Gold Open Source
Explore
Packages
Vulnerabilities
CWEs
MCP Servers
Scan
Resources
Login
Home
/
CWEs
Weakness Classes
CWE Index
1460 Common Weakness Enumeration classes tracked across the Gold vulnerability database.
CWE-400
Uncontrolled Resource Consumption
282
CWE-1333
Inefficient Regular Expression (ReDoS)
202
CWE-20
Improper Input Validation
180
CWE-1321
Prototype Pollution
177
CWE-79
Cross-site Scripting (XSS)
163
CWE-770
Allocation of Resources Without Limits
137
CWE-835
Infinite Loop
131
CWE-22
Path Traversal
129
CWE-787
Out-of-bounds Write
112
CWE-200
Exposure of Sensitive Information
107
CWE-94
Code Injection
91
CWE-416
Use After Free
78
CWE-476
NULL Pointer Dereference
72
CWE-502
Deserialization of Untrusted Data
65
CWE-122
Heap-based Buffer Overflow
64
CWE-125
Out-of-bounds Read
61
CWE-119
Improper Restriction of Memory Buffer Operations
59
CWE-78
OS Command Injection
56
CWE-295
Improper Certificate Validation
49
CWE-74
Injection
49
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
44
CWE-190
Integer Overflow or Wraparound
43
CWE-601
Open Redirect
43
CWE-918
Server-Side Request Forgery (SSRF)
42
CWE-407
Inefficient Algorithmic Complexity
41
CWE-399
Resource Management Errors
40
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
40
CWE-264
Permissions, Privileges, and Access Controls
38
CWE-59
Link Following
35
CWE-352
Cross-Site Request Forgery (CSRF)
34
CWE-310
Cryptographic Issues
33
CWE-362
Race Condition
33
CWE-347
Improper Verification of Cryptographic Signature
31
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
31
CWE-674
Uncontrolled Recursion
31
CWE-754
Improper Check for Unusual or Exceptional Conditions
31
CWE-120
Classic Buffer Overflow
29
CWE-284
Improper Access Control
29
CWE-116
Improper Encoding or Escaping of Output
28
CWE-908
Use of Uninitialized Resource
27
CWE-843
Type Confusion
26
CWE-287
Improper Authentication
25
CWE-89
SQL Injection
23
CWE-436
Interpretation Conflict
20
CWE-862
Missing Authorization
20
CWE-415
Double Free
19
CWE-189
Numeric Errors
18
CWE-704
Incorrect Type Conversion or Cast
18
CWE-1284
Improper Validation of Specified Quantity in Input
16
CWE-327
Broken or Risky Cryptographic Algorithm
16
CWE-346
Origin Validation Error
16
CWE-606
Unchecked Input for Loop Condition
16
CWE-77
Command Injection
15
CWE-1289
Improper Validation of Unsafe Equivalence in Input
14
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
14
CWE-354
Improper Validation of Integrity Check Value
14
CWE-434
Unrestricted Upload of Dangerous File Type
14
CWE-330
Use of Insufficiently Random Values
13
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
13
CWE-823
Use of Out-of-range Pointer Offset
13
CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
12
CWE-201
Insertion of Sensitive Information Into Sent Data
12
CWE-306
Missing Authentication for Critical Function
12
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
12
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
12
CWE-471
Modification of Assumed-Immutable Data (MAID)
12
CWE-61
UNIX Symbolic Link (Symlink) Following
12
CWE-668
Exposure of Resource to Wrong Sphere
11
CWE-67
Improper Handling of Windows Device Names
11
CWE-863
Incorrect Authorization
11
CWE-1021
Improper Restriction of Rendered UI Layers
10
CWE-126
Buffer Over-read
10
CWE-131
Incorrect Calculation of Buffer Size
10
CWE-680
Integer Overflow to Buffer Overflow
10
CWE-697
Incorrect Comparison
10
CWE-185
Incorrect Regular Expression
9
CWE-203
Observable Discrepancy
9
CWE-276
Incorrect Default Permissions
9
CWE-670
Always-Incorrect Control Flow Implementation
9
CWE-1050
Excessive Platform Resource Consumption within a Loop
8
CWE-121
Stack-based Buffer Overflow
8
CWE-140
Improper Neutralization of Delimiters
8
CWE-183
Permissive List of Allowed Inputs
8
CWE-248
Uncaught Exception
8
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
8
CWE-665
Improper Initialization
8
CWE-755
Improper Handling of Exceptional Conditions
8
CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
8
CWE-184
Incomplete List of Disallowed Inputs
7
CWE-281
Improper Preservation of Permissions
7
CWE-345
Insufficient Verification of Data Authenticity
7
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
7
CWE-494
Download of Code Without Integrity Check
7
CWE-672
Operation on a Resource after Expiration or Release
7
CWE-178
Improper Handling of Case Sensitivity
6
CWE-180
Incorrect Behavior Order: Validate Before Canonicalize
6
CWE-524
Use of Cache Containing Sensitive Information
6
CWE-551
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
6
CWE-611
XML External Entity (XXE)
6
CWE-706
Use of Incorrectly-Resolved Name or Reference
6
CWE-772
Missing Release of Resource after Effective Lifetime
6
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
6
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
6
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
6
CWE-129
Improper Validation of Array Index
5
CWE-1385
Missing Origin Validation in WebSockets
5
CWE-17
DEPRECATED: Code
5
CWE-23
Relative Path Traversal
5
CWE-254
7PK - Security Features
5
CWE-732
Incorrect Permission Assignment
5
CWE-824
Access of Uninitialized Pointer
5
CWE-834
Excessive Iteration
5
CWE-1220
Insufficient Granularity of Access Control
4
CWE-1286
Improper Validation of Syntactic Correctness of Input
4
CWE-130
Improper Handling of Length Parameter Inconsistency
4
CWE-134
Use of Externally-Controlled Format String
4
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
4
CWE-191
Integer Underflow (Wrap or Wraparound)
4
CWE-285
Improper Authorization
4
CWE-290
Authentication Bypass by Spoofing
4
CWE-331
Insufficient Entropy
4
CWE-350
Reliance on Reverse DNS Resolution for a Security-Critical Action
4
CWE-384
Session Fixation
4
CWE-401
Missing Release of Memory after Effective Lifetime
4
CWE-472
External Control of Assumed-Immutable Web Parameter
4
CWE-50
Path Equivalence: '//multiple/leading/slash'
4
CWE-626
Null Byte Interaction Error (Poison Null Byte)
4
CWE-639
Authorization Bypass Through User-Controlled Key
4
CWE-669
Incorrect Resource Transfer Between Spheres
4
CWE-749
Exposed Dangerous Method or Function
4
CWE-798
Use of Hard-coded Credentials
4
CWE-807
Reliance on Untrusted Inputs in a Security Decision
4
CWE-1287
Improper Validation of Specified Type of Input
3
CWE-141
Improper Neutralization of Parameter/Argument Delimiters
3
CWE-176
Improper Handling of Unicode Encoding
3
CWE-187
Partial String Comparison
3
CWE-312
Cleartext Storage of Sensitive Information
3
CWE-325
Missing Cryptographic Step
3
CWE-369
Divide By Zero
3
CWE-388
7PK - Errors
3
CWE-405
Asymmetric Resource Consumption (Amplification)
3
CWE-440
Expected Behavior Violation
3
CWE-506
Embedded Malicious Code
3
CWE-522
Insufficiently Protected Credentials
3
CWE-539
Use of Persistent Cookies Containing Sensitive Information
3
CWE-703
Improper Check or Handling of Exceptional Conditions
3
CWE-924
Improper Enforcement of Message Integrity During Transmission in a Communication Channel
3
CWE-1240
Use of a Cryptographic Primitive with a Risky Implementation
2
CWE-193
Off-by-one Error
2
CWE-289
Authentication Bypass by Alternate Name
2
CWE-300
Channel Accessible by Non-Endpoint
2
CWE-320
Key Management Errors
2
CWE-326
Inadequate Encryption Strength
2
CWE-348
Use of Less Trusted Source
2
CWE-532
Insertion of Sensitive Information into Log File
2
CWE-552
Files or Directories Accessible to External Parties
2
CWE-613
Insufficient Session Expiration
2
CWE-617
Reachable Assertion
2
CWE-662
Improper Synchronization
2
CWE-681
Incorrect Conversion between Numeric Types
2
CWE-693
Protection Mechanism Failure
2
CWE-789
Memory Allocation with Excessive Size Value
2
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
2
CWE-909
Missing Initialization of Resource
2
CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
2
CWE-1077
Floating Point Comparison with Incorrect Operator
1
CWE-1113
Inappropriate Comment Style
1
CWE-115
Misinterpretation of Input
1
CWE-124
Buffer Underwrite ('Buffer Underflow')
1
CWE-1259
Improper Restriction of Security Token Assignment
1
CWE-128
Wrap-around Error
1
CWE-1325
Improperly Controlled Sequential Memory Allocation
1
CWE-135
Incorrect Calculation of Multi-Byte String Length
1
CWE-144
Improper Neutralization of Line Delimiters
1
CWE-177
Improper Handling of URL Encoding (Hex Encoding)
1
CWE-208
Observable Timing Discrepancy
1
CWE-219
Storage of File with Sensitive Data Under Web Root
1
CWE-24
Path Traversal: '../filedir'
1
CWE-266
Incorrect Privilege Assignment
1
CWE-269
Improper Privilege Management
1
CWE-303
Incorrect Implementation of Authentication Algorithm
1
CWE-311
Missing Encryption of Sensitive Data
1
CWE-319
Cleartext Transmission of Sensitive Information
1
CWE-323
Reusing a Nonce, Key Pair in Encryption
1
CWE-329
Generation of Predictable IV with CBC Mode
1
CWE-377
Insecure Temporary File
1
CWE-378
Creation of Temporary File With Insecure Permissions
1
CWE-385
Covert Timing Channel
1
CWE-414
Missing Lock Check
1
CWE-425
Direct Request ('Forced Browsing')
1
CWE-426
Untrusted Search Path
1
CWE-427
Uncontrolled Search Path Element
1
CWE-457
Use of Uninitialized Variable
1
CWE-459
Incomplete Cleanup
1
CWE-460
Improper Cleanup on Thrown Exception
1
CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
1
CWE-514
Covert Channel
1
CWE-599
Missing Validation of OpenSSL Certificate
1
CWE-625
Permissive Regular Expression
1
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
1
CWE-647
Use of Non-Canonical URL Paths for Authorization Decisions
1
CWE-667
Improper Locking
1
CWE-684
Incorrect Provision of Specified Functionality
1
CWE-757
Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
1
CWE-786
Access of Memory Location Before Start of Buffer
1
CWE-805
Buffer Access with Incorrect Length Value
1
CWE-825
Expired Pointer Dereference
1
CWE-86
Improper Neutralization of Invalid Characters in Identifiers in Web Pages
1
CWE-912
Hidden Functionality
1
CWE-922
Insecure Storage of Sensitive Information
