Home › CWE weaknessesBrowse CVEs by CWE weakness type Every CVE stems from an underlying software weakness, classified by the Common Weakness Enumeration (CWE) — cross-site scripting, SQL injection, out-of-bounds writes, and hundreds more. Pick a weakness to see the CVEs that share it, ordered by CVSS severity.
Most common weaknesses CWE-79 — Cross-site Scripting (XSS) — 47,698 CVEsCWE-89 — SQL Injection — 18,908 CVEsCWE-787 — Out-of-bounds Write — 13,611 CVEsCWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer — 13,353 CVEsCWE-20 — Improper Input Validation — 12,488 CVEsCWE-200 — Exposure of Sensitive Information to an Unauthorized Actor — 10,393 CVEsCWE-22 — Path Traversal — 10,319 CVEsCWE-862 — Missing Authorization — 9,615 CVEsCWE-352 — Cross-Site Request Forgery (CSRF) — 9,458 CVEsCWE-125 — Out-of-bounds Read — 9,427 CVEsCWE-416 — Use After Free — 8,197 CVEsCWE-284 — Improper Access Control — 6,666 CVEsCWE-78 — OS Command Injection — 6,243 CVEsCWE-94 — Code Injection — 5,508 CVEsCWE-476 — NULL Pointer Dereference — 5,434 CVEsCWE-264 — Permissions, Privileges, and Access Controls — 5,243 CVEsCWE-287 — Improper Authentication — 4,661 CVEsCWE-434 — Unrestricted Upload of File with Dangerous Type — 3,975 CVEsCWE-74 — Improper Neutralization of Special Elements (Injection) — 3,689 CVEsCWE-120 — Classic Buffer Overflow — 3,657 CVEsCWE-863 — Incorrect Authorization — 3,649 CVEsCWE-918 — Server-Side Request Forgery (SSRF) — 3,470 CVEsCWE-269 — Improper Privilege Management — 3,369 CVEsCWE-400 — Uncontrolled Resource Consumption — 3,321 CVEsCWE-190 — Integer Overflow or Wraparound — 3,261 CVEsCWE-77 — Command Injection — 3,176 CVEsCWE-502 — Deserialization of Untrusted Data — 3,104 CVEsCWE-306 — Missing Authentication for Critical Function — 2,856 CVEsCWE-362 — Race Condition — 2,575 CVEsCWE-639 — Authorization Bypass Through User-Controlled Key (IDOR) — 2,573 CVEsCWE-399 — Resource Management Errors — 2,558 CVEsCWE-310 — Cryptographic Issues — 2,443 CVEsCWE-122 — Heap-based Buffer Overflow — 2,187 CVEsCWE-770 — Allocation of Resources Without Limits or Throttling — 2,180 CVEsCWE-401 — Missing Release of Memory after Effective Lifetime — 1,917 CVEsCWE-121 — Stack-based Buffer Overflow — 1,768 CVEsCWE-798 — Use of Hard-coded Credentials — 1,708 CVEsCWE-59 — Improper Link Resolution Before File Access (Link Following) — 1,671 CVEsCWE-601 — Open Redirect — 1,642 CVEsCWE-732 — Incorrect Permission Assignment for Critical Resource — 1,614 CVEsCWE-295 — Improper Certificate Validation — 1,576 CVEsCWE-276 — Incorrect Default Permissions — 1,490 CVEsCWE-522 — Insufficiently Protected Credentials — 1,316 CVEsCWE-611 — Improper Restriction of XML External Entity Reference (XXE) — 1,302 CVEsCWE-98 — PHP Remote File Inclusion — 1,266 CVEsCWE-189 — Numeric Errors — 1,237 CVEsCWE-532 — Insertion of Sensitive Information into Log File — 1,192 CVEsCWE-427 — Uncontrolled Search Path Element — 1,162 CVEsCWE-266 — Incorrect Privilege Assignment — 1,113 CVEsCWE-285 — Improper Authorization — 1,083 CVEsCWE-319 — Cleartext Transmission of Sensitive Information — 885 CVEsCWE-835 — Loop with Unreachable Exit Condition (Infinite Loop) — 872 CVEsCWE-415 — Double Free — 853 CVEsCWE-908 — Use of Uninitialized Resource — 829 CVEsCWE-312 — Cleartext Storage of Sensitive Information — 810 CVEsCWE-617 — Reachable Assertion — 809 CVEsCWE-347 — Improper Verification of Cryptographic Signature — 801 CVEsCWE-843 — 779 CVEsCWE-203 — Observable Discrepancy — 770 CVEsCWE-367 — Time-of-check Time-of-use (TOCTOU) Race Condition — 748 CVEsCWE-255 — Credentials Management Errors — 727 CVEsCWE-693 — Protection Mechanism Failure — 725 CVEsCWE-290 — 719 CVEsCWE-345 — Insufficient Verification of Data Authenticity — 708 CVEsCWE-346 — 708 CVEsCWE-667 — Improper Locking — 691 CVEsCWE-668 — Exposure of Resource to Wrong Sphere — 685 CVEsCWE-404 — 677 CVEsCWE-426 — Untrusted Search Path — 663 CVEsCWE-327 — Use of a Broken or Risky Cryptographic Algorithm — 656 CVEsCWE-307 — Improper Restriction of Excessive Authentication Attempts — 646 CVEsCWE-129 — Improper Validation of Array Index — 615 CVEsCWE-613 — Insufficient Session Expiration — 610 CVEsCWE-209 — Generation of Error Message Containing Sensitive Information — 583 CVEsCWE-754 — Improper Check for Unusual or Exceptional Conditions — 583 CVEsCWE-755 — Improper Handling of Exceptional Conditions — 542 CVEsCWE-1321 — Prototype Pollution — 536 CVEsCWE-674 — Uncontrolled Recursion — 525 CVEsCWE-288 — 522 CVEsCWE-73 — 490 CVEsCWE-191 — Integer Underflow — 481 CVEsCWE-369 — Divide By Zero — 465 CVEsCWE-772 — 464 CVEsCWE-1333 — 456 CVEsCWE-428 — 444 CVEsCWE-552 — Files or Directories Accessible to External Parties — 440 CVEsCWE-326 — Inadequate Encryption Strength — 438 CVEsCWE-384 — Session Fixation — 419 CVEsCWE-88 — Argument Injection — 416 CVEsCWE-134 — 407 CVEsCWE-1021 — 405 CVEsCWE-444 — HTTP Request/Response Smuggling — 405 CVEsCWE-201 — 399 CVEsCWE-497 — 384 CVEsCWE-254 — 380 CVEsCWE-116 — 368 CVEsCWE-330 — Use of Insufficiently Random Values — 367 CVEsCWE-451 — 367 CVEsCWE-1284 — Improper Validation of Specified Quantity in Input — 348 CVEsCWE-311 — Missing Encryption of Sensitive Data — 330 CVEsCWE-665 — Improper Initialization — 329 CVEsCWE-281 — Improper Preservation of Permissions — 323 CVEsCWE-1236 — Improper Neutralization of Formula Elements in a CSV File — 304 CVEsCWE-126 — Buffer Over-read — 298 CVEsCWE-922 — 298 CVEsCWE-250 — 295 CVEsCWE-23 — 294 CVEsCWE-16 — 289 CVEsCWE-640 — 286 CVEsCWE-80 — 279 CVEsCWE-1188 — Insecure Default Initialization of Resource — 272 CVEsCWE-824 — 272 CVEsCWE-704 — Incorrect Type Conversion or Cast — 263 CVEsCWE-294 — Authentication Bypass by Capture-replay — 262 CVEsCWE-829 — 258 CVEsCWE-248 — 254 CVEsCWE-521 — Weak Password Requirements — 244 CVEsCWE-19 — 230 CVEsCWE-321 — 228 CVEsCWE-425 — 227 CVEs