Search Common Weakness Enumerations (CWE) by number.
| CWE | Description | Websites |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 15,196,816 |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 2,740,642 |
| CWE-20 | Improper Input Validation | 2,751,763 |
| CWE-125 | Out-of-bounds Read | 5,946,357 |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 259,648 |
| CWE-416 | Use After Free | 681,047 |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 3,534,416 |
| CWE-352 | Cross-Site Request Forgery (CSRF) | 2,353,144 |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | 3,567,171 |
| CWE-862 | Missing Authorization | 5,357,357 |
| CWE-476 | NULL Pointer Dereference | 5,656,897 |
| CWE-287 | Improper Authentication | 2,309,544 |
| CWE-190 | Integer Overflow or Wraparound | 4,959,595 |
| CWE-502 | Deserialization of Untrusted Data | 540,100 |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | 5,398 |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | 154,809 |
| CWE-798 | Use of Hard-coded Credentials | 90 |
| CWE-918 | Server-Side Request Forgery (SSRF) | 4,300,042 |
| CWE-306 | Missing Authentication for Critical Function | 141,273 |
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | 31,256 |
| CWE-269 | Improper Privilege Management | 225,019 |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | 2,062,949 |
| CWE-863 | Incorrect Authorization | 1,606,566 |
| CWE-276 | Incorrect Default Permissions | 5,011 |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 3,406,169 |
| CWE | Description | Updated |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | Apr 13, 2026 |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Apr 13, 2026 |
| CWE-502 | Deserialization of Untrusted Data | Apr 13, 2026 |
| CWE-670 | Always-Incorrect Control Flow Implementation | Apr 12, 2026 |
| CWE-639 | Authorization Bypass Through User-Controlled Key | Apr 11, 2026 |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Apr 11, 2026 |
| CWE-918 | Server-Side Request Forgery (SSRF) | Apr 11, 2026 |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Apr 11, 2026 |
| CWE-269 | Improper Privilege Management | Apr 11, 2026 |
| CWE | Description | Websites |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 15,196,816 |
| CWE-125 | Out-of-bounds Read | 5,946,357 |
| CWE-476 | NULL Pointer Dereference | 5,656,897 |
| CWE-862 | Missing Authorization | 5,357,357 |
| CWE-190 | Integer Overflow or Wraparound | 4,959,595 |
| CWE-918 | Server-Side Request Forgery (SSRF) | 4,300,042 |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | 3,567,171 |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 3,534,416 |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 3,406,169 |
| CWE-639 | Authorization Bypass Through User-Controlled Key | 3,327,117 |