Tipos de falha

CWE-79 · XSS (CWE-79)25.980CWE-89 · Unauthenticated SQL injection (CWE-89)11.496CWE-862 · The software does not perform an authorization check when an actor attempts to access a resource or perform an action.6.679CWE-352 · The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.5.662CWE-22 · The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.4.653CWE-20 · The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.4.566CWE-787 · OUT-OF-BOUNDS WRITE CWE-7874.447CWE-284 · The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.4.335CWE-125 · OUT-OF-BOUNDS READ CWE-1254.244CWE-74 · Injection4.124CWE-416 · USE AFTER FREE CWE-416 (CVE-2019-13510)3.990CWE-200 · The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.3.859CWE-78 · The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.3.752CWE-94 · Script injection3.706CWE-121 · Stack buffer overflow (CWE-121)3.413CWE-119 · Memory Corruption - Generic (CWE-119)2.920CWE-120 · Execute unauthorized code or commands2.893CWE-434 · UNRESTRICTED UPLOAD OF FILE WITH DANGEROUS TYPE CWE-4342.782CWE-77 · The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.2.513CWE-400 · UNCONTROLLED RESOURCE CONSUMPTION ('RESOURCE EXHAUSTION') CWE-4002.364CWE-122 · Heap Overflow (CWE-122)2.327CWE-502 · The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.2.197CWE-918 · The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.2.119CWE-476 · Remote authenticated null dereference (CWE-476)2.103CWE-863 · The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.2.054CWE-287 · When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.1.825CWE-269 · The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.1.772CWE-306 · The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.1.687CWE-639 · The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.1.501CWE-770 · The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.1.308CWE-190 · INTEGER OVERFLOW OR WRAPAROUND CWE-1901.282CWE-285 · The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.1.280CWE-98 · Remote File Inclusion (CWE-98)1.230CWE-601 · URL REDIRECTION TO UNTRUSTED SITE ('OPEN REDIRECT') CWE-601987CWE-266 · Incorrect Privilege Assignment938CWE-276 · INCORRECT DEFAULT PERMISSIONS CWE-276904CWE-427 · Uncontrolled Search Path or Element841CWE-362 · Race Condition (CWE-362), Classic Buffer Overflow (CWE-120)820CWE-798 · USE OF HARD-CODED CREDENTIALS CWE-798819CWE-532 · Sensitive Information in Log Files741CWE-732 · The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.686CWE-295 · Information disclosure672CWE-59 · Link Following613CWE-404 · IMPROPER RESOURCE SHUTDOWN OR RELEASE CWE-404598CWE-288 · Improper access control579CWE-401 · Missing Release of Memory after Effective Lifetime576CWE-611 · XXE CWE-611571CWE-522 · INSUFFICIENTLY PROTECTED CREDENTIALS CWE-522550CWE-693 · PROTECTIONS MECHANISM FAILURE CWE-693548CWE-843 · Type Confusion548CWE-80 · Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) (CWE-80)543CWE-367 · Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)502CWE-319 · The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.487CWE-347 · Information disclosure463CWE-290 · This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.460CWE-73 · Improper access control457CWE-126 · Stack buffer over-read (CWE-126)449CWE-23 · The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as .. that can resolve to a location that is outside of that directory.420CWE-307 · IMPROPER RESTRICTION OF EXCESSIVE AUTHENTICATION ATTEMPTS CWE-307409CWE-754 · The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.407CWE-312 · Information disclosure406CWE-613 · Session Expiration383CWE-346 · ORIGIN VALIDATION ERROR CWE-346372CWE-617 · Reachable Assertion (CWE-617)371CWE-209 · Information Exposure Through Error Message370CWE-345 · Insufficient Verification of