Browse the archive
46 weakness classes · 5 severity bands · 7 vendors
By severity
By weakness class (CWE)
- Missing Authorization (39)
- Cross-site Scripting (36)
- SQL Injection (35)
- Server-Side Request Forgery (30)
- Path Traversal (25)
- CWE-770 (19)
- Code Injection (19)
- Incorrect Authorization (17)
- Missing Authentication for Critical Function (15)
- CWE-121 (14)
- CWE-284 (14)
- Exposure of Sensitive Information (13)
- Improper Authentication (12)
- CWE-639 (12)
- CWE-74 (11)
- Unrestricted Upload of Dangerous File Type (10)
- Command Injection (9)
- OS Command Injection (9)
- Classic Buffer Overflow (8)
- Cross-Site Request Forgery (8)
- CWE-789 (8)
- Improper Restriction of Operations within Memory Buffer (6)
- Out-of-bounds Read (6)
- Uncontrolled Resource Consumption (6)
- Deserialization of Untrusted Data (6)
- CWE-674 (6)
- Use After Free (5)
- Improper Input Validation (4)
- Improper Privilege Management (4)
- CWE-285 (4)
- CWE-367 (4)
- Out-of-bounds Write (4)
- CWE-122 (3)
- CWE-1333 (3)
- CWE-1336 (3)
- CWE-184 (3)
- Integer Overflow or Wraparound (3)
- CWE-204 (3)
- CWE-321 (3)
- CWE-401 (3)
- CWE-427 (3)
- Open Redirect (3)
- CWE-606 (3)
- CWE-73 (3)
- CWE-829 (3)
- CWE-95 (3)