1
CWE-940
Improper Verification of Source of a Communication Channel
1
CWE-942
Permissive Cross-domain Security Policy with Untrusted Domains
1
A01:2021
Broken Access Control
A02:2021
Cryptographic Failures
A03:2021
Injection
A04:2021
Insecure Design
A05:2021
Security Misconfiguration
A06:2021
Vulnerable and Outdated Components
A07:2021
Identification and Authentication Failures
A08:2021
Software and Data Integrity Failures
A09:2021
Security Logging and Monitoring Failures
A10:2021
Server-Side Request Forgery (SSRF)
CWE-1
DEPRECATED: Location
CWE-10
DEPRECATED: ASP.NET Environment Issues
CWE-100
DEPRECATED: Technology-Specific Input Validation Problems
CWE-1000
Research Concepts
CWE-1001
SFP Secondary Cluster: Use of an Improper API
CWE-1002
SFP Secondary Cluster: Unexpected Entry Points
CWE-1003
Weaknesses for Simplified Mapping of Published Vulnerabilities
CWE-1004
Sensitive Cookie Without 'HttpOnly' Flag
CWE-1005
7PK - Input Validation and Representation
CWE-1006
Bad Coding Practices
CWE-1007
Insufficient Visual Distinction of Homoglyphs Presented to User
CWE-1008
Architectural Concepts
CWE-1009
Audit
CWE-101
DEPRECATED: Struts Validation Problems
CWE-1010
Authenticate Actors
CWE-1011
Authorize Actors
CWE-1012
Cross Cutting
CWE-1013
Encrypt Data
CWE-1014
Identify Actors
CWE-1015
Limit Access
CWE-1016
Limit Exposure
CWE-1017
Lock Computer
CWE-1018
Manage User Sessions
CWE-1019
Validate Inputs
CWE-102
Struts: Duplicate Validation Forms
CWE-1020
Verify Message Integrity
CWE-1022
Use of Web Link to Untrusted Target with window.opener Access
CWE-1023
Incomplete Comparison with Missing Factors
CWE-1024
Comparison of Incompatible Types
CWE-1025
Comparison Using Wrong Factors
CWE-1026
Weaknesses in OWASP Top Ten (2017)
CWE-1027
OWASP Top Ten 2017 Category A1 - Injection
CWE-1028
OWASP Top Ten 2017 Category A2 - Broken Authentication
CWE-1029
OWASP Top Ten 2017 Category A3 - Sensitive Data Exposure
CWE-103
Struts: Incomplete validate() Method Definition
CWE-1030
OWASP Top Ten 2017 Category A4 - XML External Entities (XXE)
CWE-1031
OWASP Top Ten 2017 Category A5 - Broken Access Control
CWE-1032
OWASP Top Ten 2017 Category A6 - Security Misconfiguration
CWE-1033
OWASP Top Ten 2017 Category A7 - Cross-Site Scripting (XSS)
CWE-1034
OWASP Top Ten 2017 Category A8 - Insecure Deserialization
CWE-1035
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
CWE-1036
OWASP Top Ten 2017 Category A10 - Insufficient Logging & Monitoring
CWE-1037
Processor Optimization Removal or Modification of Security-critical Code
CWE-1038
Insecure Automated Optimizations
CWE-1039
Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism
CWE-104
Struts: Form Bean Does Not Extend Validation Class
CWE-1040
Quality Weaknesses with Indirect Security Impacts
CWE-1041
Use of Redundant Code
CWE-1042
Static Member Data Element outside of a Singleton Class Element
CWE-1043
Data Element Aggregating an Excessively Large Number of Non-Primitive Elements
CWE-1044
Architecture with Number of Horizontal Layers Outside of Expected Range
CWE-1045
Parent Class with a Virtual Destructor and a Child Class without a Virtual Destructor
CWE-1046
Creation of Immutable Text Using String Concatenation
CWE-1047
Modules with Circular Dependencies
CWE-1048
Invokable Control Element with Large Number of Outward Calls
CWE-1049
Excessive Data Query Operations in a Large Data Table
CWE-105
Struts: Form Field Without Validator
CWE-1051
Initialization with Hard-Coded Network Resource Configuration Data
CWE-1052
Excessive Use of Hard-Coded Literals in Initialization
CWE-1053
Missing Documentation for Design
CWE-1054
Invocation of a Control Element at an Unnecessarily Deep Horizontal Layer
CWE-1055
Multiple Inheritance from Concrete Classes
CWE-1056
Invokable Control Element with Variadic Parameters
CWE-1057
Data Access Operations Outside of Expected Data Manager Component
CWE-1058
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element
CWE-1059
Insufficient Technical Documentation
CWE-106
Struts: Plug-in Framework not in Use
CWE-1060
Excessive Number of Inefficient Server-Side Data Accesses
CWE-1061
Insufficient Encapsulation
CWE-1062
Parent Class with References to Child Class
CWE-1063
Creation of Class Instance within a Static Code Block
CWE-1064
Invokable Control Element with Signature Containing an Excessive Number of Parameters
CWE-1065
Runtime Resource Management Control Element in a Component Built to Run on Application Servers
CWE-1066
Missing Serialization Control Element
CWE-1067
Excessive Execution of Sequential Searches of Data Resource
CWE-1068
Inconsistency Between Implementation and Documented Design
CWE-1069
Empty Exception Block
CWE-107
Struts: Unused Validation Form
CWE-1070
Serializable Data Element Containing non-Serializable Item Elements
CWE-1071
Empty Code Block
CWE-1072
Data Resource Access without Use of Connection Pooling
CWE-1073
Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses
CWE-1074
Class with Excessively Deep Inheritance
CWE-1075
Unconditional Control Flow Transfer outside of Switch Block
CWE-1076
Insufficient Adherence to Expected Conventions
CWE-1078
Inappropriate Source Code Style or Formatting
CWE-1079
Parent Class without Virtual Destructor Method
CWE-108
Struts: Unvalidated Action Form
CWE-1080
Source Code File with Excessive Number of Lines of Code
CWE-1081
Entries with Maintenance Notes
CWE-1082
Class Instance Self Destruction Control Element
CWE-1083
Data Access from Outside Expected Data Manager Component
CWE-1084
Invokable Control Element with Excessive File or Data Access Operations
CWE-1085
Invokable Control Element with Excessive Volume of Commented-out Code
CWE-1086
Class with Excessive Number of Child Classes
CWE-1087
Class with Virtual Method without a Virtual Destructor
CWE-1088
Synchronous Access of Remote Resource without Timeout
CWE-1089
Large Data Table with Excessive Number of Indices
CWE-109
Struts: Validator Turned Off
CWE-1090
Method Containing Access of a Member Element from Another Class
CWE-1091
Use of Object without Invoking Destructor Method
CWE-1092
Use of Same Invokable Control Element in Multiple Architectural Layers
CWE-1093
Excessively Complex Data Representation
CWE-1094
Excessive Index Range Scan for a Data Resource
CWE-1095
Loop Condition Value Update within the Loop
CWE-1096
Singleton Class Instance Creation without Proper Locking or Synchronization
CWE-1097
Persistent Storable Data Element without Associated Comparison Control Element
CWE-1098
Data Element containing Pointer Item without Proper Copy Control Element
CWE-1099
Inconsistent Naming Conventions for Identifiers
CWE-11
ASP.NET Misconfiguration: Creating Debug Binary
CWE-110
Struts: Validator Without Form Field
CWE-1100
Insufficient Isolation of System-Dependent Functions
CWE-1101
Reliance on Runtime Component in Generated Code
CWE-1102
Reliance on Machine-Dependent Data Representation
CWE-1103
Use of Platform-Dependent Third Party Components
CWE-1104
Use of Unmaintained Third Party Components
CWE-1105
Insufficient Encapsulation of Machine-Dependent Functionality
CWE-1106
Insufficient Use of Symbolic Constants
CWE-1107
Insufficient Isolation of Symbolic Constant Definitions
CWE-1108
Excessive Reliance on Global Variables
CWE-1109
Use of Same Variable for Multiple Purposes
CWE-111
Direct Use of Unsafe JNI
CWE-1110
Incomplete Design Documentation
CWE-1111
Incomplete I/O Documentation
CWE-1112
Incomplete Documentation of Program Execution
CWE-1114
Inappropriate Whitespace Style
CWE-1115
Source Code Element without Standard Prologue
CWE-1116
Inaccurate Source Code Comments
CWE-1117
Callable with Insufficient Behavioral Summary
CWE-1118
Insufficient Documentation of Error Handling Techniques
CWE-1119
Excessive Use of Unconditional Branching
CWE-112
Missing XML Validation
CWE-1120
Excessive Code Complexity
CWE-1121
Excessive McCabe Cyclomatic Complexity
CWE-1122
Excessive Halstead Complexity
CWE-1123
Excessive Use of Self-Modifying Code
CWE-1124
Excessively Deep Nesting
CWE-1125
Excessive Attack Surface
CWE-1126
Declaration of Variable with Unnecessarily Wide Scope
CWE-1127
Compilation with Insufficient Warnings or Errors
CWE-1128
CISQ Quality Measures (2016)
CWE-1129
CISQ Quality Measures (2016) - Reliability
CWE-1130
CISQ Quality Measures (2016) - Maintainability
CWE-1131
CISQ Quality Measures (2016) - Security
CWE-1132
CISQ Quality Measures (2016) - Performance Efficiency
CWE-1133
Weaknesses Addressed by the SEI CERT Oracle Coding Standard for Java
CWE-1134
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 00. Input Validation and Data Sanitization (IDS)
CWE-1135
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 01. Declarations and Initialization (DCL)
CWE-1136
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 02. Expressions (EXP)
CWE-1137
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 03. Numeric Types and Operations (NUM)
CWE-1138
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 04. Characters and Strings (STR)
CWE-1139
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 05. Object Orientation (OBJ)
CWE-114
Process Control
CWE-1140
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 06. Methods (MET)
CWE-1141
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 07. Exceptional Behavior (ERR)
CWE-1142
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 08. Visibility and Atomicity (VNA)
CWE-1143
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 09. Locking (LCK)
CWE-1144
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 10. Thread APIs (THI)
CWE-1145
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 11. Thread Pools (TPS)
CWE-1146
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 12. Thread-Safety Miscellaneous (TSM)
CWE-1147
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 13. Input Output (FIO)
CWE-1148
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 14. Serialization (SER)
CWE-1149
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 15. Platform Security (SEC)
