWE-175Improper Handling of Mixed Encoding
CWE-179Incorrect Behavior Order: Early Validation
CWE-18DEPRECATED: Source Code
CWE-181Incorrect Behavior Order: Validate Before Filter
CWE-182Collapse of Data into Unsafe Value
CWE-186Overly Restrictive Regular Expression
CWE-188Reliance on Data/Memory Layout
CWE-19Data Processing Errors
CWE-192Integer Coercion Error
CWE-194Unexpected Sign Extension
CWE-195Signed to Unsigned Conversion Error
CWE-196Unsigned to Signed Conversion Error
CWE-197Numeric Truncation Error
CWE-198Use of Incorrect Byte Ordering
CWE-199Information Management Errors
CWE-27PK - Environment
CWE-2000Comprehensive CWE Dictionary
CWE-202Exposure of Sensitive Information Through Data Queries
CWE-204Observable Response Discrepancy
CWE-205Observable Behavioral Discrepancy
CWE-206Observable Internal Behavioral Discrepancy
CWE-207Observable Behavioral Discrepancy With Equivalent Products
CWE-209Generation of Error Message Containing Sensitive Information
CWE-21DEPRECATED: Pathname Traversal and Equivalence Errors
CWE-210Self-generated Error Message Containing Sensitive Information
CWE-211Externally-Generated Error Message Containing Sensitive Information
CWE-213Exposure of Sensitive Information Due to Incompatible Policies
CWE-214Invocation of Process Using Visible Sensitive Information
CWE-215Insertion of Sensitive Information Into Debugging Code
CWE-216DEPRECATED: Containment Errors (Container Errors)
CWE-217DEPRECATED: Failure to Protect Stored Data from Modification
CWE-218DEPRECATED: Failure to provide confidentiality for stored data
CWE-220Storage of File With Sensitive Data Under FTP Root
CWE-221Information Loss or Omission
CWE-222Truncation of Security-relevant Information
CWE-223Omission of Security-relevant Information
CWE-224Obscured Security-relevant Information by Alternate Name
CWE-225DEPRECATED: General Information Management Problems
CWE-226Sensitive Information in Resource Not Removed Before Reuse
CWE-2277PK - API Abuse
CWE-228Improper Handling of Syntactically Invalid Structure
CWE-229Improper Handling of Values
CWE-230Improper Handling of Missing Values
CWE-231Improper Handling of Extra Values
CWE-232Improper Handling of Undefined Values
CWE-233Improper Handling of Parameters
CWE-234Failure to Handle Missing Parameter
CWE-235Improper Handling of Extra Parameters
CWE-236Improper Handling of Undefined Parameters
CWE-237Improper Handling of Structural Elements
CWE-238Improper Handling of Incomplete Structural Elements
CWE-239Failure to Handle Incomplete Element
CWE-240Improper Handling of Inconsistent Structural Elements
CWE-241Improper Handling of Unexpected Data Type
CWE-242Use of Inherently Dangerous Function
CWE-243Creation of chroot Jail Without Changing Working Directory
CWE-244Improper Clearing of Heap Memory Before Release ('Heap Inspection')
CWE-245J2EE Bad Practices: Direct Management of Connections
CWE-246J2EE Bad Practices: Direct Use of Sockets
CWE-247DEPRECATED: Reliance on DNS Lookups in a Security Decision
CWE-249DEPRECATED: Often Misused: Path Manipulation
CWE-25Path Traversal: '/../filedir'
CWE-250Execution with Unnecessary Privileges
CWE-251Often Misused: String Management
CWE-252Unchecked Return Value
CWE-253Incorrect Check of Function Return Value
CWE-255Credentials Management Errors
CWE-256Plaintext Storage of a Password
CWE-257Storing Passwords in a Recoverable Format
CWE-258Empty Password in Configuration File
CWE-259Use of Hard-coded Password
CWE-26Path Traversal: '/dir/../filename'
CWE-260Password in Configuration File
CWE-261Weak Encoding for Password
CWE-262Not Using Password Aging
CWE-263Password Aging with Long Expiration
CWE-265Privilege Issues
CWE-267Privilege Defined With Unsafe Actions
CWE-268Privilege Chaining
CWE-27Path Traversal: 'dir/../../filename'
CWE-270Privilege Context Switching Error
CWE-271Privilege Dropping / Lowering Errors
CWE-272Least Privilege Violation
CWE-273Improper Check for Dropped Privileges
CWE-274Improper Handling of Insufficient Privileges
CWE-275Permission Issues
CWE-277Insecure Inherited Permissions
CWE-278Insecure Preserved Inherited Permissions
CWE-279Incorrect Execution-Assigned Permissions
CWE-28Path Traversal: '..filedir'
CWE-280Improper Handling of Insufficient Permissions or Privileges
CWE-282Improper Ownership Management
CWE-283Unverified Ownership
CWE-286Incorrect User Management
CWE-288Authentication Bypass Using an Alternate Path or Channel
CWE-29Path Traversal: '..filename'
CWE-291Reliance on IP Address for Authentication
CWE-292DEPRECATED: Trusting Self-reported DNS Name
CWE-293Using Referer Field for Authentication
CWE-294Authentication Bypass by Capture-replay
CWE-296Improper Following of a Certificate's Chain of Trust
CWE-297Improper Validation of Certificate with Host Mismatch
CWE-298Improper Validation of Certificate Expiration
CWE-299Improper Check for Certificate Revocation
