Home › CWE weaknessesBrowse CVEs by CWE weakness type Every CVE stems from an underlying software weakness, classified by the Common Weakness Enumeration (CWE) — cross-site scripting, SQL injection, out-of-bounds writes, and hundreds more. Pick a weakness to see the CVEs that share it, ordered by CVSS severity.
Most common weaknesses CWE-79 — Cross-site Scripting (XSS) — 46,115 CVEsCWE-89 — SQL Injection — 18,449 CVEsCWE-787 — Out-of-bounds Write — 13,275 CVEsCWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer — 13,152 CVEsCWE-20 — Improper Input Validation — 12,123 CVEsCWE-200 — Exposure of Sensitive Information to an Unauthorized Actor — 9,887 CVEsCWE-22 — Path Traversal — 9,717 CVEsCWE-352 — Cross-Site Request Forgery (CSRF) — 9,291 CVEsCWE-125 — Out-of-bounds Read — 8,975 CVEsCWE-862 — Missing Authorization — 8,662 CVEsCWE-416 — Use After Free — 7,647 CVEsCWE-78 — OS Command Injection — 5,848 CVEsCWE-284 — Improper Access Control — 5,628 CVEsCWE-476 — NULL Pointer Dereference — 5,314 CVEsCWE-94 — Code Injection — 5,260 CVEsCWE-264 — Permissions, Privileges, and Access Controls — 5,234 CVEsCWE-287 — Improper Authentication — 4,330 CVEsCWE-434 — Unrestricted Upload of File with Dangerous Type — 3,863 CVEsCWE-120 — Classic Buffer Overflow — 3,559 CVEsCWE-74 — Improper Neutralization of Special Elements (Injection) — 3,308 CVEsCWE-863 — Incorrect Authorization — 3,138 CVEsCWE-190 — Integer Overflow or Wraparound — 3,109 CVEsCWE-77 — Command Injection — 3,063 CVEsCWE-918 — Server-Side Request Forgery (SSRF) — 3,019 CVEsCWE-400 — Uncontrolled Resource Consumption — 2,979 CVEsCWE-269 — Improper Privilege Management — 2,967 CVEsCWE-502 — Deserialization of Untrusted Data — 2,872 CVEsCWE-306 — Missing Authentication for Critical Function — 2,562 CVEsCWE-399 — Resource Management Errors — 2,558 CVEsCWE-362 — Race Condition — 2,450 CVEsCWE-310 — Cryptographic Issues — 2,435 CVEsCWE-639 — Authorization Bypass Through User-Controlled Key (IDOR) — 2,099 CVEsCWE-770 — Allocation of Resources Without Limits or Throttling — 1,937 CVEsCWE-401 — Missing Release of Memory after Effective Lifetime — 1,862 CVEsCWE-122 — Heap-based Buffer Overflow — 1,719 CVEsCWE-798 — Use of Hard-coded Credentials — 1,649 CVEsCWE-121 — Stack-based Buffer Overflow — 1,609 CVEsCWE-59 — Improper Link Resolution Before File Access (Link Following) — 1,601 CVEsCWE-732 — Incorrect Permission Assignment for Critical Resource — 1,575 CVEsCWE-601 — Open Redirect — 1,556 CVEsCWE-276 — Incorrect Default Permissions — 1,471 CVEsCWE-295 — Improper Certificate Validation — 1,460 CVEsCWE-522 — Insufficiently Protected Credentials — 1,262 CVEsCWE-611 — Improper Restriction of XML External Entity Reference (XXE) — 1,257 CVEsCWE-98 — PHP Remote File Inclusion — 1,240 CVEsCWE-189 — Numeric Errors — 1,216 CVEsCWE-427 — Uncontrolled Search Path Element — 1,145 CVEsCWE-532 — Insertion of Sensitive Information into Log File — 1,126 CVEsCWE-266 — Incorrect Privilege Assignment — 983 CVEsCWE-285 — Improper Authorization — 953 CVEsCWE-319 — Cleartext Transmission of Sensitive Information — 842 CVEsCWE-835 — Loop with Unreachable Exit Condition (Infinite Loop) — 830 CVEsCWE-415 — Double Free — 801 CVEsCWE-312 — Cleartext Storage of Sensitive Information — 786 CVEsCWE-908 — Use of Uninitialized Resource — 762 CVEsCWE-617 — Reachable Assertion — 758 CVEsCWE-203 — Observable Discrepancy — 728 CVEsCWE-255 — Credentials Management Errors — 726 CVEsCWE-347 — Improper Verification of Cryptographic Signature — 714 CVEsCWE-843 — 708 CVEsCWE-667 — Improper Locking — 679 CVEsCWE-668 — Exposure of Resource to Wrong Sphere — 673 CVEsCWE-367 — Time-of-check Time-of-use (TOCTOU) Race Condition — 669 CVEsCWE-346 — 647 CVEsCWE-426 — Untrusted Search Path — 644 CVEsCWE-327 — Use of a Broken or Risky Cryptographic Algorithm — 637 CVEsCWE-290 — 628 CVEsCWE-404 — 625 CVEsCWE-345 — Insufficient Verification of Data Authenticity — 623 CVEsCWE-307 — Improper Restriction of Excessive Authentication Attempts — 603 CVEsCWE-693 — Protection Mechanism Failure — 603 CVEsCWE-129 — Improper Validation of Array Index — 579 CVEsCWE-754 — Improper Check for Unusual or Exceptional Conditions — 562 CVEsCWE-613 — Insufficient Session Expiration — 558 CVEsCWE-209 — Generation of Error Message Containing Sensitive Information — 549 CVEsCWE-755 — Improper Handling of Exceptional Conditions — 533 CVEsCWE-1321 — Prototype Pollution — 506 CVEsCWE-288 — 483 CVEsCWE-674 — Uncontrolled Recursion — 464 CVEsCWE-369 — Divide By Zero — 453 CVEsCWE-772 — 451 CVEsCWE-191 — Integer Underflow — 440 CVEsCWE-428 — 440 CVEsCWE-326 — Inadequate Encryption Strength — 428 CVEsCWE-1333 — 418 CVEsCWE-552 — Files or Directories Accessible to External Parties — 416 CVEsCWE-73 — 397 CVEsCWE-134 — 396 CVEsCWE-1021 — 395 CVEsCWE-384 — Session Fixation — 393 CVEsCWE-254 — 380 CVEsCWE-88 — Argument Injection — 369 CVEsCWE-497 — 358 CVEsCWE-444 — HTTP Request/Response Smuggling — 357 CVEsCWE-330 — Use of Insufficiently Random Values — 351 CVEsCWE-201 — 346 CVEsCWE-116 — 339 CVEsCWE-665 — Improper Initialization — 325 CVEsCWE-311 — Missing Encryption of Sensitive Data — 324 CVEsCWE-1284 — Improper Validation of Specified Quantity in Input — 318 CVEsCWE-281 — Improper Preservation of Permissions — 315 CVEsCWE-451 — 309 CVEsCWE-922 — 295 CVEsCWE-1236 — Improper Neutralization of Formula Elements in a CSV File — 293 CVEsCWE-16 — 289 CVEsCWE-250 — 276 CVEsCWE-640 — 272 CVEsCWE-824 — 268 CVEsCWE-23 — 263 CVEsCWE-1188 — Insecure Default Initialization of Resource — 260 CVEsCWE-126 — Buffer Over-read — 258 CVEsCWE-80 — 257 CVEsCWE-704 — Incorrect Type Conversion or Cast — 256 CVEsCWE-521 — Weak Password Requirements — 242 CVEsCWE-829 — 242 CVEsCWE-294 — Authentication Bypass by Capture-replay — 231 CVEsCWE-19 — 230 CVEsCWE-425 — 219 CVEsCWE-610 — 212 CVEsCWE-248 — 204 CVEs