Data Authenticity (CWE-345)365CWE-327 · USE OF A BROKEN OR RISKY CRYPTOGRAPHIC ALGORITHM CWE-327357CWE-428 · UNQUOTED SEARCH PATH OR ELEMENT CWE-428348CWE-1333 · The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.336CWE-497 · Information disclosure334CWE-201 · Insertion of Sensitive Information Into Sent Data329CWE-250 · EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250328CWE-552 · Files or Directories Accessible to External Parties (CWE-552)327CWE-835 · The program contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.323CWE-311 · MISSING ENCRYPTION OF SENSITIVE DATA CWE-311301CWE-1321 · Prototype Pollution300CWE-321 · USE OF HARD-CODED CRYPTOGRAPHIC KEY CWE-321298CWE-203 · Observable Discrepancy293CWE-415 · Execute unauthorized code or commands291CWE-191 · INTEGER UNDERFLOW (WRAP OR WRAPAROUND) CWE-191291CWE-264 · Privileges, and Access Control [CWE-264]284CWE-426 · UNTRUSTED SEARCH PATH CWE-426281CWE-116 · Improper Encoding or Escaping of Output (CWE-116), Improper Handling of Unicode Encoding (CWE-176)279CWE-922 · INSECURE STORAGE OF SENSITIVE INFORMATION CWE-922278CWE-129 · IMPROPER VALIDATION OF ARRAY INDEX CWE-129263CWE-707 · Improper Neutralization249CWE-674 · UNCONTROLLED RECURSION CWE-674236CWE-908 · Use of Uninitialized Resource (CWE-908)234CWE-444 · Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')234CWE-451 · User Interface (UI) Misrepresentation of Critical Information (CWE-451)231CWE-1284 · Improper Validation of Specified Quantity in Input230CWE-755 · Improper handling of exceptional conditions CWE-755222CWE-384 · Session Fixiation221CWE-88 · Information disclosure218CWE-281 · Improper Preservation of Permissions210CWE-248 · UNCAUGHT EXCEPTION CWE-248207CWE-256 · Use of Hard-coded Password or Plaintext Storage of a Password206CWE-668 · EXPOSURE OF RESOURCE TO WRONG SPHERE CWE-668205CWE-822 · UNTRUSTED POINTER DEREFERENCE CWE-822201CWE-824 · Uninitialized Pointer198CWE-259 · USE OF HARD-CODED PASSWORD CWE-259194CWE-1021 · Inappropriate implementation189CWE-359 · Privacy Violation (CWE-359)187CWE-369 · Division by zero182CWE-1336 · Information disclosure178CWE-326 · INADEQUATE ENCRYPTION STRENGTH CWE-326175CWE-457 · Use of Uninitialized Variable173CWE-829 · Inclusion of Functionality from Untrusted Control Sphere (CWE-829)171CWE-1236 · IMPROPER NEUTRALIZATION OF FORMULA ELEMENTS IN A CSV FILE CWE-1236170CWE-35 · The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.170CWE-640 · WEAK PASSWORD RECOVERY MECHANISM FOR FORGOTTEN PASSWORD CWE-640169CWE-1188 · The software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.167CWE-749 · Exposed Dangerous Method or Function (CWE-749)162CWE-399 · Resource Management Errors160CWE-204 · The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.158CWE-494 · Escalation of privilege155CWE-789 · Uncontrolled Memory Allocation154CWE-521 · WEAK PASSWORD REQUIREMENTS CWE-521153CWE-294 · CWE-294: Authentication Bypass by Capture-Replay150CWE-93 · Information disclosure149CWE-667 · Improper Locking149CWE-703 · IMPROPER CHECK OR HANDLING OF EXCEPTIONAL CONDITIONS CWE-703149CWE-330 · USE OF INSUFFICIENTLY RANDOM VALUES CWE-330148CWE-305 · The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.147CWE-788 · CWE-788: Access of Memory Location After End of Buffer147CWE-280 · Improper Handling of Insufficient Permissions or Privileges (CWE-280)144CWE-665 · The software does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.143CWE-95 · Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')141CWE-61 · UNIX Symbolic Link (Symlink) Following140CWE-208 · Observable Timing Discrepancy138CWE-1287 · Improper Validation of Specified Type of Input136CWE-134 · Use of Externally-Controlled Format String134CWE-36 · The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as /abs/path that can resolve