CWE-3DEPRECATED: Technology-specific Environment Issues
CWE-30Path Traversal: 'dir..filename'
CWE-301Reflection Attack in an Authentication Protocol
CWE-302Authentication Bypass by Assumed-Immutable Data
CWE-304Missing Critical Step in Authentication
CWE-305Authentication Bypass by Primary Weakness
CWE-307Improper Restriction of Excessive Authentication Attempts
CWE-308Use of Single-factor Authentication
CWE-309Use of Password System for Primary Authentication
CWE-31Path Traversal: 'dir....filename'
CWE-313Cleartext Storage in a File or on Disk
CWE-314Cleartext Storage in the Registry
CWE-315Cleartext Storage of Sensitive Information in a Cookie
CWE-316Cleartext Storage of Sensitive Information in Memory
CWE-317Cleartext Storage of Sensitive Information in GUI
CWE-318Cleartext Storage of Sensitive Information in Executable
CWE-32Path Traversal: '...' (Triple Dot)
CWE-321Use of Hard-coded Cryptographic Key
CWE-322Key Exchange without Entity Authentication
CWE-324Use of a Key Past its Expiration Date
CWE-328Use of Weak Hash
CWE-33Path Traversal: '....' (Multiple Dot)
CWE-332Insufficient Entropy in PRNG
CWE-333Improper Handling of Insufficient Entropy in TRNG
CWE-334Small Space of Random Values
CWE-335Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
CWE-336Same Seed in Pseudo-Random Number Generator (PRNG)
CWE-337Predictable Seed in Pseudo-Random Number Generator (PRNG)
CWE-339Small Seed Space in PRNG
CWE-34Path Traversal: '....//'
CWE-340Generation of Predictable Numbers or Identifiers
CWE-341Predictable from Observable State
CWE-342Predictable Exact Value from Previous Values
CWE-343Predictable Value Range from Previous Values
CWE-344Use of Invariant Value in Dynamically Changing Context
CWE-349Acceptance of Extraneous Untrusted Data With Trusted Data
CWE-35Path Traversal: '.../...//'
CWE-351Insufficient Type Distinction
CWE-353Missing Support for Integrity Check
CWE-355User Interface Security Issues
CWE-356Product UI does not Warn User of Unsafe Actions
CWE-357Insufficient UI Warning of Dangerous Operations
CWE-358Improperly Implemented Security Check for Standard
CWE-36Absolute Path Traversal
CWE-360Trust of System Event Data
CWE-3617PK - Time and State
CWE-363Race Condition Enabling Link Following
CWE-364Signal Handler Race Condition
CWE-365DEPRECATED: Race Condition in Switch
CWE-366Race Condition within a Thread
CWE-368Context Switching Race Condition
CWE-37Path Traversal: '/absolute/pathname/here'
CWE-370Missing Check for Certificate Revocation after Initial Check
CWE-371State Issues
CWE-372Incomplete Internal State Distinction
CWE-373DEPRECATED: State Synchronization Error
CWE-374Passing Mutable Objects to an Untrusted Method
CWE-375Returning a Mutable Object to an Untrusted Caller
CWE-376DEPRECATED: Temporary File Issues
CWE-379Creation of Temporary File in Directory with Insecure Permissions
CWE-38Path Traversal: 'absolutepathnamehere'
CWE-380DEPRECATED: Technology-Specific Time and State Issues
CWE-381DEPRECATED: J2EE Time and State Issues
CWE-382J2EE Bad Practices: Use of System.exit()
CWE-383J2EE Bad Practices: Direct Use of Threads
CWE-386Symbolic Name not Mapping to Correct Object
CWE-387Signal Errors
CWE-389Error Conditions, Return Values, Status Codes
CWE-39Path Traversal: 'C:dirname'
CWE-390Detection of Error Condition Without Action
CWE-391Unchecked Error Condition
CWE-392Missing Report of Error Condition
CWE-393Return of Wrong Status Code
CWE-394Unexpected Status Code or Return Value
CWE-395Use of NullPointerException Catch to Detect NULL Pointer Dereference
CWE-396Declaration of Catch for Generic Exception
CWE-397Declaration of Throws for Generic Exception
CWE-3987PK - Code Quality
CWE-4DEPRECATED: J2EE Environment Issues
CWE-40Path Traversal: 'UNCsharename' (Windows UNC Share)
CWE-402Transmission of Private Resources into a New Sphere ('Resource Leak')
CWE-403Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')
CWE-404Improper Resource Shutdown or Release
CWE-406Insufficient Control of Network Message Volume (Network Amplification)
CWE-408Incorrect Behavior Order: Early Amplification
CWE-41Improper Resolution of Path Equivalence
CWE-410Insufficient Resource Pool
CWE-411Resource Locking Problems
CWE-412Unrestricted Externally Accessible Lock
CWE-413Improper Resource Locking
CWE-417Communication Channel Errors
CWE-418DEPRECATED: Channel Errors
CWE-419Unprotected Primary Channel
CWE-42Path Equivalence: 'filename.' (Trailing Dot)
CWE-420Unprotected Alternate Channel
CWE-421Race Condition During Access to Alternate Channel
CWE-422Unprotected Windows Messaging Channel ('Shatter')
CWE-423DEPRECATED: Proxied Trusted Channel
CWE-424Improper Protection of Alternate Path
CWE-428Unquoted Search Path or Element
CWE-429Handler Errors
CWE-43Path Equivalence: 'filename....' (Multiple Trailing Dot)
CWE-430Deployment of Wrong Handler
CWE-431Missing Handler
