CVEbaza.pl › Słownik CWE
Słownik CWE
Common Weakness Enumeration — katalog typów podatności bezpieczeństwa. Każde CWE opisuje klasę błędów programistycznych które prowadzą do podatności CVE.
200 typów podatności · 374 091 powiązanych CVE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
53 074
CVE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
24 122
CVE
CWE-787
Out-of-bounds Write
17 120
CVE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
14 570
CVE
CWE-20
Improper Input Validation
14 201
CVE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
11 360
CVE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
11 173
CVE
CWE-125
Out-of-bounds Read
10 986
CVE
CWE-352
Cross-Site Request Forgery (CSRF)
10 811
CVE
CWE-862
Missing Authorization
10 330
CVE
CWE-416
Use After Free
9974
CVE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
7742
CVE
CWE-284
Improper Access Control
7452
CVE
CWE-94
Improper Control of Generation of Code ('Code Injection')
7409
CVE
CWE-476
NULL Pointer Dereference
6589
CVE
CWE-264
—
5495
CVE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
5354
CVE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
5352
CVE
CWE-287
Improper Authentication
5293
CVE
CWE-434
Unrestricted Upload of File with Dangerous Type
5184
CVE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
4395
CVE
CWE-863
Incorrect Authorization
4127
CVE
CWE-190
Integer Overflow or Wraparound
3988
CVE
CWE-400
Uncontrolled Resource Consumption
3960
CVE
CWE-918
Server-Side Request Forgery (SSRF)
3784
CVE
CWE-121
Stack-based Buffer Overflow
3709
CVE
CWE-502
Deserialization of Untrusted Data
3665
CVE
CWE-269
Improper Privilege Management
3571
CVE
CWE-306
Missing Authentication for Critical Function
3441
CVE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
2931
CVE
CWE-122
Heap-based Buffer Overflow
2810
CVE
CWE-639
Authorization Bypass Through User-Controlled Key
2710
CVE
CWE-399
—
2700
CVE
CWE-770
Allocation of Resources Without Limits or Throttling
2556
CVE
CWE-310
—
2527
CVE
CWE-401
Missing Release of Memory after Effective Lifetime
2290
CVE
CWE-798
Use of Hard-coded Credentials
2087
CVE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
1953
CVE
CWE-732
Incorrect Permission Assignment for Critical Resource
1942
CVE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
1882
CVE
CWE-276
Incorrect Default Permissions
1818
CVE
CWE-295
Improper Certificate Validation
1771
CVE
CWE-522
Insufficiently Protected Credentials
1643
CVE
CWE-611
Improper Restriction of XML External Entity Reference
1559
CVE
CWE-285
Improper Authorization
1556
CVE
CWE-427
Uncontrolled Search Path Element
1527
CVE
CWE-532
Insertion of Sensitive Information into Log File
1486
CVE
CWE-189
—
1250
CVE
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
1212
CVE
CWE-266
Incorrect Privilege Assignment
1102
CVE
CWE-319
Cleartext Transmission of Sensitive Information
1102
CVE
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
1093
CVE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
1052
CVE
CWE-415
Double Free
985
CVE
CWE-312
Cleartext Storage of Sensitive Information
979
CVE
CWE-908
Use of Uninitialized Resource
958
CVE
CWE-347
Improper Verification of Cryptographic Signature
953
CVE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
943
CVE
CWE-617
Reachable Assertion
925
CVE
CWE-203
Observable Discrepancy
890
CVE
CWE-404
Improper Resource Shutdown or Release
860
CVE
CWE-667
Improper Locking
857
CVE
CWE-345
Insufficient Verification of Data Authenticity
831
CVE
CWE-668
Exposure of Resource to Wrong Sphere
818
CVE
CWE-346
Origin Validation Error
816
CVE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
798
CVE
CWE-255
—
787
CVE
CWE-290
Authentication Bypass by Spoofing
787
CVE
CWE-754
Improper Check for Unusual or Exceptional Conditions
772
CVE
CWE-693
Protection Mechanism Failure
769
CVE
CWE-426
Untrusted Search Path
762
CVE
CWE-307
Improper Restriction of Excessive Authentication Attempts
761
CVE
CWE-129
Improper Validation of Array Index
751
CVE
CWE-209
Generation of Error Message Containing Sensitive Information
702
CVE
CWE-613
Insufficient Session Expiration
694
CVE
CWE-755
Improper Handling of Exceptional Conditions
687
CVE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
664
CVE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
649
CVE
CWE-191
Integer Underflow (Wrap or Wraparound)
624
CVE
CWE-1333
Inefficient Regular Expression Complexity
622
CVE
CWE-73
External Control of File Name or Path
608
CVE
CWE-552
Files or Directories Accessible to External Parties
590
CVE
CWE-674
Uncontrolled Recursion
585
CVE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
578
CVE
CWE-311
Missing Encryption of Sensitive Data
564
CVE
CWE-116
Improper Encoding or Escaping of Output
553
CVE
CWE-369
Divide By Zero
551
CVE
CWE-326
Inadequate Encryption Strength
536
CVE
CWE-772
Missing Release of Resource after Effective Lifetime
511
CVE
CWE-428
Unquoted Search Path or Element
509
CVE
CWE-384
Session Fixation
500
CVE
CWE-126
Buffer Over-read
499
CVE
CWE-23
Relative Path Traversal
489
CVE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
482
CVE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
481
CVE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
475
CVE
CWE-330
Use of Insufficiently Random Values
448
CVE
CWE-134
Use of Externally-Controlled Format String
448
CVE
CWE-1284