CWE-1150
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 16. Runtime Environment (ENV)
CWE-1151
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 17. Java Native Interface (JNI)
CWE-1152
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 49. Miscellaneous (MSC)
CWE-1153
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 50. Android (DRD)
CWE-1154
Weaknesses Addressed by the SEI CERT C Coding Standard
CWE-1155
SEI CERT C Coding Standard - Guidelines 01. Preprocessor (PRE)
CWE-1156
SEI CERT C Coding Standard - Guidelines 02. Declarations and Initialization (DCL)
CWE-1157
SEI CERT C Coding Standard - Guidelines 03. Expressions (EXP)
CWE-1158
SEI CERT C Coding Standard - Guidelines 04. Integers (INT)
CWE-1159
SEI CERT C Coding Standard - Guidelines 05. Floating Point (FLP)
CWE-1160
SEI CERT C Coding Standard - Guidelines 06. Arrays (ARR)
CWE-1161
SEI CERT C Coding Standard - Guidelines 07. Characters and Strings (STR)
CWE-1162
SEI CERT C Coding Standard - Guidelines 08. Memory Management (MEM)
CWE-1163
SEI CERT C Coding Standard - Guidelines 09. Input Output (FIO)
CWE-1164
Irrelevant Code
CWE-1165
SEI CERT C Coding Standard - Guidelines 10. Environment (ENV)
CWE-1166
SEI CERT C Coding Standard - Guidelines 11. Signals (SIG)
CWE-1167
SEI CERT C Coding Standard - Guidelines 12. Error Handling (ERR)
CWE-1168
SEI CERT C Coding Standard - Guidelines 13. Application Programming Interfaces (API)
CWE-1169
SEI CERT C Coding Standard - Guidelines 14. Concurrency (CON)
CWE-117
Improper Output Neutralization for Logs
CWE-1170
SEI CERT C Coding Standard - Guidelines 48. Miscellaneous (MSC)
CWE-1171
SEI CERT C Coding Standard - Guidelines 50. POSIX (POS)
CWE-1172
SEI CERT C Coding Standard - Guidelines 51. Microsoft Windows (WIN)
CWE-1173
Improper Use of Validation Framework
CWE-1174
ASP.NET Misconfiguration: Improper Model Validation
CWE-1175
SEI CERT Oracle Secure Coding Standard for Java - Guidelines 18. Concurrency (CON)
CWE-1176
Inefficient CPU Computation
CWE-1177
Use of Prohibited Code
CWE-1178
Weaknesses Addressed by the SEI CERT Perl Coding Standard
CWE-1179
SEI CERT Perl Coding Standard - Guidelines 01. Input Validation and Data Sanitization (IDS)
CWE-118
Incorrect Access of Indexable Resource ('Range Error')
CWE-1180
SEI CERT Perl Coding Standard - Guidelines 02. Declarations and Initialization (DCL)
CWE-1181
SEI CERT Perl Coding Standard - Guidelines 03. Expressions (EXP)
CWE-1182
SEI CERT Perl Coding Standard - Guidelines 04. Integers (INT)
CWE-1183
SEI CERT Perl Coding Standard - Guidelines 05. Strings (STR)
CWE-1184
SEI CERT Perl Coding Standard - Guidelines 06. Object-Oriented Programming (OOP)
CWE-1185
SEI CERT Perl Coding Standard - Guidelines 07. File Input and Output (FIO)
CWE-1186
SEI CERT Perl Coding Standard - Guidelines 50. Miscellaneous (MSC)
CWE-1187
DEPRECATED: Use of Uninitialized Resource
CWE-1188
Initialization of a Resource with an Insecure Default
CWE-1189
Improper Isolation of Shared Resources on System-on-a-Chip (SoC)
CWE-1190
DMA Device Enabled Too Early in Boot Phase
CWE-1191
On-Chip Debug and Test Interface With Improper Access Control
CWE-1192
Improper Identifier for IP Block used in System-On-Chip (SOC)
CWE-1193
Power-On of Untrusted Execution Core Before Enabling Fabric Access Control
CWE-1194
Hardware Design
CWE-1195
Manufacturing and Life Cycle Management Concerns
CWE-1196
Security Flow Issues
CWE-1197
Integration Issues
CWE-1198
Privilege Separation and Access Control Issues
CWE-1199
General Circuit and Logic Design Concerns
CWE-12
ASP.NET Misconfiguration: Missing Custom Error Page
CWE-1200
Weaknesses in the 2019 CWE Top 25 Most Dangerous Software Errors
CWE-1201
Core and Compute Issues
CWE-1202
Memory and Storage Issues
CWE-1203
Peripherals, On-chip Fabric, and Interface/IO Problems
CWE-1204
Generation of Weak Initialization Vector (IV)
CWE-1205
Security Primitives and Cryptography Issues
CWE-1206
Power, Clock, Thermal, and Reset Concerns
CWE-1207
Debug and Test Problems
CWE-1208
Cross-Cutting Problems
CWE-1209
Failure to Disable Reserved Bits
CWE-1210
Audit / Logging Errors
CWE-1211
Authentication Errors
CWE-1212
Authorization Errors
CWE-1213
Random Number Issues
CWE-1214
Data Integrity Issues
CWE-1215
Data Validation Issues
CWE-1216
Lockout Mechanism Errors
CWE-1217
User Session Errors
CWE-1218
Memory Buffer Errors
CWE-1219
File Handling Issues
CWE-1221
Incorrect Register Defaults or Module Parameters
CWE-1222
Insufficient Granularity of Address Regions Protected by Register Locks
CWE-1223
Race Condition for Write-Once Attributes
CWE-1224
Improper Restriction of Write-Once Bit Fields
CWE-1225
Documentation Issues
CWE-1226
Complexity Issues
CWE-1227
Encapsulation Issues
CWE-1228
API / Function Errors
CWE-1229
Creation of Emergent Resource
CWE-123
Write-what-where Condition
CWE-1230
Exposure of Sensitive Information Through Metadata
CWE-1231
Improper Prevention of Lock Bit Modification
CWE-1232
Improper Lock Behavior After Power State Transition
CWE-1233
Security-Sensitive Hardware Controls with Missing Lock Bit Protection
CWE-1234
Hardware Internal or Debug Modes Allow Override of Locks
CWE-1235
Incorrect Use of Autoboxing and Unboxing for Performance Critical Operations
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
CWE-1237
SFP Primary Cluster: Faulty Resource Release
CWE-1238
SFP Primary Cluster: Failure to Release Memory
CWE-1239
Improper Zeroization of Hardware Register
CWE-1241
Use of Predictable Algorithm in Random Number Generator
CWE-1242
Inclusion of Undocumented Features or Chicken Bits
CWE-1243
Sensitive Non-Volatile Information Not Protected During Debug
CWE-1244
Internal Asset Exposed to Unsafe Debug Access Level or State
CWE-1245
Improper Finite State Machines (FSMs) in Hardware Logic
CWE-1246
Improper Write Handling in Limited-write Non-Volatile Memories
CWE-1247
Improper Protection Against Voltage and Clock Glitches
CWE-1248
Semiconductor Defects in Hardware Logic with Security-Sensitive Implications
CWE-1249
Application-Level Admin Tool with Inconsistent View of Underlying Operating System
CWE-1250
Improper Preservation of Consistency Between Independent Representations of Shared State
CWE-1251
Mirrored Regions with Different Values
CWE-1252
CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations
CWE-1253
Incorrect Selection of Fuse Values
CWE-1254
Incorrect Comparison Logic Granularity
CWE-1255
Comparison Logic is Vulnerable to Power Side-Channel Attacks
CWE-1256
Improper Restriction of Software Interfaces to Hardware Features
CWE-1257
Improper Access Control Applied to Mirrored or Aliased Memory Regions
CWE-1258
Exposure of Sensitive System Information Due to Uncleared Debug Information
CWE-1260
Improper Handling of Overlap Between Protected Memory Ranges
CWE-1261
Improper Handling of Single Event Upsets
CWE-1262
Improper Access Control for Register Interface
CWE-1263
Improper Physical Access Control
CWE-1264
Hardware Logic with Insecure De-Synchronization between Control and Data Channels
CWE-1265
Unintended Reentrant Invocation of Non-reentrant Code Via Nested Calls
CWE-1266
Improper Scrubbing of Sensitive Data from Decommissioned Device
CWE-1267
Policy Uses Obsolete Encoding
CWE-1268
Policy Privileges are not Assigned Consistently Between Control and Data Agents
CWE-1269
Product Released in Non-Release Configuration
CWE-127
Buffer Under-read
CWE-1270
Generation of Incorrect Security Tokens
CWE-1271
Uninitialized Value on Reset for Registers Holding Security Settings
CWE-1272
Sensitive Information Uncleared Before Debug/Power State Transition
CWE-1273
Device Unlock Credential Sharing
CWE-1274
Improper Access Control for Volatile Memory Containing Boot Code
CWE-1275
Sensitive Cookie with Improper SameSite Attribute
CWE-1276
Hardware Child Block Incorrectly Connected to Parent System
CWE-1277
Firmware Not Updateable
CWE-1278
Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques
CWE-1279
Cryptographic Operations are run Before Supporting Units are Ready
CWE-1280
Access Control Check Implemented After Asset is Accessed
CWE-1281
Sequence of Processor Instructions Leads to Unexpected Behavior
CWE-1282
Assumed-Immutable Data is Stored in Writable Memory
CWE-1283
Mutable Attestation or Measurement Reporting Data
CWE-1285
Improper Validation of Specified Index, Position, or Offset in Input
CWE-1288
Improper Validation of Consistency within Input
CWE-1290
Incorrect Decoding of Security Identifiers
CWE-1291
Public Key Re-Use for Signing both Debug and Production Code
CWE-1292
Incorrect Conversion of Security Identifiers
CWE-1293
Missing Source Correlation of Multiple Independent Data
CWE-1294
Insecure Security Identifier Mechanism
CWE-1295
Debug Messages Revealing Unnecessary Information
CWE-1296
Incorrect Chaining or Granularity of Debug Components
CWE-1297
Unprotected Confidential Information on Device is Accessible by OSAT Vendors
CWE-1298
Hardware Logic Contains Race Conditions
CWE-1299
Missing Protection Mechanism for Alternate Hardware Interface
CWE-13
ASP.NET Misconfiguration: Password in Configuration File
CWE-1300
Improper Protection of Physical Side Channels
CWE-1301
Insufficient or Incomplete Data Removal within Hardware Component
CWE-1302
Missing Source Identifier in Entity Transactions on a System-On-Chip (SOC)
CWE-1303
Non-Transparent Sharing of Microarchitectural Resources
CWE-1304
Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation
CWE-1305
CISQ Quality Measures (2020)
CWE-1306
CISQ Quality Measures - Reliability
CWE-1307
CISQ Quality Measures - Maintainability
CWE-1308
CISQ Quality Measures - Security
CWE-1309
CISQ Quality Measures - Efficiency
CWE-1310
Missing Ability to Patch ROM Code
CWE-1311
Improper Translation of Security Attributes by Fabric Bridge
CWE-1312
Missing Protection for Mirrored Regions in On-Chip Fabric Firewall
CWE-1313
Hardware Allows Activation of Test or Debug Logic at Runtime
CWE-1314
Missing Write Protection for Parametric Data Values
CWE-1315
