Search Common Weakness Enumerations (CWE) by number.
| CWE | Description | Websites |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 17,562,641 |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 8,852,712 |
| CWE-20 | Improper Input Validation | 2,474,107 |
| CWE-125 | Out-of-bounds Read | 6,714,617 |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 235,022 |
| CWE-416 | Use After Free | 6,278,514 |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 3,983,257 |
| CWE-352 | Cross-Site Request Forgery (CSRF) | 2,154,396 |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | 3,819,606 |
| CWE-862 | Missing Authorization | 6,732,349 |
| CWE-476 | NULL Pointer Dereference | 5,856,039 |
| CWE-287 | Improper Authentication | 2,163,177 |
| CWE-190 | Integer Overflow or Wraparound | 5,403,923 |
| CWE-502 | Deserialization of Untrusted Data | 1,287,503 |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | 4,943 |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | 142,579 |
| CWE-798 | Use of Hard-coded Credentials | 232 |
| CWE-918 | Server-Side Request Forgery (SSRF) | 4,575,184 |
| CWE-306 | Missing Authentication for Critical Function | 123,739 |
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | 33,552 |
| CWE-269 | Improper Privilege Management | 2,895,484 |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | 3,022,686 |
| CWE-863 | Incorrect Authorization | 2,649,138 |
| CWE-276 | Incorrect Default Permissions | 4,367 |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 5,788,602 |
| CWE | Description | Updated |
|---|---|---|
| CWE-20 | Improper Input Validation | Jul 30, 2026 |
| CWE-787 | Out-of-bounds Write | Jul 30, 2026 |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Jul 30, 2026 |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | Jul 30, 2026 |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | Jul 30, 2026 |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | Jul 30, 2026 |
| CWE-863 | Incorrect Authorization | Jul 30, 2026 |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Jul 30, 2026 |
| CWE-352 | Cross-Site Request Forgery (CSRF) | Jul 30, 2026 |
| CWE | Description | Websites |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 17,562,641 |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 8,852,712 |
| CWE-862 | Missing Authorization | 6,732,349 |
| CWE-125 | Out-of-bounds Read | 6,714,617 |
| CWE-416 | Use After Free | 6,278,514 |
| CWE-476 | NULL Pointer Dereference | 5,856,039 |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 5,788,602 |
| CWE-190 | Integer Overflow or Wraparound | 5,403,923 |
| CWE-436 | Interpretation Conflict | 4,792,909 |
| CWE-918 | Server-Side Request Forgery (SSRF) | 4,575,184 |