CWE-432Dangerous Signal Handler not Disabled During Sensitive Operations
CWE-433Unparsed Raw Web Content Delivery
CWE-435Improper Interaction Between Multiple Correctly-Behaving Entities
CWE-437Incomplete Model of Endpoint Features
CWE-438Behavioral Problems
CWE-439Behavioral Change in New Version or Environment
CWE-44Path Equivalence: 'file.name' (Internal Dot)
CWE-442DEPRECATED: Web Problems
CWE-443DEPRECATED: HTTP response splitting
CWE-445DEPRECATED: User Interface Errors
CWE-446UI Discrepancy for Security Feature
CWE-447Unimplemented or Unsupported Feature in UI
CWE-448Obsolete Feature in UI
CWE-449The UI Performs the Wrong Action
CWE-45Path Equivalence: 'file...name' (Multiple Internal Dot)
CWE-450Multiple Interpretations of UI Input
CWE-451User Interface (UI) Misrepresentation of Critical Information
CWE-452Initialization and Cleanup Errors
CWE-453Insecure Default Variable Initialization
CWE-454External Initialization of Trusted Variables or Data Stores
CWE-455Non-exit on Failed Initialization
CWE-456Missing Initialization of a Variable
CWE-458DEPRECATED: Incorrect Initialization
CWE-46Path Equivalence: 'filename ' (Trailing Space)
CWE-461DEPRECATED: Data Structure Issues
CWE-462Duplicate Key in Associative List (Alist)
CWE-463Deletion of Data Structure Sentinel
CWE-464Addition of Data Structure Sentinel
CWE-465Pointer Issues
CWE-466Return of Pointer Value Outside of Expected Range
CWE-467Use of sizeof() on a Pointer Type
CWE-468Incorrect Pointer Scaling
CWE-469Use of Pointer Subtraction to Determine Size
CWE-47Path Equivalence: ' filename' (Leading Space)
CWE-473PHP External Variable Modification
CWE-474Use of Function with Inconsistent Implementations
CWE-475Undefined Behavior for Input to API
CWE-477Use of Obsolete Function
CWE-478Missing Default Case in Multiple Condition Expression
CWE-479Signal Handler Use of a Non-reentrant Function
CWE-48Path Equivalence: 'file name' (Internal Whitespace)
CWE-480Use of Incorrect Operator
CWE-481Assigning instead of Comparing
CWE-482Comparing instead of Assigning
CWE-483Incorrect Block Delimitation
CWE-484Omitted Break Statement in Switch
CWE-4857PK - Encapsulation
CWE-486Comparison of Classes by Name
CWE-487Reliance on Package-level Scope
CWE-488Exposure of Data Element to Wrong Session
CWE-489Active Debug Code
CWE-49Path Equivalence: 'filename/' (Trailing Slash)
CWE-490DEPRECATED: Mobile Code Issues
CWE-491Public cloneable() Method Without Final ('Object Hijack')
CWE-492Use of Inner Class Containing Sensitive Data
CWE-493Critical Public Variable Without Final Modifier
CWE-495Private Data Structure Returned From A Public Method
CWE-496Public Data Assigned to Private Array-Typed Field
CWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere
CWE-498Cloneable Class Containing Sensitive Information
CWE-499Serializable Class Containing Sensitive Data
CWE-5J2EE Misconfiguration: Data Transmission Without Encryption
CWE-500Public Static Field Not Marked Final
CWE-501Trust Boundary Violation
CWE-503DEPRECATED: Byte/Object Code
CWE-504DEPRECATED: Motivation/Intent
CWE-505DEPRECATED: Intentionally Introduced Weakness
CWE-507Trojan Horse
CWE-508Non-Replicating Malicious Code
CWE-509Replicating Malicious Code (Virus or Worm)
CWE-51Path Equivalence: '/multiple//internal/slash'
CWE-510Trapdoor
CWE-511Logic/Time Bomb
CWE-512Spyware
CWE-513DEPRECATED: Intentionally Introduced Nonmalicious Weakness
CWE-515Covert Storage Channel
CWE-516DEPRECATED: Covert Timing Channel
CWE-517DEPRECATED: Other Intentional, Nonmalicious Weakness
CWE-518DEPRECATED: Inadvertently Introduced Weakness
CWE-519DEPRECATED: .NET Environment Issues
CWE-52Path Equivalence: '/multiple/trailing/slash//'
CWE-520.NET Misconfiguration: Use of Impersonation
CWE-521Weak Password Requirements
CWE-523Unprotected Transport of Credentials
CWE-525Use of Web Browser Cache Containing Sensitive Information
CWE-526Cleartext Storage of Sensitive Information in an Environment Variable
CWE-527Exposure of Version-Control Repository to an Unauthorized Control Sphere
CWE-528Exposure of Core Dump File to an Unauthorized Control Sphere
CWE-529Exposure of Access Control List Files to an Unauthorized Control Sphere
CWE-53Path Equivalence: 'multipleinternalbackslash'
CWE-530Exposure of Backup File to an Unauthorized Control Sphere
CWE-531Inclusion of Sensitive Information in Test Code
CWE-533DEPRECATED: Information Exposure Through Server Log Files
CWE-534DEPRECATED: Information Exposure Through Debug Log Files
CWE-535Exposure of Information Through Shell Error Message
CWE-536Servlet Runtime Error Message Containing Sensitive Information
CWE-537Java Runtime Error Message Containing Sensitive Information
CWE-538Insertion of Sensitive Information into Externally-Accessible File or Directory
CWE-54Path Equivalence: 'filedir' (Trailing Backslash)
CWE-540Inclusion of Sensitive Information in Source Code