to a location that is outside of that directory.127CWE-184 · Incomplete List of Disallowed Inputs127CWE-338 · Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) (CWE-338)125CWE-472 · Integer overflow123CWE-602 · The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.120CWE-131 · Incorrect Calculation of Buffer Size (CWE-131)118CWE-24 · Path Traversal: '../filedir'111CWE-425 · The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.109CWE-358 · Security Check for Standard105CWE-680 · Integer Overflow to Buffer Overflow (CWE-680)105CWE-915 · Improperly Controlled Modification of Dynamically-Determined Object Attributes100CWE-1392 · Use of Default Credentials100CWE-942 · Permissive Cross-domain Security Policy with Untrusted Domains99CWE-117 · The software does not neutralize or incorrectly neutralizes output that is written to logs.98CWE-252 · Unchecked Return Value98CWE-193 · OFF-BY-ONE ERROR CWE-19396CWE-670 · Incorrect Control Flow95CWE-823 · Use of Out-of-range Pointer Offset (CWE-823)94CWE-130 · Improper Handling of Length Parameter Inconsistency (CWE-130)93CWE-377 · Insecure Temporary File (CWE-377)93CWE-354 · Improper Validation of Integrity Check Value93CWE-441 · Unintended Proxy or Intermediary ('Confused Deputy')89CWE-407 · Inefficient Algorithmic Complexity88CWE-840 · CWE-840: Business Logic Errors87CWE-303 · Incorrect Implementation of Authentication Algorithms (CWE-303)86CWE-1220 · Insufficient Granularity of Access Control85CWE-506 · Embedded Malicious Code (CWE-506)85CWE-610 · Improper access control84CWE-538 · Insertion of Sensitive Information into Externally-Accessible File or Directory83CWE-620 · Unverified Password Change (CWE-620)83CWE-113 · The software receives data from an upstream component, but does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.82CWE-459 · INCOMPLETE CLEANUP CWE-45982CWE-1390 · Weak Authentication81CWE-331 · Insufficient Entropy81CWE-328 · Use of Weak Hash80CWE-1286 · Improper Validation of Syntactic Correctness of Input80CWE-598 · Use of HTTP Request With Sensitive Query String80CWE-926 · Improper Export of Android Application Components79CWE-489 · LEFTOVER DEBUG CODE CWE-48979CWE-912 · HIDDEN FUNCTIONALITY CWE-91279CWE-807 · Reliance on Untrusted Inputs in a Security Decision (CWE-807)78CWE-310 · Information disclosure78CWE-591 · CWE-591: Sensitive Data Storage in Improperly Locked Memory77CWE-704 · INCORRECT TYPE VERSION OR CAST CWE-70477CWE-436 · Interpretation Conflict76CWE-91 · XML Injection (CWE-91)72CWE-697 · Incorrect Comparison (CWE-697)70CWE-772 · Missing Release of Resource after Effective Lifetime70CWE-277 · Insecure Inherited Permissions (CWE-277)70CWE-799 · Improper Control of Interaction Frequency69CWE-913 · Improper Control of Dynamically-Managed Code Resources68CWE-15 · External Control of System or Configuration Setting65CWE-916 · USE OF PASSWORD HASH WITH INSUFFICIENT COMPUTATIONAL EFFORT CWE-91665CWE-150 · Improper Neutralization of Escape, Meta, or Control Sequences (CWE-150)65CWE-212 · Information disclosure64CWE-257 · STORING PASSWORDS IN A RECOVERABLE FORMAT CWE-25764CWE-267 · Privilege Defined With Unsafe Actions64CWE-29 · Path Traversal: '..filename'64CWE-648 · Incorrect Use of Privileged APIs63CWE-409 · Improper Handling of Highly Compressed Data (Data Amplification) (CWE-409)61CWE-255 · CWE-255 Credentials Management Errors61CWE-923 · Improper Restriction of Communication Channel to Intended Endpoints60CWE-16 · Misconfiguration (CWE-16)60CWE-669 · Incorrect resource transfer between spheres59CWE-682 · INCORRECT CALCULATION CWE-68259CWE-614 · Sensitive Cookie Without Secure Attribute58CWE-548 · INFORMATION EXPOSURE THROUGH DIRECTORY LISTING CWE-54857CWE-706 · Use of Incorrectly-Resolved Name or Reference (CWE-706)57CWE-320 · Key Management Error56CWE-90 · Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')56CWE-681 · Incorrect Conversion between Numeric Types56CWE-644 · IMPROPER NEUTRALIZATION OF HTTP HEADERS FOR SCRIPTING SYNTAX CWE-64455CWE-379 · CWE-379: Creation of Temporary File in Directory with Insecure Permissions55CWE-653 · The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.54CWE-99 · Resource Injection (CWE-99)54CWE-300 · Man-in-the-Middle (CWE-300)54CWE-943 · Improper Neutralization of Special Elements in Data Query Logic54CWE-87 · Improper Neutralization of Alternate XSS Syntax53CWE-348 · Use of Less Trusted Source52CWE-297 · Information disclosure52CWE-940 · Improper Verification of Source of a Communication Channel52CWE-1391 · Use of Weak Credentials50CWE-841 · Enforcement of Behavioral Workflow50CWE-325 · Missing Required Cryptographic Step (CWE-325)50CWE-672 · OPERATION ON A RESOURCE AFTER EXPIRATION OR RELEASE CWE-67250CWE-170 · Improper Null Termination (CWE-170)49CWE-178 · Improper Handling of Case Sensitivity49CWE-275 · Permission Issues (CWE-275)49CWE-1285 · Improper Validation of Specified Index, Position, or Offset in Input49CWE-917 · Improper Neutralization of Special Elements used in an Expression Language Statement49CWE-470 · Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')47CWE-524 · Use of Cache Containing Sensitive Information47CWE-805 · CWE-805: Buffer Access with Incorrect Length Value47CWE-340 · Generation of Predictable Numbers or Identifiers46CWE-197 · Execute unauthorized code or commands46CWE-378 · CWE-378: Creation of Temporary File With Insecure Permissions45CWE-405 · CWE-405: Asymmetric Resource Consumption (Amplification)44CWE-1395 · Dependency on Vulnerable Third-Party Component (CWE-1395)44CWE-123 · WRITE-WHAT-WHERE CONDITION CWE-12344CWE-274 · Privilege Escalation (CWE-274)41CWE-1004 · CWE-1004: Sensitive Cookie Without HttpOnly Flag41CWE-440 · CWE-440: Expected Behavior Violation41CWE-565 · Reliance on Cookies without Validation and Integrity Checking40CWE-385 · CWE-385: Covert Timing Channel40CWE-261 · Weak encoding for password40CWE-1393 · Use of Default Password40CWE-664 · CWE-664: Improper Control of a Resource Through its Lifetime39CWE-353 · Missing Support for Integrity Check (CWE-353)38CWE-302 · CWE-302: Authentication Bypass by Assumed-Immutable Data38CWE-323 · Reusing a Nonce, Key Pair in Encryption37CWE-420 · Unprotected Alternate Channel37CWE-349 · CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data36CWE-124 · Execute unauthorized code or commands36CWE-471 · Modification of Assumed-Immutable Data (MAID) (CWE-471)36CWE-316 · The product stores sensitive information in cleartext in memory.36CWE-696 · Incorrect Behavior Order35CWE-825 · Expired Pointer Dereference35CWE-202 · Exposure of Sensitive Information Through Data Queries35CWE-776 · XML Entity Expansion (CWE-776)34CWE-636 · When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.34CWE-75 · Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) (CWE-75)34CWE-791 · Incomplete Filtering of Special Elements34CWE-92 · Improper conditions check34CWE-183 · Permissive List of Allowed Inputs34CWE-834 · Excessive Iteration (CWE-834)34CWE-763 · Release of Invalid Pointer or Reference33CWE-690 · CWE-690: Unchecked Return Value to NULL Pointer Dereference33CWE-241 · Improper Handling of Unexpected Data Type32CWE-782 · Exposed IOCTL with Insufficient Access Control (CWE-782)32CWE-424 · Improper Protection of Alternate Path32CWE-691 · Insufficient Control Flow Management (CWE-691)32CWE-356 · Product UI does not warn user of unsafe actions CWE-35632CWE-272 · Least Privilege Violation32CWE-226 · Sensitive Information in Resource Not Removed Before Reuse31CWE-304 · The product implements an authentication technique, but it skips a step that weakens the technique.31CWE-286 · Incorrect User Management30CWE-233 · Improper Handling of Parameters (CWE-233)30CWE-1385 · Missing Origin Validation in WebSockets30CWE-540 · Inclusion of Sensitive Information in Source Code30CWE-289 · CWE-289: Authentication Bypass by Alternate Name29CWE-213 · CWE-213: Intentional Information Exposure29CWE-488 · Exposure of Data Element to Wrong Session29CWE-525 · CWE-525: Use of Web Browser Cache Containing Sensitive Information29CWE-1289 · CWE-1289: Improper Validation of Unsafe Equivalence in Input28CWE-282 · Improper Ownership Management28CWE-313 · CWE-313: Cleartext Storage in a File or on Disk28CWE-115 · Misinterpretation of Input27CWE-27 · Path Traversal: 'dir/../../filename'27CWE-684 · Incorrect Provision of Specified Functionality27CWE-114 · CWE-114: Process Control26CWE-41 · Information disclosure26CWE-185 · Incorrect Regular Expression26CWE-189 · Numeric Error26CWE-176 · The software does not properly handle when an input contains Unicode encoding.26CWE-158 · IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-15826CWE-270 · Privilege Context Switching Error26CWE-279 · Incorrect Execution-Assigned Permissions25CWE-1230 · Inappropriate implementation25CWE-778 · Insufficient Logging (CWE-778)25CWE-758 · Reliance on Undefined, Unspecified, or Implementation-Defined Behavior25CWE-592 · This weakness has been deprecated because it covered redundant concepts already described in CWE-287.24CWE-939 · Improper Authorization in Handler for Custom URL Scheme24CWE-391 · Unchecked Error Condition (CWE-391)24CWE-1275 · Sensitive Cookie with Improper SameSite Attribute24CWE-260 · Password in Configuration File24CWE-501 · Trust Boundary Violation24CWE-322 · Key Exchange without Entity Authentication24CWE-757 · Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')24CWE-96 · CWE-96: Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')23CWE-402 · Transmission of Private Resources into a New Sphere ('Resource Leak')23CWE-523 · UNPROTECTED TRANSPORT OF CREDENTIALS CWE-52323CWE-273 · Improper Check for Dropped Privileges22CWE-460 · Improper cleanup on thrown exception CWE-46022CWE-833 · Deadlock22CWE-603 · USE OF CLIENT-SIDE AUTHENTICATION CWE-60322CWE-268 · Privilege Chaining22CWE-350 · Reliance on Reverse DNS Resolution for a Security-Critical Action (CWE-350)22CWE-283 · Unverified Ownership22CWE-83 · The product does not neutralize or incorrectly neutralizes "javascript:" or other URIs from dangerous attributes within tags, such as onmouseover, onload, onerror, or style.22CWE-606 · Unchecked Input for Loop Condition21CWE-1288 · Improper Validation of Consistency within Input21CWE-253 · Incorrect Check of Function Return Value21CWE-1295 · Information disclosure21CWE-924 · CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel21CWE-779 · Logging of Excessive Data20CWE-783 · Operator Precedence Logic Error20CWE-1191 · On-Chip Debug and Test Interface With Improper Access Control20CWE-708 · Incorrect Ownership Assignment20CWE-410 · Insufficient Resource Pool20CWE-214 · CWE-214: Invocation of Process Using Visible Sensitive Information20CWE-335 · CWE-335: Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)19CWE-228 · Improper Handling of Syntactically Invalid Structure19CWE-1104 · Use of Unmaintained Third Party Components19CWE-195 · CWE-195: Signed to Unsigned Conversion Error19CWE-244 · Improper Clearing of Heap Memory Before Release ('Heap Inspection')19CWE-357 · INSUFFICIENT UI WARNING OF DANGEROUS OPERATIONS CWE-35719CWE-590 · Free of Memory not on the Heap19CWE-324 · Use of a Key Past its Expiration Date19CWE-657 · Violation of Secure Design Principles (CWE-657)18CWE-140 · CWE-140: Improper Neutralization of Delimiters18CWE-1240 · CWE-1240: Use of a Cryptographic Primitive with a Risky Implementation18CWE-1327 · CWE-1327: Binding to an Unrestricted IP Address18CWE-927 · CWE-927: Use of