Improper Setting of Bus Controlling Capability in Fabric End-point
CWE-1316
Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges
CWE-1317
Improper Access Control in Fabric Bridge
CWE-1318
Missing Support for Security Features in On-chip Fabrics or Buses
CWE-1319
Improper Protection against Electromagnetic Fault Injection (EM-FI)
CWE-132
DEPRECATED: Miscalculated Null Termination
CWE-1320
Improper Protection for Outbound Error Messages and Alert Signals
CWE-1322
Use of Blocking Code in Single-threaded, Non-blocking Context
CWE-1323
Improper Management of Sensitive Trace Data
CWE-1324
DEPRECATED: Sensitive Information Accessible by Physical Probing of JTAG Interface
CWE-1326
Missing Immutable Root of Trust in Hardware
CWE-1327
Binding to an Unrestricted IP Address
CWE-1328
Security Version Number Mutable to Older Versions
CWE-1329
Reliance on Component That is Not Updateable
CWE-133
String Errors
CWE-1330
Remanent Data Readable after Memory Erase
CWE-1331
Improper Isolation of Shared Resources in Network On Chip (NoC)
CWE-1332
Improper Handling of Faults that Lead to Instruction Skips
CWE-1334
Unauthorized Error Injection Can Degrade Hardware Redundancy
CWE-1335
Incorrect Bitwise Shift of Integer
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
CWE-1337
Weaknesses in the 2021 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1338
Improper Protections Against Hardware Overheating
CWE-1339
Insufficient Precision or Accuracy of a Real Number
CWE-1340
CISQ Data Protection Measures
CWE-1341
Multiple Releases of Same Resource or Handle
CWE-1342
Information Exposure through Microarchitectural State after Transient Execution
CWE-1343
Weaknesses in the 2021 CWE Most Important Hardware Weaknesses List
CWE-1344
Weaknesses in OWASP Top Ten (2021)
CWE-1345
OWASP Top Ten 2021 Category A01:2021 - Broken Access Control
CWE-1346
OWASP Top Ten 2021 Category A02:2021 - Cryptographic Failures
CWE-1347
OWASP Top Ten 2021 Category A03:2021 - Injection
CWE-1348
OWASP Top Ten 2021 Category A04:2021 - Insecure Design
CWE-1349
OWASP Top Ten 2021 Category A05:2021 - Security Misconfiguration
CWE-1350
Weaknesses in the 2020 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1351
Improper Handling of Hardware Behavior in Exceptionally Cold Environments
CWE-1352
OWASP Top Ten 2021 Category A06:2021 - Vulnerable and Outdated Components
CWE-1353
OWASP Top Ten 2021 Category A07:2021 - Identification and Authentication Failures
CWE-1354
OWASP Top Ten 2021 Category A08:2021 - Software and Data Integrity Failures
CWE-1355
OWASP Top Ten 2021 Category A09:2021 - Security Logging and Monitoring Failures
CWE-1356
OWASP Top Ten 2021 Category A10:2021 - Server-Side Request Forgery (SSRF)
CWE-1357
Reliance on Insufficiently Trustworthy Component
CWE-1358
Weaknesses in SEI ETF Categories of Security Vulnerabilities in ICS
CWE-1359
ICS Communications
CWE-136
Type Errors
CWE-1360
ICS Dependencies (& Architecture)
CWE-1361
ICS Supply Chain
CWE-1362
ICS Engineering (Constructions/Deployment)
CWE-1363
ICS Operations (& Maintenance)
CWE-1364
ICS Communications: Zone Boundary Failures
CWE-1365
ICS Communications: Unreliability
CWE-1366
ICS Communications: Frail Security in Protocols
CWE-1367
ICS Dependencies (& Architecture): External Physical Systems
CWE-1368
ICS Dependencies (& Architecture): External Digital Systems
CWE-1369
ICS Supply Chain: IT/OT Convergence/Expansion
CWE-137
Data Neutralization Issues
CWE-1370
ICS Supply Chain: Common Mode Frailties
CWE-1371
ICS Supply Chain: Poorly Documented or Undocumented Features
CWE-1372
ICS Supply Chain: OT Counterfeit and Malicious Corruption
CWE-1373
ICS Engineering (Construction/Deployment): Trust Model Problems
CWE-1374
ICS Engineering (Construction/Deployment): Maker Breaker Blindness
CWE-1375
ICS Engineering (Construction/Deployment): Gaps in Details/Data
CWE-1376
ICS Engineering (Construction/Deployment): Security Gaps in Commissioning
CWE-1377
ICS Engineering (Construction/Deployment): Inherent Predictability in Design
CWE-1378
ICS Operations (& Maintenance): Gaps in obligations and training
CWE-1379
ICS Operations (& Maintenance): Human factors in ICS environments
CWE-138
Improper Neutralization of Special Elements
CWE-1380
ICS Operations (& Maintenance): Post-analysis changes
CWE-1381
ICS Operations (& Maintenance): Exploitable Standard Operational Procedures
CWE-1382
ICS Operations (& Maintenance): Emerging Energy Technologies
CWE-1383
ICS Operations (& Maintenance): Compliance/Conformance with Regulatory Requirements
CWE-1384
Improper Handling of Physical or Environmental Conditions
CWE-1386
Insecure Operation on Windows Junction / Mount Point
CWE-1387
Weaknesses in the 2022 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1388
Physical Access Issues and Concerns
CWE-1389
Incorrect Parsing of Numbers with Different Radices
CWE-139
DEPRECATED: General Special Element Problems
CWE-1390
Weak Authentication
CWE-1391
Use of Weak Credentials
CWE-1392
Use of Default Credentials
CWE-1393
Use of Default Password
CWE-1394
Use of Default Cryptographic Key
CWE-1395
Dependency on Vulnerable Third-Party Component
CWE-1396
Comprehensive Categorization: Access Control
CWE-1397
Comprehensive Categorization: Comparison
CWE-1398
Comprehensive Categorization: Component Interaction
CWE-1399
Comprehensive Categorization: Memory Safety
CWE-14
Compiler Removal of Code to Clear Buffers
CWE-1400
Comprehensive Categorization for Software Assurance Trends
CWE-1401
Comprehensive Categorization: Concurrency
CWE-1402
Comprehensive Categorization: Encryption
CWE-1403
Comprehensive Categorization: Exposed Resource
CWE-1404
Comprehensive Categorization: File Handling
CWE-1405
Comprehensive Categorization: Improper Check or Handling of Exceptional Conditions
CWE-1406
Comprehensive Categorization: Improper Input Validation
CWE-1407
Comprehensive Categorization: Improper Neutralization
CWE-1408
Comprehensive Categorization: Incorrect Calculation
CWE-1409
Comprehensive Categorization: Injection
CWE-1410
Comprehensive Categorization: Insufficient Control Flow Management
CWE-1411
Comprehensive Categorization: Insufficient Verification of Data Authenticity
CWE-1412
Comprehensive Categorization: Poor Coding Practices
CWE-1413
Comprehensive Categorization: Protection Mechanism Failure
CWE-1414
Comprehensive Categorization: Randomness
CWE-1415
Comprehensive Categorization: Resource Control
CWE-1416
Comprehensive Categorization: Resource Lifecycle Management
CWE-1417
Comprehensive Categorization: Sensitive Information Exposure
CWE-1418
Comprehensive Categorization: Violation of Secure Design Principles
CWE-1419
Incorrect Initialization of Resource
CWE-142
Improper Neutralization of Value Delimiters
CWE-1420
Exposure of Sensitive Information during Transient Execution
CWE-1421
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
CWE-1422
Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution
CWE-1423
Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution
CWE-1424
Weaknesses Addressed by ISA/IEC 62443 Requirements
CWE-1425
Weaknesses in the 2023 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1426
Improper Validation of Generative AI Output
CWE-1427
Improper Neutralization of Input Used for LLM Prompting
CWE-1428
Reliance on HTTP instead of HTTPS
CWE-1429
Missing Security-Relevant Feedback for Unexecuted Operations in Hardware Interface
CWE-143
Improper Neutralization of Record Delimiters
CWE-1430
Weaknesses in the 2024 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1431
Driving Intermediate Cryptographic State/Results to Hardware Module Outputs
CWE-1432
Weaknesses in the 2025 CWE Most Important Hardware Weaknesses List
CWE-1433
2025 MIHW Supplement: Expert Insights
CWE-1434
Insecure Setting of Generative AI/ML Model Inference Parameters
CWE-1435
Weaknesses in the 2025 CWE Top 25 Most Dangerous Software Weaknesses
CWE-1436
OWASP Top Ten 2025 Category A01:2025 - Broken Access Control
CWE-1437
OWASP Top Ten 2025 Category A02:2025 - Security Misconfiguration
CWE-1438
OWASP Top Ten 2025 Category A03:2025 - Software Supply Chain Failures
CWE-1439
OWASP Top Ten 2025 Category A04:2025 - Cryptographic Failures
CWE-1440
OWASP Top Ten 2025 Category A05:2025 - Injection
CWE-1441
OWASP Top Ten 2025 Category A06:2025 - Insecure Design
CWE-1442
OWASP Top Ten 2025 Category A07:2025 - Authentication Failures
CWE-1443
OWASP Top Ten 2025 Category A08:2025 - Software or Data Integrity Failures
CWE-1444
OWASP Top Ten 2025 Category A09:2025 - Logging & Alerting Failures
CWE-1445
OWASP Top Ten 2025 Category A10:2025 - Mishandling of Exceptional Conditions
CWE-1446
Weaknesses That are Specific to AI/ML Technology
CWE-1447
General Software Weaknesses that Appear in Products that Use or Support AI/ML Technology
CWE-1448
Weaknesses Related to AI/ML Products
CWE-145
Improper Neutralization of Section Delimiters
CWE-1450
Weaknesses in OWASP Top Ten RC1 (2025)
CWE-146
Improper Neutralization of Expression/Command Delimiters
CWE-147
Improper Neutralization of Input Terminators
CWE-148
Improper Neutralization of Input Leaders
CWE-149
Improper Neutralization of Quoting Syntax
CWE-15
External Control of System or Configuration Setting
CWE-151
Improper Neutralization of Comment Delimiters
CWE-152
Improper Neutralization of Macro Symbols
CWE-153
Improper Neutralization of Substitution Characters
CWE-154
Improper Neutralization of Variable Name Delimiters
CWE-155
Improper Neutralization of Wildcards or Matching Symbols
CWE-156
Improper Neutralization of Whitespace
CWE-157
Failure to Sanitize Paired Delimiters
CWE-158
Improper Neutralization of Null Byte or NUL Character
CWE-159
Improper Handling of Invalid Use of Special Elements
CWE-16
Configuration
CWE-160
Improper Neutralization of Leading Special Elements
CWE-161
Improper Neutralization of Multiple Leading Special Elements
CWE-162
Improper Neutralization of Trailing Special Elements
CWE-163
Improper Neutralization of Multiple Trailing Special Elements
CWE-164