CWE-541Inclusion of Sensitive Information in an Include File
CWE-542DEPRECATED: Information Exposure Through Cleanup Log Files
CWE-543Use of Singleton Pattern Without Synchronization in a Multithreaded Context
CWE-544Missing Standardized Error Handling Mechanism
CWE-545DEPRECATED: Use of Dynamic Class Loading
CWE-546Suspicious Comment
CWE-547Use of Hard-coded, Security-relevant Constants
CWE-548Exposure of Information Through Directory Listing
CWE-549Missing Password Field Masking
CWE-55Path Equivalence: '/./' (Single Dot Directory)
CWE-550Server-generated Error Message Containing Sensitive Information
CWE-553Command Shell in Externally Accessible Directory
CWE-554ASP.NET Misconfiguration: Not Using Input Validation Framework
CWE-555J2EE Misconfiguration: Plaintext Password in Configuration File
CWE-556ASP.NET Misconfiguration: Use of Identity Impersonation
CWE-557Concurrency Issues
CWE-558Use of getlogin() in Multithreaded Application
CWE-559DEPRECATED: Often Misused: Arguments and Parameters
CWE-56Path Equivalence: 'filedir*' (Wildcard)
CWE-560Use of umask() with chmod-style Argument
CWE-561Dead Code
CWE-562Return of Stack Variable Address
CWE-563Assignment to Variable without Use
CWE-564SQL Injection: Hibernate
CWE-565Reliance on Cookies without Validation and Integrity Checking
CWE-566Authorization Bypass Through User-Controlled SQL Primary Key
CWE-567Unsynchronized Access to Shared Data in a Multithreaded Context
CWE-568finalize() Method Without super.finalize()
CWE-569Expression Issues
CWE-57Path Equivalence: 'fakedir/../realdir/filename'
CWE-570Expression is Always False
CWE-571Expression is Always True
CWE-572Call to Thread run() instead of start()
CWE-573Improper Following of Specification by Caller
CWE-574EJB Bad Practices: Use of Synchronization Primitives
CWE-575EJB Bad Practices: Use of AWT Swing
CWE-576EJB Bad Practices: Use of Java I/O
CWE-577EJB Bad Practices: Use of Sockets
CWE-578EJB Bad Practices: Use of Class Loader
CWE-579J2EE Bad Practices: Non-serializable Object Stored in Session
CWE-58Path Equivalence: Windows 8.3 Filename
CWE-580clone() Method Without super.clone()
CWE-581Object Model Violation: Just One of Equals and Hashcode Defined
CWE-582Array Declared Public, Final, and Static
CWE-583finalize() Method Declared Public
CWE-584Return Inside Finally Block
CWE-585Empty Synchronized Block
CWE-586Explicit Call to Finalize()
CWE-587Assignment of a Fixed Address to a Pointer
CWE-588Attempt to Access Child of a Non-structure Pointer
CWE-589Call to Non-ubiquitous API
CWE-590Free of Memory not on the Heap
CWE-591Sensitive Data Storage in Improperly Locked Memory
CWE-592DEPRECATED: Authentication Bypass Issues
CWE-593Authentication Bypass: OpenSSL CTX Object Modified after SSL Objects are Created
CWE-594J2EE Framework: Saving Unserializable Objects to Disk
CWE-595Comparison of Object References Instead of Object Contents
CWE-596DEPRECATED: Incorrect Semantic Object Comparison
CWE-597Use of Wrong Operator in String Comparison
CWE-598Use of HTTP Request With Sensitive Query String
CWE-6J2EE Misconfiguration: Insufficient Session-ID Length
CWE-60DEPRECATED: UNIX Path Link Problems
CWE-600Uncaught Exception in Servlet
CWE-602Client-Side Enforcement of Server-Side Security
CWE-603Use of Client-Side Authentication
CWE-604Deprecated Entries
CWE-605Multiple Binds to the Same Port
CWE-607Public Static Final Field References Mutable Object
CWE-608Struts: Non-private Field in ActionForm Class
CWE-609Double-Checked Locking
CWE-610Externally Controlled Reference to a Resource in Another Sphere
CWE-612Improper Authorization of Index Containing Sensitive Information
CWE-614Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CWE-615Inclusion of Sensitive Information in Source Code Comments
CWE-616Incomplete Identification of Uploaded File Variables (PHP)
CWE-618Exposed Unsafe ActiveX Method
CWE-619Dangling Database Cursor ('Cursor Injection')
CWE-62UNIX Hard Link
CWE-620Unverified Password Change
CWE-621Variable Extraction Error
CWE-622Improper Validation of Function Hook Arguments
CWE-623Unsafe ActiveX Control Marked Safe For Scripting
CWE-624Executable Regular Expression Error
CWE-627Dynamic Variable Evaluation
CWE-628Function Call with Incorrectly Specified Arguments
CWE-629Weaknesses in OWASP Top Ten (2007)
CWE-63DEPRECATED: Windows Path Link Problems
CWE-630DEPRECATED: Weaknesses Examined by SAMATE
CWE-631DEPRECATED: Resource-specific Weaknesses
CWE-632DEPRECATED: Weaknesses that Affect Files or Directories
CWE-633DEPRECATED: Weaknesses that Affect Memory
CWE-634DEPRECATED: Weaknesses that Affect System Processes
CWE-635Weaknesses Originally Used by NVD from 2008 to 2016
CWE-636Not Failing Securely ('Failing Open')
CWE-637Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')
CWE-638Not Using Complete Mediation
CWE-64Windows Shortcut Following (.LNK)