Implicit Intent for Sensitive Communication 18CWE-84 · The web application improperly neutralizes user-controlled input for executable script disguised with URI encodings.18CWE-453 · CWE-453: Insecure Default Variable Initialization18CWE-526 · CWE-526: Exposure of Sensitive Information Through Environmental Variables18CWE-1325 · Improperly Controlled Sequential Memory Allocation17CWE-296 · Improper Following of a Certificate's Chain of Trust (CWE-296)17CWE-26 · Path Traversal17CWE-395 · NULL pointer dereference17CWE-215 · Insertion of Sensitive Information Into Debugging Code17CWE-229 · Improper Handling of Values17CWE-549 · Missing Password Field Masking16CWE-366 · Race Condition within a Thread16CWE-1394 · Use of Default Cryptographic Key16CWE-837 · Improper Enforcement of a Single, Unique Action16CWE-698 · Execution After Redirect16CWE-390 · Detection of Error Condition Without Action16CWE-759 · USE OF A ONE-WAY HASH WITHOUT A SALT CWE-75916CWE-662 · Improper Synchronization16CWE-642 · External Control of Critical State Data (CWE-642)16CWE-477 · USE OF OBSOLETE FUNCTION CWE-47716CWE-406 · CWE-406: Insufficient Control of Network Message Volume (Network Amplification)16CWE-1259 · CWE-1259: Improper Restriction of Security Token Assignment15CWE-1260 · Improper Handling of Overlap Between Protected Memory Ranges15CWE-1386 · CWE-1386: Insecure Operation on Windows Junction / Mount Point15CWE-155 · CWE-155: Improper Neutralization of Wildcards or Matching Symbols15CWE-413 · Improper Resource Locking15CWE-804 · Guessable CAPTCHA15CWE-909 · CWE-909: Missing Initialization of Resource15CWE-394 · CWE-394: Unexpected Status Code or Return Value14CWE-449 · CWE-449: The UI Performs the Wrong Action14CWE-180 · Incorrect Behavior Order: Validate Before Canonicalize (CWE-180).14CWE-351 · CWE-351: Insufficient Type Distinction14CWE-1300 · Side-channel information leakage14CWE-1242 · Inclusion of undocumented features or chicken bits14CWE-364 · Signal Handler Race Condition14CWE-790 · CWE-790: Improper Filtering of Special Elements14CWE-836 · Use of Password Hash Instead of Password for Authentication14CWE-475 · Undefined Behavior for Input to API13CWE-643 · Improper Neutralization of Data within XPath Expressions ('XPath Injection')13CWE-1263 · Improper Physical Access Control13CWE-138 · Improper Neutralization of Special Elements13CWE-599 · CWE-599: Missing Validation of OpenSSL Certificate13CWE-337 · Predictable Seed in Pseudo-Random Number Generator (PRNG)13CWE-641 · Improper Restriction of Names for Files and Other Resources13CWE-334 · Small Space of Random Values13CWE-159 · CWE-159: Improper Handling of Invalid Use of Special Elements13CWE-19 · Data Handling13CWE-762 · Mismatched Memory Management Routines12CWE-821 · Incorrect Synchronization12CWE-25 · Path Traversal: '/../filedir'12CWE-1022 · CWE-1022: Use of Web Link to Untrusted Target with window.opener Access12CWE-830 · CWE-830: Inclusion of Web Functionality from an Untrusted Source12CWE-341 · PREDICTABLE FROM OBSERVABLE STATE CWE-34112CWE-419 · CWE-419: Unprotected Primary Channel12CWE-1258 · Exposure of Sensitive System Information Due to Uncleared Debug Information12CWE-230 · Improper Handling of Missing Values12CWE-911 · Improper Update of Reference Count12CWE-1244 · Improper Authorization on Physical Debug and Test Interfaces12CWE-271 · Privilege Dropping / Lowering Errors12CWE-392 · Missing Report of Error Condition12CWE-308 · CWE-308: Use of Single-factor Authentication12CWE-1023 · Incomplete Comparison with Missing Factors11CWE-656 · CWE-656: Reliance on Security Through Obscurity11CWE-612 · Improper Authorization of Index Containing Sensitive Information11CWE-1427 · CWE-1427: Improper Neutralization of Input Used for LLM Prompting11CWE-1050 · Excessive Platform Resource Consumption within a Loop11