Improper Neutralization of Internal Special Elements
CWE-165
Improper Neutralization of Multiple Internal Special Elements
CWE-166
Improper Handling of Missing Special Element
CWE-167
Improper Handling of Additional Special Element
CWE-168
Improper Handling of Inconsistent Special Elements
CWE-169
DEPRECATED: Technology-Specific Special Elements
CWE-170
Improper Null Termination
CWE-171
DEPRECATED: Cleansing, Canonicalization, and Comparison Errors
CWE-172
Encoding Error
CWE-173
Improper Handling of Alternate Encoding
CWE-174
Double Decoding of the Same Data
CWE-175
Improper Handling of Mixed Encoding
CWE-179
Incorrect Behavior Order: Early Validation
CWE-18
DEPRECATED: Source Code
CWE-181
Incorrect Behavior Order: Validate Before Filter
CWE-182
Collapse of Data into Unsafe Value
CWE-186
Overly Restrictive Regular Expression
CWE-188
Reliance on Data/Memory Layout
CWE-19
Data Processing Errors
CWE-192
Integer Coercion Error
CWE-194
Unexpected Sign Extension
CWE-195
Signed to Unsigned Conversion Error
CWE-196
Unsigned to Signed Conversion Error
CWE-197
Numeric Truncation Error
CWE-198
Use of Incorrect Byte Ordering
CWE-199
Information Management Errors
CWE-2
7PK - Environment
CWE-2000
Comprehensive CWE Dictionary
CWE-202
Exposure of Sensitive Information Through Data Queries
CWE-204
Observable Response Discrepancy
CWE-205
Observable Behavioral Discrepancy
CWE-206
Observable Internal Behavioral Discrepancy
CWE-207
Observable Behavioral Discrepancy With Equivalent Products
CWE-209
Generation of Error Message Containing Sensitive Information
CWE-21
DEPRECATED: Pathname Traversal and Equivalence Errors
CWE-210
Self-generated Error Message Containing Sensitive Information
CWE-211
Externally-Generated Error Message Containing Sensitive Information
CWE-213
Exposure of Sensitive Information Due to Incompatible Policies
CWE-214
Invocation of Process Using Visible Sensitive Information
CWE-215
Insertion of Sensitive Information Into Debugging Code
CWE-216
DEPRECATED: Containment Errors (Container Errors)
CWE-217
DEPRECATED: Failure to Protect Stored Data from Modification
CWE-218
DEPRECATED: Failure to provide confidentiality for stored data
CWE-220
Storage of File With Sensitive Data Under FTP Root
CWE-221
Information Loss or Omission
CWE-222
Truncation of Security-relevant Information
CWE-223
Omission of Security-relevant Information
CWE-224
Obscured Security-relevant Information by Alternate Name
CWE-225
DEPRECATED: General Information Management Problems
CWE-226
Sensitive Information in Resource Not Removed Before Reuse
CWE-227
7PK - API Abuse
CWE-228
Improper Handling of Syntactically Invalid Structure
CWE-229
Improper Handling of Values
CWE-230
Improper Handling of Missing Values
CWE-231
Improper Handling of Extra Values
CWE-232
Improper Handling of Undefined Values
CWE-233
Improper Handling of Parameters
CWE-234
Failure to Handle Missing Parameter
CWE-235
Improper Handling of Extra Parameters
CWE-236
Improper Handling of Undefined Parameters
CWE-237
Improper Handling of Structural Elements
CWE-238
Improper Handling of Incomplete Structural Elements
CWE-239
Failure to Handle Incomplete Element
CWE-240
Improper Handling of Inconsistent Structural Elements
CWE-241
Improper Handling of Unexpected Data Type
CWE-242
Use of Inherently Dangerous Function
CWE-243
Creation of chroot Jail Without Changing Working Directory
CWE-244
Improper Clearing of Heap Memory Before Release ('Heap Inspection')
CWE-245
J2EE Bad Practices: Direct Management of Connections
CWE-246
J2EE Bad Practices: Direct Use of Sockets
CWE-247
DEPRECATED: Reliance on DNS Lookups in a Security Decision
CWE-249
DEPRECATED: Often Misused: Path Manipulation
CWE-25
Path Traversal: '/../filedir'
CWE-250
Execution with Unnecessary Privileges
CWE-251
Often Misused: String Management
CWE-252
Unchecked Return Value
CWE-253
Incorrect Check of Function Return Value
CWE-255
Credentials Management Errors
CWE-256
Plaintext Storage of a Password
CWE-257
Storing Passwords in a Recoverable Format
CWE-258
Empty Password in Configuration File
CWE-259
Use of Hard-coded Password
CWE-26
Path Traversal: '/dir/../filename'
CWE-260
Password in Configuration File
CWE-261
Weak Encoding for Password
CWE-262
Not Using Password Aging
CWE-263
Password Aging with Long Expiration
CWE-265
Privilege Issues
CWE-267
Privilege Defined With Unsafe Actions
CWE-268
Privilege Chaining
CWE-27
Path Traversal: 'dir/../../filename'
CWE-270
Privilege Context Switching Error
CWE-271
Privilege Dropping / Lowering Errors
CWE-272
Least Privilege Violation
CWE-273
Improper Check for Dropped Privileges
CWE-274
Improper Handling of Insufficient Privileges
CWE-275
Permission Issues
CWE-277
Insecure Inherited Permissions
CWE-278
Insecure Preserved Inherited Permissions
CWE-279
Incorrect Execution-Assigned Permissions
CWE-28
Path Traversal: '..filedir'
CWE-280
Improper Handling of Insufficient Permissions or Privileges
CWE-282
Improper Ownership Management
CWE-283
Unverified Ownership
CWE-286
Incorrect User Management
CWE-288
Authentication Bypass Using an Alternate Path or Channel
CWE-29
Path Traversal: '..filename'
CWE-291
Reliance on IP Address for Authentication
CWE-292
DEPRECATED: Trusting Self-reported DNS Name
CWE-293
Using Referer Field for Authentication
CWE-294
Authentication Bypass by Capture-replay
CWE-296
Improper Following of a Certificate's Chain of Trust
CWE-297
Improper Validation of Certificate with Host Mismatch
CWE-298
Improper Validation of Certificate Expiration
CWE-299
Improper Check for Certificate Revocation
CWE-3
DEPRECATED: Technology-specific Environment Issues
CWE-30
Path Traversal: 'dir..filename'
CWE-301
Reflection Attack in an Authentication Protocol
CWE-302
Authentication Bypass by Assumed-Immutable Data
CWE-304
Missing Critical Step in Authentication
CWE-305
Authentication Bypass by Primary Weakness
CWE-307
Improper Restriction of Excessive Authentication Attempts
CWE-308
Use of Single-factor Authentication
CWE-309
Use of Password System for Primary Authentication
CWE-31
Path Traversal: 'dir....filename'
CWE-313
Cleartext Storage in a File or on Disk
CWE-314
Cleartext Storage in the Registry
CWE-315
Cleartext Storage of Sensitive Information in a Cookie
CWE-316
Cleartext Storage of Sensitive Information in Memory
CWE-317
Cleartext Storage of Sensitive Information in GUI
CWE-318
Cleartext Storage of Sensitive Information in Executable
CWE-32
Path Traversal: '...' (Triple Dot)
CWE-321
Use of Hard-coded Cryptographic Key
CWE-322
Key Exchange without Entity Authentication
CWE-324
Use of a Key Past its Expiration Date
CWE-328
Use of Weak Hash
CWE-33
Path Traversal: '....' (Multiple Dot)
CWE-332
Insufficient Entropy in PRNG
CWE-333
Improper Handling of Insufficient Entropy in TRNG
CWE-334
Small Space of Random Values
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
CWE-336
Same Seed in Pseudo-Random Number Generator (PRNG)
CWE-337
Predictable Seed in Pseudo-Random Number Generator (PRNG)
CWE-339
Small Seed Space in PRNG
CWE-34
Path Traversal: '....//'
CWE-340
Generation of Predictable Numbers or Identifiers
CWE-341
Predictable from Observable State
CWE-342
Predictable Exact Value from Previous Values
CWE-343
Predictable Value Range from Previous Values
CWE-344
Use of Invariant Value in Dynamically Changing Context
CWE-349
Acceptance of Extraneous Untrusted Data With Trusted Data
CWE-35
Path Traversal: '.../...//'
CWE-351
Insufficient Type Distinction
CWE-353
Missing Support for Integrity Check
CWE-355
User Interface Security Issues
CWE-356
Product UI does not Warn User of Unsafe Actions
CWE-357
Insufficient UI Warning of Dangerous Operations
CWE-358
Improperly Implemented Security Check for Standard
CWE-36
Absolute Path Traversal
CWE-360
Trust of System Event Data
CWE-361
7PK - Time and State
CWE-363
Race Condition Enabling Link Following
CWE-364
Signal Handler Race Condition
CWE-365
DEPRECATED: Race Condition in Switch
CWE-366
Race Condition within a Thread
CWE-368
Context Switching Race Condition
CWE-37
Path Traversal: '/absolute/pathname/here'
CWE-370
Missing Check for Certificate Revocation after Initial Check
CWE-371
State Issues
CWE-372
Incomplete Internal State Distinction
CWE-373
DEPRECATED: State Synchronization Error
CWE-374
Passing Mutable Objects to an Untrusted Method
CWE-375
Returning a Mutable Object to an Untrusted Caller
CWE-376
DEPRECATED: Temporary File Issues
CWE-379
Creation of Temporary File in Directory with Insecure Permissions
CWE-38
Path Traversal: 'absolutepathnamehere'
CWE-380
DEPRECATED: Technology-Specific Time and State Issues
CWE-381
DEPRECATED: J2EE Time and State Issues
CWE-382
J2EE Bad Practices: Use of System.exit()
CWE-383
J2EE Bad Practices: Direct Use of Threads
CWE-386
Symbolic Name not Mapping to Correct Object
CWE-387
Signal Errors
CWE-389
Error Conditions, Return Values, Status Codes
CWE-39
Path Traversal: 'C:dirname'
CWE-390
Detection of Error Condition Without Action
CWE-391
Unchecked Error Condition
CWE-392
Missing Report of Error Condition
CWE-393
Return of Wrong Status Code
CWE-394
Unexpected Status Code or Return Value
CWE-395
Use of NullPointerException Catch to Detect NULL Pointer Dereference
CWE-396
Declaration of Catch for Generic Exception
CWE-397
Declaration of Throws for Generic Exception
CWE-398
7PK - Code Quality
CWE-4
DEPRECATED: J2EE Environment Issues
CWE-40
Path Traversal: 'UNCsharename' (Windows UNC Share)
CWE-402
Transmission of Private Resources into a New Sphere ('Resource Leak')
CWE-403
Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')
CWE-404
Improper Resource Shutdown or Release
CWE-406
Insufficient Control of Network Message Volume (Network Amplification)
CWE-408
Incorrect Behavior Order: Early Amplification
CWE-41
Improper Resolution of Path Equivalence
CWE-410
Insufficient Resource Pool
CWE-411
Resource Locking Problems
CWE-412
Unrestricted Externally Accessible Lock
CWE-413
Improper Resource Locking
CWE-417
Communication Channel Errors
CWE-418
DEPRECATED: Channel Errors
CWE-419