CWE-641Improper Restriction of Names for Files and Other Resources
CWE-642External Control of Critical State Data
CWE-643Improper Neutralization of Data within XPath Expressions ('XPath Injection')
CWE-644Improper Neutralization of HTTP Headers for Scripting Syntax
CWE-645Overly Restrictive Account Lockout Mechanism
CWE-646Reliance on File Name or Extension of Externally-Supplied File
CWE-648Incorrect Use of Privileged APIs
CWE-649Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking
CWE-65Windows Hard Link
CWE-650Trusting HTTP Permission Methods on the Server Side
CWE-651Exposure of WSDL File Containing Sensitive Information
CWE-652Improper Neutralization of Data within XQuery Expressions ('XQuery Injection')
CWE-653Improper Isolation or Compartmentalization
CWE-654Reliance on a Single Factor in a Security Decision
CWE-655Insufficient Psychological Acceptability
CWE-656Reliance on Security Through Obscurity
CWE-657Violation of Secure Design Principles
CWE-658Weaknesses in Software Written in C
CWE-659Weaknesses in Software Written in C++
CWE-66Improper Handling of File Names that Identify Virtual Resources
CWE-660Weaknesses in Software Written in Java
CWE-661Weaknesses in Software Written in PHP
CWE-663Use of a Non-reentrant Function in a Concurrent Context
CWE-664Improper Control of a Resource Through its Lifetime
CWE-666Operation on Resource in Wrong Phase of Lifetime
CWE-671Lack of Administrator Control over Security
CWE-673External Influence of Sphere Definition
CWE-675Multiple Operations on Resource in Single-Operation Context
CWE-676Use of Potentially Dangerous Function
CWE-677Weakness Base Elements
CWE-678Composites
CWE-679DEPRECATED: Chain Elements
CWE-68DEPRECATED: Windows Virtual File Problems
CWE-682Incorrect Calculation
CWE-683Function Call With Incorrect Order of Arguments
CWE-685Function Call With Incorrect Number of Arguments
CWE-686Function Call With Incorrect Argument Type
CWE-687Function Call With Incorrectly Specified Argument Value
CWE-688Function Call With Incorrect Variable or Reference as Argument
CWE-689Permission Race Condition During Resource Copy
CWE-69Improper Handling of Windows ::DATA Alternate Data Stream
CWE-690Unchecked Return Value to NULL Pointer Dereference
CWE-691Insufficient Control Flow Management
CWE-692Incomplete Denylist to Cross-Site Scripting
CWE-694Use of Multiple Resources with Duplicate Identifier
CWE-695Use of Low-Level Functionality
CWE-696Incorrect Behavior Order
CWE-698Execution After Redirect (EAR)
CWE-699Software Development
CWE-7J2EE Misconfiguration: Missing Custom Error Page
CWE-70DEPRECATED: Mac Virtual File Problems
CWE-700Seven Pernicious Kingdoms
CWE-701Weaknesses Introduced During Design
CWE-702Weaknesses Introduced During Implementation
CWE-705Incorrect Control Flow Scoping
CWE-707Improper Neutralization
CWE-708Incorrect Ownership Assignment
CWE-709Named Chains
CWE-71DEPRECATED: Apple '.DS_Store'
CWE-710Improper Adherence to Coding Standards
CWE-711Weaknesses in OWASP Top Ten (2004)
CWE-712OWASP Top Ten 2007 Category A1 - Cross Site Scripting (XSS)
CWE-713OWASP Top Ten 2007 Category A2 - Injection Flaws
CWE-714OWASP Top Ten 2007 Category A3 - Malicious File Execution
CWE-715OWASP Top Ten 2007 Category A4 - Insecure Direct Object Reference
CWE-716OWASP Top Ten 2007 Category A5 - Cross Site Request Forgery (CSRF)
CWE-717OWASP Top Ten 2007 Category A6 - Information Leakage and Improper Error Handling
CWE-718OWASP Top Ten 2007 Category A7 - Broken Authentication and Session Management
CWE-719OWASP Top Ten 2007 Category A8 - Insecure Cryptographic Storage
CWE-72Improper Handling of Apple HFS+ Alternate Data Stream Path
CWE-720OWASP Top Ten 2007 Category A9 - Insecure Communications
CWE-721OWASP Top Ten 2007 Category A10 - Failure to Restrict URL Access
CWE-722OWASP Top Ten 2004 Category A1 - Unvalidated Input
CWE-723OWASP Top Ten 2004 Category A2 - Broken Access Control
CWE-724OWASP Top Ten 2004 Category A3 - Broken Authentication and Session Management
CWE-725OWASP Top Ten 2004 Category A4 - Cross-Site Scripting (XSS) Flaws
CWE-726OWASP Top Ten 2004 Category A5 - Buffer Overflows
CWE-727OWASP Top Ten 2004 Category A6 - Injection Flaws
CWE-728OWASP Top Ten 2004 Category A7 - Improper Error Handling
CWE-729OWASP Top Ten 2004 Category A8 - Insecure Storage
CWE-73External Control of File Name or Path
CWE-730OWASP Top Ten 2004 Category A9 - Denial of Service
CWE-731OWASP Top Ten 2004 Category A10 - Insecure Configuration Management
CWE-733Compiler Optimization Removal or Modification of Security-critical Code
CWE-734Weaknesses Addressed by the CERT C Secure Coding Standard (2008)
CWE-735CERT C Secure Coding Standard (2008) Chapter 2 - Preprocessor (PRE)
CWE-736CERT C Secure Coding Standard (2008) Chapter 3 - Declarations and Initialization (DCL)
CWE-737CERT C Secure Coding Standard (2008) Chapter 4 - Expressions (EXP)
