Home › CWE weaknessesBrowse CVEs by CWE weakness type Every CVE stems from an underlying software weakness, classified by the Common Weakness Enumeration (CWE) — cross-site scripting, SQL injection, out-of-bounds writes, and hundreds more. Pick a weakness to see the CVEs that share it, ordered by CVSS severity.
Most common weaknesses CWE-79 — Cross-site Scripting (XSS) — 46,797 CVEsCWE-89 — SQL Injection — 18,622 CVEsCWE-787 — Out-of-bounds Write — 13,408 CVEsCWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer — 13,226 CVEsCWE-20 — Improper Input Validation — 12,313 CVEsCWE-200 — Exposure of Sensitive Information to an Unauthorized Actor — 10,094 CVEsCWE-22 — Path Traversal — 9,961 CVEsCWE-352 — Cross-Site Request Forgery (CSRF) — 9,368 CVEsCWE-125 — Out-of-bounds Read — 9,245 CVEsCWE-862 — Missing Authorization — 9,075 CVEsCWE-416 — Use After Free — 8,004 CVEsCWE-284 — Improper Access Control — 6,185 CVEsCWE-78 — OS Command Injection — 6,041 CVEsCWE-476 — NULL Pointer Dereference — 5,379 CVEsCWE-94 — Code Injection — 5,366 CVEsCWE-264 — Permissions, Privileges, and Access Controls — 5,241 CVEsCWE-287 — Improper Authentication — 4,455 CVEsCWE-434 — Unrestricted Upload of File with Dangerous Type — 3,918 CVEsCWE-120 — Classic Buffer Overflow — 3,609 CVEsCWE-74 — Improper Neutralization of Special Elements (Injection) — 3,471 CVEsCWE-863 — Incorrect Authorization — 3,418 CVEsCWE-918 — Server-Side Request Forgery (SSRF) — 3,211 CVEsCWE-190 — Integer Overflow or Wraparound — 3,190 CVEsCWE-77 — Command Injection — 3,125 CVEsCWE-400 — Uncontrolled Resource Consumption — 3,114 CVEsCWE-269 — Improper Privilege Management — 3,101 CVEsCWE-502 — Deserialization of Untrusted Data — 2,989 CVEsCWE-306 — Missing Authentication for Critical Function — 2,690 CVEsCWE-399 — Resource Management Errors — 2,558 CVEsCWE-362 — Race Condition — 2,513 CVEsCWE-310 — Cryptographic Issues — 2,439 CVEsCWE-639 — Authorization Bypass Through User-Controlled Key (IDOR) — 2,310 CVEsCWE-122 — Heap-based Buffer Overflow — 2,101 CVEsCWE-770 — Allocation of Resources Without Limits or Throttling — 2,034 CVEsCWE-401 — Missing Release of Memory after Effective Lifetime — 1,891 CVEsCWE-121 — Stack-based Buffer Overflow — 1,709 CVEsCWE-798 — Use of Hard-coded Credentials — 1,677 CVEsCWE-59 — Improper Link Resolution Before File Access (Link Following) — 1,637 CVEsCWE-601 — Open Redirect — 1,600 CVEsCWE-732 — Incorrect Permission Assignment for Critical Resource — 1,589 CVEsCWE-295 — Improper Certificate Validation — 1,514 CVEsCWE-276 — Incorrect Default Permissions — 1,480 CVEsCWE-522 — Insufficiently Protected Credentials — 1,285 CVEsCWE-611 — Improper Restriction of XML External Entity Reference (XXE) — 1,276 CVEsCWE-98 — PHP Remote File Inclusion — 1,253 CVEsCWE-189 — Numeric Errors — 1,222 CVEsCWE-427 — Uncontrolled Search Path Element — 1,154 CVEsCWE-532 — Insertion of Sensitive Information into Log File — 1,154 CVEsCWE-266 — Incorrect Privilege Assignment — 1,045 CVEsCWE-285 — Improper Authorization — 999 CVEsCWE-319 — Cleartext Transmission of Sensitive Information — 862 CVEsCWE-835 — Loop with Unreachable Exit Condition (Infinite Loop) — 845 CVEsCWE-415 — Double Free — 841 CVEsCWE-908 — Use of Uninitialized Resource — 810 CVEsCWE-312 — Cleartext Storage of Sensitive Information — 794 CVEsCWE-617 — Reachable Assertion — 782 CVEsCWE-347 — Improper Verification of Cryptographic Signature — 756 CVEsCWE-203 — Observable Discrepancy — 752 CVEsCWE-843 — 742 CVEsCWE-255 — Credentials Management Errors — 726 CVEsCWE-367 — Time-of-check Time-of-use (TOCTOU) Race Condition — 715 CVEsCWE-667 — Improper Locking — 689 CVEsCWE-668 — Exposure of Resource to Wrong Sphere — 679 CVEsCWE-346 — 673 CVEsCWE-290 — 663 CVEsCWE-345 — Insufficient Verification of Data Authenticity — 657 CVEsCWE-426 — Untrusted Search Path — 656 CVEsCWE-404 — 651 CVEsCWE-693 — Protection Mechanism Failure — 646 CVEsCWE-327 — Use of a Broken or Risky Cryptographic Algorithm — 644 CVEsCWE-307 — Improper Restriction of Excessive Authentication Attempts — 622 CVEsCWE-129 — Improper Validation of Array Index — 591 CVEsCWE-613 — Insufficient Session Expiration — 573 CVEsCWE-754 — Improper Check for Unusual or Exceptional Conditions — 570 CVEsCWE-209 — Generation of Error Message Containing Sensitive Information — 568 CVEsCWE-755 — Improper Handling of Exceptional Conditions — 533 CVEsCWE-1321 — Prototype Pollution — 518 CVEsCWE-288 — 507 CVEsCWE-674 — Uncontrolled Recursion — 488 CVEsCWE-191 — Integer Underflow — 465 CVEsCWE-369 — Divide By Zero — 458 CVEsCWE-772 — 456 CVEsCWE-73 — 447 CVEsCWE-428 — 441 CVEsCWE-326 — Inadequate Encryption Strength — 434 CVEsCWE-552 — Files or Directories Accessible to External Parties — 431 CVEsCWE-1333 — 429 CVEsCWE-1021 — 401 CVEsCWE-134 — 401 CVEsCWE-384 — Session Fixation — 400 CVEsCWE-88 — Argument Injection — 389 CVEsCWE-254 — 380 CVEsCWE-497 — 375 CVEsCWE-444 — HTTP Request/Response Smuggling — 372 CVEsCWE-201 — 362 CVEsCWE-330 — Use of Insufficiently Random Values — 358 CVEsCWE-116 — 355 CVEsCWE-451 — 345 CVEsCWE-1284 — Improper Validation of Specified Quantity in Input — 334 CVEsCWE-311 — Missing Encryption of Sensitive Data — 327 CVEsCWE-665 — Improper Initialization — 327 CVEsCWE-281 — Improper Preservation of Permissions — 315 CVEsCWE-1236 — Improper Neutralization of Formula Elements in a CSV File — 302 CVEsCWE-922 — 296 CVEsCWE-16 — 289 CVEsCWE-23 — 287 CVEsCWE-250 — 286 CVEsCWE-126 — Buffer Over-read — 281 CVEsCWE-640 — 280 CVEsCWE-824 — 268 CVEsCWE-80 — 263 CVEsCWE-1188 — Insecure Default Initialization of Resource — 261 CVEsCWE-704 — Incorrect Type Conversion or Cast — 260 CVEsCWE-294 — Authentication Bypass by Capture-replay — 250 CVEsCWE-829 — 247 CVEsCWE-521 — Weak Password Requirements — 244 CVEsCWE-19 — 230 CVEsCWE-248 — 221 CVEsCWE-425 — 221 CVEsCWE-610 — 214 CVEs