Unprotected Primary Channel
CWE-42
Path Equivalence: 'filename.' (Trailing Dot)
CWE-420
Unprotected Alternate Channel
CWE-421
Race Condition During Access to Alternate Channel
CWE-422
Unprotected Windows Messaging Channel ('Shatter')
CWE-423
DEPRECATED: Proxied Trusted Channel
CWE-424
Improper Protection of Alternate Path
CWE-428
Unquoted Search Path or Element
CWE-429
Handler Errors
CWE-43
Path Equivalence: 'filename....' (Multiple Trailing Dot)
CWE-430
Deployment of Wrong Handler
CWE-431
Missing Handler
CWE-432
Dangerous Signal Handler not Disabled During Sensitive Operations
CWE-433
Unparsed Raw Web Content Delivery
CWE-435
Improper Interaction Between Multiple Correctly-Behaving Entities
CWE-437
Incomplete Model of Endpoint Features
CWE-438
Behavioral Problems
CWE-439
Behavioral Change in New Version or Environment
CWE-44
Path Equivalence: 'file.name' (Internal Dot)
CWE-442
DEPRECATED: Web Problems
CWE-443
DEPRECATED: HTTP response splitting
CWE-445
DEPRECATED: User Interface Errors
CWE-446
UI Discrepancy for Security Feature
CWE-447
Unimplemented or Unsupported Feature in UI
CWE-448
Obsolete Feature in UI
CWE-449
The UI Performs the Wrong Action
CWE-45
Path Equivalence: 'file...name' (Multiple Internal Dot)
CWE-450
Multiple Interpretations of UI Input
CWE-451
User Interface (UI) Misrepresentation of Critical Information
CWE-452
Initialization and Cleanup Errors
CWE-453
Insecure Default Variable Initialization
CWE-454
External Initialization of Trusted Variables or Data Stores
CWE-455
Non-exit on Failed Initialization
CWE-456
Missing Initialization of a Variable
CWE-458
DEPRECATED: Incorrect Initialization
CWE-46
Path Equivalence: 'filename ' (Trailing Space)
CWE-461
DEPRECATED: Data Structure Issues
CWE-462
Duplicate Key in Associative List (Alist)
CWE-463
Deletion of Data Structure Sentinel
CWE-464
Addition of Data Structure Sentinel
CWE-465
Pointer Issues
CWE-466
Return of Pointer Value Outside of Expected Range
CWE-467
Use of sizeof() on a Pointer Type
CWE-468
Incorrect Pointer Scaling
CWE-469
Use of Pointer Subtraction to Determine Size
CWE-47
Path Equivalence: ' filename' (Leading Space)
CWE-473
PHP External Variable Modification
CWE-474
Use of Function with Inconsistent Implementations
CWE-475
Undefined Behavior for Input to API
CWE-477
Use of Obsolete Function
CWE-478
Missing Default Case in Multiple Condition Expression
CWE-479
Signal Handler Use of a Non-reentrant Function
CWE-48
Path Equivalence: 'file name' (Internal Whitespace)
CWE-480
Use of Incorrect Operator
CWE-481
Assigning instead of Comparing
CWE-482
Comparing instead of Assigning
CWE-483
Incorrect Block Delimitation
CWE-484
Omitted Break Statement in Switch
CWE-485
7PK - Encapsulation
CWE-486
Comparison of Classes by Name
CWE-487
Reliance on Package-level Scope
CWE-488
Exposure of Data Element to Wrong Session
CWE-489
Active Debug Code
CWE-49
Path Equivalence: 'filename/' (Trailing Slash)
CWE-490
DEPRECATED: Mobile Code Issues
CWE-491
Public cloneable() Method Without Final ('Object Hijack')
CWE-492
Use of Inner Class Containing Sensitive Data
CWE-493
Critical Public Variable Without Final Modifier
CWE-495
Private Data Structure Returned From A Public Method
CWE-496
Public Data Assigned to Private Array-Typed Field
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CWE-498
Cloneable Class Containing Sensitive Information
CWE-499
Serializable Class Containing Sensitive Data
CWE-5
J2EE Misconfiguration: Data Transmission Without Encryption
CWE-500
Public Static Field Not Marked Final
CWE-501
Trust Boundary Violation
CWE-503
DEPRECATED: Byte/Object Code
CWE-504
DEPRECATED: Motivation/Intent
CWE-505
DEPRECATED: Intentionally Introduced Weakness
CWE-507
Trojan Horse
CWE-508
Non-Replicating Malicious Code
CWE-509
Replicating Malicious Code (Virus or Worm)
CWE-51
Path Equivalence: '/multiple//internal/slash'
CWE-510
Trapdoor
CWE-511
Logic/Time Bomb
CWE-512
Spyware
CWE-513
DEPRECATED: Intentionally Introduced Nonmalicious Weakness
CWE-515
Covert Storage Channel
CWE-516
DEPRECATED: Covert Timing Channel
CWE-517
DEPRECATED: Other Intentional, Nonmalicious Weakness
CWE-518
DEPRECATED: Inadvertently Introduced Weakness
CWE-519
DEPRECATED: .NET Environment Issues
CWE-52
Path Equivalence: '/multiple/trailing/slash//'
CWE-520
.NET Misconfiguration: Use of Impersonation
CWE-521
Weak Password Requirements
CWE-523
Unprotected Transport of Credentials
CWE-525
Use of Web Browser Cache Containing Sensitive Information
CWE-526
Cleartext Storage of Sensitive Information in an Environment Variable
CWE-527
Exposure of Version-Control Repository to an Unauthorized Control Sphere
CWE-528
Exposure of Core Dump File to an Unauthorized Control Sphere
CWE-529
Exposure of Access Control List Files to an Unauthorized Control Sphere
CWE-53
Path Equivalence: 'multipleinternalbackslash'
CWE-530
Exposure of Backup File to an Unauthorized Control Sphere
CWE-531
Inclusion of Sensitive Information in Test Code
CWE-533
DEPRECATED: Information Exposure Through Server Log Files
CWE-534
DEPRECATED: Information Exposure Through Debug Log Files
CWE-535
Exposure of Information Through Shell Error Message
CWE-536
Servlet Runtime Error Message Containing Sensitive Information
CWE-537
Java Runtime Error Message Containing Sensitive Information
CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
CWE-54
Path Equivalence: 'filedir' (Trailing Backslash)
CWE-540
Inclusion of Sensitive Information in Source Code
CWE-541
Inclusion of Sensitive Information in an Include File
CWE-542
DEPRECATED: Information Exposure Through Cleanup Log Files
CWE-543
Use of Singleton Pattern Without Synchronization in a Multithreaded Context
CWE-544
Missing Standardized Error Handling Mechanism
CWE-545
DEPRECATED: Use of Dynamic Class Loading
CWE-546
Suspicious Comment
CWE-547
Use of Hard-coded, Security-relevant Constants
CWE-548
Exposure of Information Through Directory Listing
CWE-549
Missing Password Field Masking
CWE-55
Path Equivalence: '/./' (Single Dot Directory)
CWE-550
Server-generated Error Message Containing Sensitive Information
CWE-553
Command Shell in Externally Accessible Directory
CWE-554
ASP.NET Misconfiguration: Not Using Input Validation Framework
CWE-555
J2EE Misconfiguration: Plaintext Password in Configuration File
CWE-556
ASP.NET Misconfiguration: Use of Identity Impersonation
CWE-557
Concurrency Issues
CWE-558
Use of getlogin() in Multithreaded Application
CWE-559
DEPRECATED: Often Misused: Arguments and Parameters
CWE-56
Path Equivalence: 'filedir*' (Wildcard)
CWE-560
Use of umask() with chmod-style Argument
CWE-561
Dead Code
CWE-562
Return of Stack Variable Address
CWE-563
Assignment to Variable without Use
CWE-564
SQL Injection: Hibernate
CWE-565
Reliance on Cookies without Validation and Integrity Checking
CWE-566
Authorization Bypass Through User-Controlled SQL Primary Key
CWE-567
Unsynchronized Access to Shared Data in a Multithreaded Context
CWE-568
finalize() Method Without super.finalize()
CWE-569
Expression Issues
CWE-57
Path Equivalence: 'fakedir/../realdir/filename'
CWE-570
Expression is Always False
CWE-571
Expression is Always True
CWE-572
Call to Thread run() instead of start()
CWE-573
Improper Following of Specification by Caller
CWE-574
EJB Bad Practices: Use of Synchronization Primitives
CWE-575
EJB Bad Practices: Use of AWT Swing
CWE-576
EJB Bad Practices: Use of Java I/O
CWE-577
EJB Bad Practices: Use of Sockets
CWE-578
EJB Bad Practices: Use of Class Loader
CWE-579
J2EE Bad Practices: Non-serializable Object Stored in Session
CWE-58
Path Equivalence: Windows 8.3 Filename
CWE-580
clone() Method Without super.clone()
CWE-581
Object Model Violation: Just One of Equals and Hashcode Defined
CWE-582
Array Declared Public, Final, and Static
CWE-583
finalize() Method Declared Public
CWE-584
Return Inside Finally Block
CWE-585
Empty Synchronized Block
CWE-586
Explicit Call to Finalize()
CWE-587
Assignment of a Fixed Address to a Pointer
CWE-588
Attempt to Access Child of a Non-structure Pointer
CWE-589
Call to Non-ubiquitous API
CWE-590
Free of Memory not on the Heap
CWE-591
Sensitive Data Storage in Improperly Locked Memory
CWE-592
DEPRECATED: Authentication Bypass Issues
CWE-593
Authentication Bypass: OpenSSL CTX Object Modified after SSL Objects are Created
CWE-594
J2EE Framework: Saving Unserializable Objects to Disk
CWE-595
Comparison of Object References Instead of Object Contents
CWE-596
DEPRECATED: Incorrect Semantic Object Comparison
CWE-597
Use of Wrong Operator in String Comparison
CWE-598
Use of HTTP Request With Sensitive Query String
CWE-6
J2EE Misconfiguration: Insufficient Session-ID Length
CWE-60
DEPRECATED: UNIX Path Link Problems
CWE-600
Uncaught Exception in Servlet
CWE-602
Client-Side Enforcement of Server-Side Security
CWE-603
Use of Client-Side Authentication
CWE-604
Deprecated Entries
CWE-605
Multiple Binds to the Same Port
CWE-607
Public Static Final Field References Mutable Object
CWE-608
Struts: Non-private Field in ActionForm Class
CWE-609
Double-Checked Locking
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
CWE-612
Improper Authorization of Index Containing Sensitive Information
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CWE-615
Inclusion of Sensitive Information in Source Code Comments
CWE-616
Incomplete Identification of Uploaded File Variables (PHP)
CWE-618
Exposed Unsafe ActiveX Method
CWE-619
Dangling Database Cursor ('Cursor Injection')
CWE-62
UNIX Hard Link
CWE-620
Unverified Password Change
CWE-621
Variable Extraction Error
CWE-622
Improper Validation of Function Hook Arguments
CWE-623
Unsafe ActiveX Control Marked Safe For Scripting
CWE-624
Executable Regular Expression Error
CWE-627
Dynamic Variable Evaluation
CWE-628
Function Call with Incorrectly Specified Arguments
CWE-629
Weaknesses in OWASP Top Ten (2007)
CWE-63
DEPRECATED: Windows Path Link Problems
CWE-630
DEPRECATED: Weaknesses Examined by SAMATE
CWE-631
DEPRECATED: Resource-specific Weaknesses
CWE-632