CWE-738CERT C Secure Coding Standard (2008) Chapter 5 - Integers (INT)
CWE-739CERT C Secure Coding Standard (2008) Chapter 6 - Floating Point (FLP)
CWE-740CERT C Secure Coding Standard (2008) Chapter 7 - Arrays (ARR)
CWE-741CERT C Secure Coding Standard (2008) Chapter 8 - Characters and Strings (STR)
CWE-742CERT C Secure Coding Standard (2008) Chapter 9 - Memory Management (MEM)
CWE-743CERT C Secure Coding Standard (2008) Chapter 10 - Input Output (FIO)
CWE-744CERT C Secure Coding Standard (2008) Chapter 11 - Environment (ENV)
CWE-745CERT C Secure Coding Standard (2008) Chapter 12 - Signals (SIG)
CWE-746CERT C Secure Coding Standard (2008) Chapter 13 - Error Handling (ERR)
CWE-747CERT C Secure Coding Standard (2008) Chapter 14 - Miscellaneous (MSC)
CWE-748CERT C Secure Coding Standard (2008) Appendix - POSIX (POS)
CWE-75Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
CWE-750Weaknesses in the 2009 CWE/SANS Top 25 Most Dangerous Programming Errors
CWE-7512009 Top 25 - Insecure Interaction Between Components
CWE-7522009 Top 25 - Risky Resource Management
CWE-7532009 Top 25 - Porous Defenses
CWE-756Missing Custom Error Page
CWE-758Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
CWE-759Use of a One-Way Hash without a Salt
CWE-76Improper Neutralization of Equivalent Special Elements
CWE-760Use of a One-Way Hash with a Predictable Salt
CWE-761Free of Pointer not at Start of Buffer
CWE-762Mismatched Memory Management Routines
CWE-763Release of Invalid Pointer or Reference
CWE-764Multiple Locks of a Critical Resource
CWE-765Multiple Unlocks of a Critical Resource
CWE-766Critical Data Element Declared Public
CWE-767Access to Critical Private Variable via Public Method
CWE-768Incorrect Short Circuit Evaluation
CWE-769DEPRECATED: Uncontrolled File Descriptor Consumption
CWE-771Missing Reference to Active Allocated Resource
CWE-773Missing Reference to Active File Descriptor or Handle
CWE-774Allocation of File Descriptors or Handles Without Limits or Throttling
CWE-775Missing Release of File Descriptor or Handle after Effective Lifetime
CWE-777Regular Expression without Anchors
CWE-778Insufficient Logging
CWE-779Logging of Excessive Data
CWE-780Use of RSA Algorithm without OAEP
CWE-781Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code
CWE-782Exposed IOCTL with Insufficient Access Control
CWE-783Operator Precedence Logic Error
CWE-784Reliance on Cookies without Validation and Integrity Checking in a Security Decision
CWE-785Use of Path Manipulation Function without Maximum-sized Buffer
CWE-788Access of Memory Location After End of Buffer
CWE-790Improper Filtering of Special Elements
CWE-791Incomplete Filtering of Special Elements
CWE-792Incomplete Filtering of One or More Instances of Special Elements
CWE-793Only Filtering One Instance of a Special Element
CWE-794Incomplete Filtering of Multiple Instances of Special Elements
CWE-795Only Filtering Special Elements at a Specified Location
CWE-796Only Filtering Special Elements Relative to a Marker
CWE-797Only Filtering Special Elements at an Absolute Position
CWE-799Improper Control of Interaction Frequency
CWE-8J2EE Misconfiguration: Entity Bean Declared Remote
CWE-800Weaknesses in the 2010 CWE/SANS Top 25 Most Dangerous Programming Errors
CWE-8012010 Top 25 - Insecure Interaction Between Components
CWE-8022010 Top 25 - Risky Resource Management
CWE-8032010 Top 25 - Porous Defenses
CWE-804Guessable CAPTCHA
CWE-806Buffer Access Using Size of Source Buffer
CWE-8082010 Top 25 - Weaknesses On the Cusp
CWE-809Weaknesses in OWASP Top Ten (2010)
CWE-81Improper Neutralization of Script in an Error Message Web Page
CWE-810OWASP Top Ten 2010 Category A1 - Injection
CWE-811OWASP Top Ten 2010 Category A2 - Cross-Site Scripting (XSS)
CWE-812OWASP Top Ten 2010 Category A3 - Broken Authentication and Session Management
CWE-813OWASP Top Ten 2010 Category A4 - Insecure Direct Object References
CWE-814OWASP Top Ten 2010 Category A5 - Cross-Site Request Forgery(CSRF)
CWE-815OWASP Top Ten 2010 Category A6 - Security Misconfiguration
CWE-816OWASP Top Ten 2010 Category A7 - Insecure Cryptographic Storage
CWE-817OWASP Top Ten 2010 Category A8 - Failure to Restrict URL Access
CWE-818OWASP Top Ten 2010 Category A9 - Insufficient Transport Layer Protection
CWE-819OWASP Top Ten 2010 Category A10 - Unvalidated Redirects and Forwards
CWE-82Improper Neutralization of Script in Attributes of IMG Tags in a Web Page
CWE-820Missing Synchronization
CWE-821Incorrect Synchronization
CWE-822Untrusted Pointer Dereference
CWE-826Premature Release of Resource During Expected Lifetime
CWE-827Improper Control of Document Type Definition
CWE-828Signal Handler with Functionality that is not Asynchronous-Safe
CWE-83Improper Neutralization of Script in Attributes in a Web Page
CWE-830Inclusion of Web Functionality from an Untrusted Source