Improper Validation of Specified Quantity in Input
440
CVE
CWE-922
Insecure Storage of Sensitive Information
429
CVE
CWE-665
Improper Initialization
428
CVE
CWE-254
—
414
CVE
CWE-281
Improper Preservation of Permissions
405
CVE
CWE-201
Insertion of Sensitive Information Into Sent Data
396
CVE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
378
CVE
CWE-451
User Interface (UI) Misrepresentation of Critical Information
369
CVE
CWE-250
Execution with Unnecessary Privileges
362
CVE
CWE-1188
Initialization of a Resource with an Insecure Default
361
CVE
CWE-824
Access of Uninitialized Pointer
359
CVE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
355
CVE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
355
CVE
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
344
CVE
CWE-321
Use of Hard-coded Cryptographic Key
336
CVE
CWE-294
Authentication Bypass by Capture-replay
321
CVE
CWE-16
—
319
CVE
CWE-521
Weak Password Requirements
313
CVE
CWE-704
Incorrect Type Conversion or Cast
309
CVE
CWE-248
Uncaught Exception
272
CVE
CWE-494
Download of Code Without Integrity Check
272
CVE
CWE-425
Direct Request ('Forced Browsing')
272
CVE
CWE-193
Off-by-one Error
265
CVE
CWE-707
Improper Neutralization
257
CVE
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
257
CVE
CWE-131
Incorrect Calculation of Buffer Size
251
CVE
CWE-459
Incomplete Cleanup
249
CVE
CWE-457
Use of Uninitialized Variable
249
CVE
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
241
CVE
CWE-19
—
235
CVE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
232
CVE
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
229
CVE
CWE-822
Untrusted Pointer Dereference
228
CVE
CWE-789
Memory Allocation with Excessive Size Value
226
CVE
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
222
CVE
CWE-256
Plaintext Storage of a Password
222
CVE
CWE-252
Unchecked Return Value
215
CVE
CWE-354
Improper Validation of Integrity Check Value
208
CVE
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
202
CVE
CWE-259
Use of Hard-coded Password
201
CVE
CWE-697
Incorrect Comparison
198
CVE
CWE-749
Exposed Dangerous Method or Function
187
CVE
CWE-208
Observable Timing Discrepancy
184
CVE
CWE-184
Incomplete List of Disallowed Inputs
183
CVE
CWE-204
Observable Response Discrepancy
182
CVE
CWE-35
Path Traversal: '.../...//'
179
CVE
CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
178
CVE
CWE-670
Always-Incorrect Control Flow Implementation
175
CVE
CWE-602
Client-Side Enforcement of Server-Side Security
170
CVE
CWE-61
UNIX Symbolic Link (Symlink) Following
167
CVE
CWE-703
Improper Check or Handling of Exceptional Conditions
167
CVE
CWE-407
Inefficient Algorithmic Complexity
167
CVE
CWE-17
—
166
CVE
CWE-305
Authentication Bypass by Primary Weakness
165
CVE
CWE-91
XML Injection (aka Blind XPath Injection)
162
CVE
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
161
CVE
CWE-280
Improper Handling of Insufficient Permissions or Privileges
160
CVE
CWE-331
Insufficient Entropy
160
CVE
CWE-682
Incorrect Calculation
156
CVE
CWE-1287
Improper Validation of Specified Type of Input
155
CVE
CWE-436
Interpretation Conflict
154
CVE
CWE-472
External Control of Assumed-Immutable Web Parameter
152
CVE
CWE-681
Incorrect Conversion between Numeric Types
151
CVE
CWE-916
Use of Password Hash With Insufficient Computational Effort
149
CVE
CWE-788
Access of Memory Location After End of Buffer
147
CVE
CWE-706
Use of Incorrectly-Resolved Name or Reference
141
CVE
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
138
CVE
CWE-358
Improperly Implemented Security Check for Standard
136
CVE
CWE-36
Absolute Path Traversal
136
CVE
CWE-942
Permissive Cross-domain Security Policy with Untrusted Domains
126
CVE
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
124
CVE
CWE-834
Excessive Iteration
124
CVE
CWE-913
Improper Control of Dynamically-Managed Code Resources
121
CVE
CWE-24
Path Traversal: '../filedir'
118
CVE
CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
117
CVE
CWE-763
Release of Invalid Pointer or Reference
116
CVE
CWE-117
Improper Output Neutralization for Logs
114
CVE
CWE-275
—
114
CVE
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
114
CVE
CWE-178
Improper Handling of Case Sensitivity
112
CVE
CWE-130
Improper Handling of Length Parameter Inconsistency
112
CVE
CWE-1220
Insufficient Granularity of Access Control
111
CVE
CWE-669
Incorrect Resource Transfer Between Spheres
111
CVE
CWE-680
Integer Overflow to Buffer Overflow
110
CVE
CWE-1392
Use of Default Credentials
110
CVE
CWE-909
Missing Initialization of Resource
109
CVE
CWE-823
Use of Out-of-range Pointer Offset
105
CVE
CWE-377
Insecure Temporary File
105
CVE
CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
104
CVE
CWE-672
Operation on a Resource after Expiration or Release
102
CVE
CWE-303
Incorrect Implementation of Authentication Algorithm
102
CVE
CWE-506
Embedded Malicious Code
100
CVE
CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
100
CVE
CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
98
CVE
CWE-840
—
97
CVE
CWE-807
Reliance on Untrusted Inputs in a Security Decision
95
CVE
CWE-1286
Improper Validation of Syntactic Correctness of Input
94
CVE
CWE-320
—
93
CVE
CWE-620
Unverified Password Change
93
CVE
CWE-598
Use of HTTP Request With Sensitive Query String
92
CVE
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
92
CVE
CWE-825
Expired Pointer Dereference
91
CVE