DEPRECATED: Weaknesses that Affect Files or Directories
CWE-633
DEPRECATED: Weaknesses that Affect Memory
CWE-634
DEPRECATED: Weaknesses that Affect System Processes
CWE-635
Weaknesses Originally Used by NVD from 2008 to 2016
CWE-636
Not Failing Securely ('Failing Open')
CWE-637
Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')
CWE-638
Not Using Complete Mediation
CWE-64
Windows Shortcut Following (.LNK)
CWE-641
Improper Restriction of Names for Files and Other Resources
CWE-642
External Control of Critical State Data
CWE-643
Improper Neutralization of Data within XPath Expressions ('XPath Injection')
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
CWE-645
Overly Restrictive Account Lockout Mechanism
CWE-646
Reliance on File Name or Extension of Externally-Supplied File
CWE-648
Incorrect Use of Privileged APIs
CWE-649
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking
CWE-65
Windows Hard Link
CWE-650
Trusting HTTP Permission Methods on the Server Side
CWE-651
Exposure of WSDL File Containing Sensitive Information
CWE-652
Improper Neutralization of Data within XQuery Expressions ('XQuery Injection')
CWE-653
Improper Isolation or Compartmentalization
CWE-654
Reliance on a Single Factor in a Security Decision
CWE-655
Insufficient Psychological Acceptability
CWE-656
Reliance on Security Through Obscurity
CWE-657
Violation of Secure Design Principles
CWE-658
Weaknesses in Software Written in C
CWE-659
Weaknesses in Software Written in C++
CWE-66
Improper Handling of File Names that Identify Virtual Resources
CWE-660
Weaknesses in Software Written in Java
CWE-661
Weaknesses in Software Written in PHP
CWE-663
Use of a Non-reentrant Function in a Concurrent Context
CWE-664
Improper Control of a Resource Through its Lifetime
CWE-666
Operation on Resource in Wrong Phase of Lifetime
CWE-671
Lack of Administrator Control over Security
CWE-673
External Influence of Sphere Definition
CWE-675
Multiple Operations on Resource in Single-Operation Context
CWE-676
Use of Potentially Dangerous Function
CWE-677
Weakness Base Elements
CWE-678
Composites
CWE-679
DEPRECATED: Chain Elements
CWE-68
DEPRECATED: Windows Virtual File Problems
CWE-682
Incorrect Calculation
CWE-683
Function Call With Incorrect Order of Arguments
CWE-685
Function Call With Incorrect Number of Arguments
CWE-686
Function Call With Incorrect Argument Type
CWE-687
Function Call With Incorrectly Specified Argument Value
CWE-688
Function Call With Incorrect Variable or Reference as Argument
CWE-689
Permission Race Condition During Resource Copy
CWE-69
Improper Handling of Windows ::DATA Alternate Data Stream
CWE-690
Unchecked Return Value to NULL Pointer Dereference
CWE-691
Insufficient Control Flow Management
CWE-692
Incomplete Denylist to Cross-Site Scripting
CWE-694
Use of Multiple Resources with Duplicate Identifier
CWE-695
Use of Low-Level Functionality
CWE-696
Incorrect Behavior Order
CWE-698
Execution After Redirect (EAR)
CWE-699
Software Development
CWE-7
J2EE Misconfiguration: Missing Custom Error Page
CWE-70
DEPRECATED: Mac Virtual File Problems
CWE-700
Seven Pernicious Kingdoms
CWE-701
Weaknesses Introduced During Design
CWE-702
Weaknesses Introduced During Implementation
CWE-705
Incorrect Control Flow Scoping
CWE-707
Improper Neutralization
CWE-708
Incorrect Ownership Assignment
CWE-709
Named Chains
CWE-71
DEPRECATED: Apple '.DS_Store'
CWE-710
Improper Adherence to Coding Standards
CWE-711
Weaknesses in OWASP Top Ten (2004)
CWE-712
OWASP Top Ten 2007 Category A1 - Cross Site Scripting (XSS)
CWE-713
OWASP Top Ten 2007 Category A2 - Injection Flaws
CWE-714
OWASP Top Ten 2007 Category A3 - Malicious File Execution
CWE-715
OWASP Top Ten 2007 Category A4 - Insecure Direct Object Reference
CWE-716
OWASP Top Ten 2007 Category A5 - Cross Site Request Forgery (CSRF)
CWE-717
OWASP Top Ten 2007 Category A6 - Information Leakage and Improper Error Handling
CWE-718
OWASP Top Ten 2007 Category A7 - Broken Authentication and Session Management
CWE-719
OWASP Top Ten 2007 Category A8 - Insecure Cryptographic Storage
CWE-72
Improper Handling of Apple HFS+ Alternate Data Stream Path
CWE-720
OWASP Top Ten 2007 Category A9 - Insecure Communications
CWE-721
OWASP Top Ten 2007 Category A10 - Failure to Restrict URL Access
CWE-722
OWASP Top Ten 2004 Category A1 - Unvalidated Input
CWE-723
OWASP Top Ten 2004 Category A2 - Broken Access Control
CWE-724
OWASP Top Ten 2004 Category A3 - Broken Authentication and Session Management
CWE-725
OWASP Top Ten 2004 Category A4 - Cross-Site Scripting (XSS) Flaws
CWE-726
OWASP Top Ten 2004 Category A5 - Buffer Overflows
CWE-727
OWASP Top Ten 2004 Category A6 - Injection Flaws
CWE-728
OWASP Top Ten 2004 Category A7 - Improper Error Handling
CWE-729
OWASP Top Ten 2004 Category A8 - Insecure Storage
CWE-73
External Control of File Name or Path
CWE-730
OWASP Top Ten 2004 Category A9 - Denial of Service
CWE-731
OWASP Top Ten 2004 Category A10 - Insecure Configuration Management
CWE-733
Compiler Optimization Removal or Modification of Security-critical Code
CWE-734
Weaknesses Addressed by the CERT C Secure Coding Standard (2008)
CWE-735
CERT C Secure Coding Standard (2008) Chapter 2 - Preprocessor (PRE)
CWE-736
CERT C Secure Coding Standard (2008) Chapter 3 - Declarations and Initialization (DCL)
CWE-737
CERT C Secure Coding Standard (2008) Chapter 4 - Expressions (EXP)
CWE-738
CERT C Secure Coding Standard (2008) Chapter 5 - Integers (INT)
CWE-739
CERT C Secure Coding Standard (2008) Chapter 6 - Floating Point (FLP)
CWE-740
CERT C Secure Coding Standard (2008) Chapter 7 - Arrays (ARR)
CWE-741
CERT C Secure Coding Standard (2008) Chapter 8 - Characters and Strings (STR)
CWE-742
CERT C Secure Coding Standard (2008) Chapter 9 - Memory Management (MEM)
CWE-743
CERT C Secure Coding Standard (2008) Chapter 10 - Input Output (FIO)
CWE-744
CERT C Secure Coding Standard (2008) Chapter 11 - Environment (ENV)
CWE-745
CERT C Secure Coding Standard (2008) Chapter 12 - Signals (SIG)
CWE-746
CERT C Secure Coding Standard (2008) Chapter 13 - Error Handling (ERR)
CWE-747
CERT C Secure Coding Standard (2008) Chapter 14 - Miscellaneous (MSC)
CWE-748
CERT C Secure Coding Standard (2008) Appendix - POSIX (POS)
CWE-75
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
CWE-750
Weaknesses in the 2009 CWE/SANS Top 25 Most Dangerous Programming Errors
CWE-751
2009 Top 25 - Insecure Interaction Between Components
CWE-752
2009 Top 25 - Risky Resource Management
CWE-753
2009 Top 25 - Porous Defenses
CWE-756
Missing Custom Error Page
CWE-758
Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
CWE-759
Use of a One-Way Hash without a Salt
CWE-76
Improper Neutralization of Equivalent Special Elements
CWE-760
Use of a One-Way Hash with a Predictable Salt
CWE-761
Free of Pointer not at Start of Buffer
CWE-762
Mismatched Memory Management Routines
CWE-763
Release of Invalid Pointer or Reference
CWE-764
Multiple Locks of a Critical Resource
CWE-765
Multiple Unlocks of a Critical Resource
CWE-766
Critical Data Element Declared Public
CWE-767
Access to Critical Private Variable via Public Method
CWE-768
Incorrect Short Circuit Evaluation
CWE-769
DEPRECATED: Uncontrolled File Descriptor Consumption
CWE-771
Missing Reference to Active Allocated Resource
CWE-773
Missing Reference to Active File Descriptor or Handle
CWE-774
Allocation of File Descriptors or Handles Without Limits or Throttling
CWE-775
Missing Release of File Descriptor or Handle after Effective Lifetime
CWE-777
Regular Expression without Anchors
CWE-778
Insufficient Logging
CWE-779
Logging of Excessive Data
CWE-780
Use of RSA Algorithm without OAEP
CWE-781
Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code
CWE-782
Exposed IOCTL with Insufficient Access Control
CWE-783
Operator Precedence Logic Error
CWE-784
Reliance on Cookies without Validation and Integrity Checking in a Security Decision
CWE-785
Use of Path Manipulation Function without Maximum-sized Buffer
CWE-788
Access of Memory Location After End of Buffer
CWE-790
Improper Filtering of Special Elements
CWE-791
Incomplete Filtering of Special Elements
CWE-792
Incomplete Filtering of One or More Instances of Special Elements
CWE-793
Only Filtering One Instance of a Special Element
CWE-794
Incomplete Filtering of Multiple Instances of Special Elements
CWE-795
Only Filtering Special Elements at a Specified Location
CWE-796
Only Filtering Special Elements Relative to a Marker
CWE-797
Only Filtering Special Elements at an Absolute Position
CWE-799
Improper Control of Interaction Frequency
CWE-8
J2EE Misconfiguration: Entity Bean Declared Remote
CWE-800
Weaknesses in the 2010 CWE/SANS Top 25 Most Dangerous Programming Errors
CWE-801
2010 Top 25 - Insecure Interaction Between Components
CWE-802
2010 Top 25 - Risky Resource Management
CWE-803
2010 Top 25 - Porous Defenses
CWE-804
Guessable CAPTCHA
CWE-806
Buffer Access Using Size of Source Buffer
CWE-808
2010 Top 25 - Weaknesses On the Cusp
CWE-809
Weaknesses in OWASP Top Ten (2010)
CWE-81
Improper Neutralization of Script in an Error Message Web Page
CWE-810
OWASP Top Ten 2010 Category A1 - Injection
CWE-811
OWASP Top Ten 2010 Category A2 - Cross-Site Scripting (XSS)
CWE-812
OWASP Top Ten 2010 Category A3 - Broken Authentication and Session Management
CWE-813
OWASP Top Ten 2010 Category A4 - Insecure Direct Object References
CWE-814
OWASP Top Ten 2010 Category A5 - Cross-Site Request Forgery(CSRF)
CWE-815
OWASP Top Ten 2010 Category A6 - Security Misconfiguration
CWE-816
OWASP Top Ten 2010 Category A7 - Insecure Cryptographic Storage
CWE-817
OWASP Top Ten 2010 Category A8 - Failure to Restrict URL Access
CWE-818
OWASP Top Ten 2010 Category A9 - Insufficient Transport Layer Protection
CWE-819
OWASP Top Ten 2010 Category A10 - Unvalidated Redirects and Forwards
CWE-82
Improper Neutralization of Script in Attributes of IMG Tags in a Web Page
CWE-820
Missing Synchronization
CWE-821
Incorrect Synchronization
CWE-822
Untrusted Pointer Dereference
CWE-826
Premature Release of Resource During Expected Lifetime