CWE-831Signal Handler Function Associated with Multiple Signals
CWE-832Unlock of a Resource that is not Locked
CWE-833Deadlock
CWE-836Use of Password Hash Instead of Password for Authentication
CWE-837Improper Enforcement of a Single, Unique Action
CWE-838Inappropriate Encoding for Output Context
CWE-839Numeric Range Comparison Without Minimum Check
CWE-84Improper Neutralization of Encoded URI Schemes in a Web Page
CWE-840Business Logic Errors
CWE-841Improper Enforcement of Behavioral Workflow
CWE-842Placement of User into Incorrect Group
CWE-844Weaknesses Addressed by The CERT Oracle Secure Coding Standard for Java (2011)
CWE-845The CERT Oracle Secure Coding Standard for Java (2011) Chapter 2 - Input Validation and Data Sanitization (IDS)
CWE-846The CERT Oracle Secure Coding Standard for Java (2011) Chapter 3 - Declarations and Initialization (DCL)
CWE-847The CERT Oracle Secure Coding Standard for Java (2011) Chapter 4 - Expressions (EXP)
CWE-848The CERT Oracle Secure Coding Standard for Java (2011) Chapter 5 - Numeric Types and Operations (NUM)
CWE-849The CERT Oracle Secure Coding Standard for Java (2011) Chapter 6 - Object Orientation (OBJ)
CWE-85Doubled Character XSS Manipulations
CWE-850The CERT Oracle Secure Coding Standard for Java (2011) Chapter 7 - Methods (MET)
CWE-851The CERT Oracle Secure Coding Standard for Java (2011) Chapter 8 - Exceptional Behavior (ERR)
CWE-852The CERT Oracle Secure Coding Standard for Java (2011) Chapter 9 - Visibility and Atomicity (VNA)
CWE-853The CERT Oracle Secure Coding Standard for Java (2011) Chapter 10 - Locking (LCK)
CWE-854The CERT Oracle Secure Coding Standard for Java (2011) Chapter 11 - Thread APIs (THI)
CWE-855The CERT Oracle Secure Coding Standard for Java (2011) Chapter 12 - Thread Pools (TPS)
CWE-856The CERT Oracle Secure Coding Standard for Java (2011) Chapter 13 - Thread-Safety Miscellaneous (TSM)
CWE-857The CERT Oracle Secure Coding Standard for Java (2011) Chapter 14 - Input Output (FIO)
CWE-858The CERT Oracle Secure Coding Standard for Java (2011) Chapter 15 - Serialization (SER)
CWE-859The CERT Oracle Secure Coding Standard for Java (2011) Chapter 16 - Platform Security (SEC)
CWE-860The CERT Oracle Secure Coding Standard for Java (2011) Chapter 17 - Runtime Environment (ENV)
CWE-861The CERT Oracle Secure Coding Standard for Java (2011) Chapter 18 - Miscellaneous (MSC)
CWE-8642011 Top 25 - Insecure Interaction Between Components
CWE-8652011 Top 25 - Risky Resource Management
CWE-8662011 Top 25 - Porous Defenses
CWE-8672011 Top 25 - Weaknesses On the Cusp
CWE-868Weaknesses Addressed by the SEI CERT C++ Coding Standard (2016 Version)
CWE-869CERT C++ Secure Coding Section 01 - Preprocessor (PRE)
CWE-87Improper Neutralization of Alternate XSS Syntax
CWE-870CERT C++ Secure Coding Section 02 - Declarations and Initialization (DCL)
CWE-871CERT C++ Secure Coding Section 03 - Expressions (EXP)
CWE-872CERT C++ Secure Coding Section 04 - Integers (INT)
CWE-873CERT C++ Secure Coding Section 05 - Floating Point Arithmetic (FLP)
CWE-874CERT C++ Secure Coding Section 06 - Arrays and the STL (ARR)
CWE-875CERT C++ Secure Coding Section 07 - Characters and Strings (STR)
CWE-876CERT C++ Secure Coding Section 08 - Memory Management (MEM)
CWE-877CERT C++ Secure Coding Section 09 - Input Output (FIO)
CWE-878CERT C++ Secure Coding Section 10 - Environment (ENV)
CWE-879CERT C++ Secure Coding Section 11 - Signals (SIG)
CWE-880CERT C++ Secure Coding Section 12 - Exceptions and Error Handling (ERR)
CWE-881CERT C++ Secure Coding Section 13 - Object Oriented Programming (OOP)
CWE-882CERT C++ Secure Coding Section 14 - Concurrency (CON)
CWE-883CERT C++ Secure Coding Section 49 - Miscellaneous (MSC)
CWE-884CWE Cross-section
CWE-885SFP Primary Cluster: Risky Values
CWE-886SFP Primary Cluster: Unused entities
CWE-887SFP Primary Cluster: API
CWE-888Software Fault Pattern (SFP) Clusters
CWE-889SFP Primary Cluster: Exception Management
CWE-890SFP Primary Cluster: Memory Access
CWE-891SFP Primary Cluster: Memory Management
CWE-892SFP Primary Cluster: Resource Management
CWE-893SFP Primary Cluster: Path Resolution
CWE-894SFP Primary Cluster: Synchronization
CWE-895SFP Primary Cluster: Information Leak
CWE-896SFP Primary Cluster: Tainted Input
CWE-897SFP Primary Cluster: Entry Points
CWE-898SFP Primary Cluster: Authentication
CWE-899SFP Primary Cluster: Access Control
CWE-9J2EE Misconfiguration: Weak Access Permissions for EJB Methods
CWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CWE-900Weaknesses in the 2011 CWE/SANS Top 25 Most Dangerous Software Errors
CWE-901SFP Primary Cluster: Privilege
CWE-902SFP Primary Cluster: Channel
CWE-903SFP Primary Cluster: Cryptography
CWE-904SFP Primary Cluster: Malware
CWE-905SFP Primary Cluster: Predictability
CWE-906SFP Primary Cluster: UI
CWE-907SFP Primary Cluster: Other
CWE-91XML Injection (aka Blind XPath Injection)
CWE-910Use of Expired File Descriptor
CWE-911Improper Update of Reference Count
CWE-913Improper Control of Dynamically-Managed Code Resources
CWE-914Improper Control of Dynamically-Identified Variables
CWE-916Use of Password Hash With Insufficient Computational Effort
CWE-919Weaknesses in Mobile Applications
CWE-92DEPRECATED: Improper Sanitization of Custom Special Characters
CWE-920Improper Restriction of Power Consumption
CWE-921Storage of Sensitive Data in a Mechanism without Access Control
CWE-923Improper Restriction of Communication Channel to Intended Endpoints
CWE-925Improper Verification of Intent by Broadcast Receiver
CWE-926Improper Export of Android Application Components
CWE-927Use of Implicit Intent for Sensitive Communication
CWE-928Weaknesses in OWASP Top Ten (2013)
CWE-929OWASP Top Ten 2013 Category A1 - Injection
CWE-930OWASP Top Ten 2013 Category A2 - Broken Authentication and Session Management
CWE-931OWASP Top Ten 2013 Category A3 - Cross-Site Scripting (XSS)
CWE-932OWASP Top Ten 2013 Category A4 - Insecure Direct Object References
CWE-933OWASP Top Ten 2013 Category A5 - Security Misconfiguration
CWE-934OWASP Top Ten 2013 Category A6 - Sensitive Data Exposure
CWE-935OWASP Top Ten 2013 Category A7 - Missing Function Level Access Control
CWE-936OWASP Top Ten 2013 Category A8 - Cross-Site Request Forgery (CSRF)
CWE-937OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities
CWE-938OWASP Top Ten 2013 Category A10 - Unvalidated Redirects and Forwards
CWE-939Improper Authorization in Handler for Custom URL Scheme
CWE-941Incorrectly Specified Destination in a Communication Channel
CWE-943Improper Neutralization of Special Elements in Data Query Logic
CWE-944SFP Secondary Cluster: Access Management
CWE-945SFP Secondary Cluster: Insecure Resource Access
CWE-946SFP Secondary Cluster: Insecure Resource Permissions
CWE-947SFP Secondary Cluster: Authentication Bypass
CWE-948SFP Secondary Cluster: Digital Certificate
CWE-949SFP Secondary Cluster: Faulty Endpoint Authentication
CWE-950SFP Secondary Cluster: Hardcoded Sensitive Data
CWE-951SFP Secondary Cluster: Insecure Authentication Policy
CWE-952SFP Secondary Cluster: Missing Authentication
CWE-953SFP Secondary Cluster: Missing Endpoint Authentication
CWE-954SFP Secondary Cluster: Multiple Binds to the Same Port
CWE-955SFP Secondary Cluster: Unrestricted Authentication
CWE-956SFP Secondary Cluster: Channel Attack
CWE-957SFP Secondary Cluster: Protocol Error
CWE-958SFP Secondary Cluster: Broken Cryptography
CWE-959SFP Secondary Cluster: Weak Cryptography
CWE-96Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
CWE-960SFP Secondary Cluster: Ambiguous Exception Type
CWE-961SFP Secondary Cluster: Incorrect Exception Behavior
CWE-962SFP Secondary Cluster: Unchecked Status Condition
CWE-963SFP Secondary Cluster: Exposed Data
CWE-964SFP Secondary Cluster: Exposure Temporary File
CWE-965SFP Secondary Cluster: Insecure Session Management
CWE-966SFP Secondary Cluster: Other Exposures
CWE-967SFP Secondary Cluster: State Disclosure
CWE-968SFP Secondary Cluster: Covert Channel
CWE-969SFP Secondary Cluster: Faulty Memory Release
CWE-97Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
CWE-970SFP Secondary Cluster: Faulty Buffer Access
CWE-971SFP Secondary Cluster: Faulty Pointer Use
CWE-972SFP Secondary Cluster: Faulty String Expansion
CWE-973SFP Secondary Cluster: Improper NULL Termination
CWE-974SFP Secondary Cluster: Incorrect Buffer Length Computation
CWE-975SFP Secondary Cluster: Architecture
CWE-976SFP Secondary Cluster: Compiler
CWE-977SFP Secondary Cluster: Design
CWE-978SFP Secondary Cluster: Implementation
CWE-979SFP Secondary Cluster: Failed Chroot Jail
CWE-98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CWE-980SFP Secondary Cluster: Link in Resource Name Resolution
CWE-981SFP Secondary Cluster: Path Traversal
CWE-982SFP Secondary Cluster: Failure to Release Resource
CWE-983SFP Secondary Cluster: Faulty Resource Use
CWE-984SFP Secondary Cluster: Life Cycle
CWE-985SFP Secondary Cluster: Unrestricted Consumption
CWE-986SFP Secondary Cluster: Missing Lock
CWE-987SFP Secondary Cluster: Multiple Locks/Unlocks
CWE-988SFP Secondary Cluster: Race Condition Window
CWE-989SFP Secondary Cluster: Unrestricted Lock
CWE-99Improper Control of Resource Identifiers ('Resource Injection')
CWE-990SFP Secondary Cluster: Tainted Input to Command
CWE-991SFP Secondary Cluster: Tainted Input to Environment
CWE-992SFP Secondary Cluster: Faulty Input Transformation
CWE-993SFP Secondary Cluster: Incorrect Input Handling
CWE-994SFP Secondary Cluster: Tainted Input to Variable
CWE-995SFP Secondary Cluster: Feature
CWE-996SFP Secondary Cluster: Security
CWE-997SFP Secondary Cluster: Information Loss
CWE-998SFP Secondary Cluster: Glitch in Computation
CWE-999DEPRECATED: Weaknesses without Software Fault Patterns