CWE-827
Improper Control of Document Type Definition
CWE-828
Signal Handler with Functionality that is not Asynchronous-Safe
CWE-83
Improper Neutralization of Script in Attributes in a Web Page
CWE-830
Inclusion of Web Functionality from an Untrusted Source
CWE-831
Signal Handler Function Associated with Multiple Signals
CWE-832
Unlock of a Resource that is not Locked
CWE-833
Deadlock
CWE-836
Use of Password Hash Instead of Password for Authentication
CWE-837
Improper Enforcement of a Single, Unique Action
CWE-838
Inappropriate Encoding for Output Context
CWE-839
Numeric Range Comparison Without Minimum Check
CWE-84
Improper Neutralization of Encoded URI Schemes in a Web Page
CWE-840
Business Logic Errors
CWE-841
Improper Enforcement of Behavioral Workflow
CWE-842
Placement of User into Incorrect Group
CWE-844
Weaknesses Addressed by The CERT Oracle Secure Coding Standard for Java (2011)
CWE-845
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 2 - Input Validation and Data Sanitization (IDS)
CWE-846
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 3 - Declarations and Initialization (DCL)
CWE-847
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 4 - Expressions (EXP)
CWE-848
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 5 - Numeric Types and Operations (NUM)
CWE-849
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 6 - Object Orientation (OBJ)
CWE-85
Doubled Character XSS Manipulations
CWE-850
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 7 - Methods (MET)
CWE-851
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 8 - Exceptional Behavior (ERR)
CWE-852
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 9 - Visibility and Atomicity (VNA)
CWE-853
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 10 - Locking (LCK)
CWE-854
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 11 - Thread APIs (THI)
CWE-855
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 12 - Thread Pools (TPS)
CWE-856
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 13 - Thread-Safety Miscellaneous (TSM)
CWE-857
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 14 - Input Output (FIO)
CWE-858
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 15 - Serialization (SER)
CWE-859
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 16 - Platform Security (SEC)
CWE-860
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 17 - Runtime Environment (ENV)
CWE-861
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 18 - Miscellaneous (MSC)
CWE-864
2011 Top 25 - Insecure Interaction Between Components
CWE-865
2011 Top 25 - Risky Resource Management
CWE-866
2011 Top 25 - Porous Defenses
CWE-867
2011 Top 25 - Weaknesses On the Cusp
CWE-868
Weaknesses Addressed by the SEI CERT C++ Coding Standard (2016 Version)
CWE-869
CERT C++ Secure Coding Section 01 - Preprocessor (PRE)
CWE-87
Improper Neutralization of Alternate XSS Syntax
CWE-870
CERT C++ Secure Coding Section 02 - Declarations and Initialization (DCL)
CWE-871
CERT C++ Secure Coding Section 03 - Expressions (EXP)
CWE-872
CERT C++ Secure Coding Section 04 - Integers (INT)
CWE-873
CERT C++ Secure Coding Section 05 - Floating Point Arithmetic (FLP)
CWE-874
CERT C++ Secure Coding Section 06 - Arrays and the STL (ARR)
CWE-875
CERT C++ Secure Coding Section 07 - Characters and Strings (STR)
CWE-876
CERT C++ Secure Coding Section 08 - Memory Management (MEM)
CWE-877
CERT C++ Secure Coding Section 09 - Input Output (FIO)
CWE-878
CERT C++ Secure Coding Section 10 - Environment (ENV)
CWE-879
CERT C++ Secure Coding Section 11 - Signals (SIG)
CWE-880
CERT C++ Secure Coding Section 12 - Exceptions and Error Handling (ERR)
CWE-881
CERT C++ Secure Coding Section 13 - Object Oriented Programming (OOP)
CWE-882
CERT C++ Secure Coding Section 14 - Concurrency (CON)
CWE-883
CERT C++ Secure Coding Section 49 - Miscellaneous (MSC)
CWE-884
CWE Cross-section
CWE-885
SFP Primary Cluster: Risky Values
CWE-886
SFP Primary Cluster: Unused entities
CWE-887
SFP Primary Cluster: API
CWE-888
Software Fault Pattern (SFP) Clusters
CWE-889
SFP Primary Cluster: Exception Management
CWE-890
SFP Primary Cluster: Memory Access
CWE-891
SFP Primary Cluster: Memory Management
CWE-892
SFP Primary Cluster: Resource Management
CWE-893
SFP Primary Cluster: Path Resolution
CWE-894
SFP Primary Cluster: Synchronization
CWE-895
SFP Primary Cluster: Information Leak
CWE-896
SFP Primary Cluster: Tainted Input
CWE-897
SFP Primary Cluster: Entry Points
CWE-898
SFP Primary Cluster: Authentication
CWE-899
SFP Primary Cluster: Access Control
CWE-9
J2EE Misconfiguration: Weak Access Permissions for EJB Methods
CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CWE-900
Weaknesses in the 2011 CWE/SANS Top 25 Most Dangerous Software Errors
CWE-901
SFP Primary Cluster: Privilege
CWE-902
SFP Primary Cluster: Channel
CWE-903
SFP Primary Cluster: Cryptography
CWE-904
SFP Primary Cluster: Malware
CWE-905
SFP Primary Cluster: Predictability
CWE-906
SFP Primary Cluster: UI
CWE-907
SFP Primary Cluster: Other
CWE-91
XML Injection (aka Blind XPath Injection)
CWE-910
Use of Expired File Descriptor
CWE-911
Improper Update of Reference Count
CWE-913
Improper Control of Dynamically-Managed Code Resources
CWE-914
Improper Control of Dynamically-Identified Variables
CWE-916
Use of Password Hash With Insufficient Computational Effort
CWE-919
Weaknesses in Mobile Applications
CWE-92
DEPRECATED: Improper Sanitization of Custom Special Characters
CWE-920
Improper Restriction of Power Consumption
CWE-921
Storage of Sensitive Data in a Mechanism without Access Control
CWE-923
Improper Restriction of Communication Channel to Intended Endpoints
CWE-925
Improper Verification of Intent by Broadcast Receiver
CWE-926
Improper Export of Android Application Components
CWE-927
Use of Implicit Intent for Sensitive Communication
CWE-928
Weaknesses in OWASP Top Ten (2013)
CWE-929
OWASP Top Ten 2013 Category A1 - Injection
CWE-930
OWASP Top Ten 2013 Category A2 - Broken Authentication and Session Management
CWE-931
OWASP Top Ten 2013 Category A3 - Cross-Site Scripting (XSS)
CWE-932
OWASP Top Ten 2013 Category A4 - Insecure Direct Object References
CWE-933
OWASP Top Ten 2013 Category A5 - Security Misconfiguration
CWE-934
OWASP Top Ten 2013 Category A6 - Sensitive Data Exposure
CWE-935
OWASP Top Ten 2013 Category A7 - Missing Function Level Access Control
CWE-936
OWASP Top Ten 2013 Category A8 - Cross-Site Request Forgery (CSRF)
CWE-937
OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities
CWE-938
OWASP Top Ten 2013 Category A10 - Unvalidated Redirects and Forwards
CWE-939
Improper Authorization in Handler for Custom URL Scheme
CWE-941
Incorrectly Specified Destination in a Communication Channel
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
CWE-944
SFP Secondary Cluster: Access Management
CWE-945
SFP Secondary Cluster: Insecure Resource Access
CWE-946
SFP Secondary Cluster: Insecure Resource Permissions
CWE-947
SFP Secondary Cluster: Authentication Bypass
CWE-948
SFP Secondary Cluster: Digital Certificate
CWE-949
SFP Secondary Cluster: Faulty Endpoint Authentication
CWE-950
SFP Secondary Cluster: Hardcoded Sensitive Data
CWE-951
SFP Secondary Cluster: Insecure Authentication Policy
CWE-952
SFP Secondary Cluster: Missing Authentication
CWE-953
SFP Secondary Cluster: Missing Endpoint Authentication
CWE-954
SFP Secondary Cluster: Multiple Binds to the Same Port
CWE-955
SFP Secondary Cluster: Unrestricted Authentication
CWE-956
SFP Secondary Cluster: Channel Attack
CWE-957
SFP Secondary Cluster: Protocol Error
CWE-958
SFP Secondary Cluster: Broken Cryptography
CWE-959
SFP Secondary Cluster: Weak Cryptography
CWE-96
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
CWE-960
SFP Secondary Cluster: Ambiguous Exception Type
CWE-961
SFP Secondary Cluster: Incorrect Exception Behavior
CWE-962
SFP Secondary Cluster: Unchecked Status Condition
CWE-963
SFP Secondary Cluster: Exposed Data
CWE-964
SFP Secondary Cluster: Exposure Temporary File
CWE-965
SFP Secondary Cluster: Insecure Session Management
CWE-966
SFP Secondary Cluster: Other Exposures
CWE-967
SFP Secondary Cluster: State Disclosure
CWE-968
SFP Secondary Cluster: Covert Channel
CWE-969
SFP Secondary Cluster: Faulty Memory Release
CWE-97
Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
CWE-970
SFP Secondary Cluster: Faulty Buffer Access
CWE-971
SFP Secondary Cluster: Faulty Pointer Use
CWE-972
SFP Secondary Cluster: Faulty String Expansion
CWE-973
SFP Secondary Cluster: Improper NULL Termination
CWE-974
SFP Secondary Cluster: Incorrect Buffer Length Computation
CWE-975
SFP Secondary Cluster: Architecture
CWE-976
SFP Secondary Cluster: Compiler
CWE-977
SFP Secondary Cluster: Design
CWE-978
SFP Secondary Cluster: Implementation
CWE-979
SFP Secondary Cluster: Failed Chroot Jail
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CWE-980
SFP Secondary Cluster: Link in Resource Name Resolution
CWE-981
SFP Secondary Cluster: Path Traversal
CWE-982
SFP Secondary Cluster: Failure to Release Resource
CWE-983
SFP Secondary Cluster: Faulty Resource Use
CWE-984
SFP Secondary Cluster: Life Cycle
CWE-985
SFP Secondary Cluster: Unrestricted Consumption
CWE-986
SFP Secondary Cluster: Missing Lock
CWE-987
SFP Secondary Cluster: Multiple Locks/Unlocks
CWE-988
SFP Secondary Cluster: Race Condition Window
CWE-989
SFP Secondary Cluster: Unrestricted Lock
CWE-99
Improper Control of Resource Identifiers ('Resource Injection')
CWE-990
SFP Secondary Cluster: Tainted Input to Command
CWE-991
SFP Secondary Cluster: Tainted Input to Environment
CWE-992
SFP Secondary Cluster: Faulty Input Transformation
CWE-993
SFP Secondary Cluster: Incorrect Input Handling
CWE-994
SFP Secondary Cluster: Tainted Input to Variable
CWE-995
SFP Secondary Cluster: Feature
CWE-996
SFP Secondary Cluster: Security
CWE-997
SFP Secondary Cluster: Information Loss
CWE-998
SFP Secondary Cluster: Glitch in Computation
CWE-999
DEPRECATED: Weaknesses without Software Fault Patterns