1-100 of about 102 matches for site:cwe.mitre.org site:cwe.mitre.org site:cwe.mitre.org site:cwe.mitre.org weakness
https://cwe.mitre.org/
CWE - Common Weakness Enumeration Common Weakness Enumeration A community-developed list of SW & HW weaknesses that
https://cwe.mitre.org/community/submissions/overview.html
CWE - Contribute Weakness Content to CWE Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/1000.html
CWE - CWE-1000: Research Concepts (4.18) Common Weakness Enumeration A community-developed list of SW &
https://cwe.mitre.org/data/definitions/1000.html
CWE - CWE-1000: Research Concepts (4.17) Common Weakness Enumeration A community-developed list of SW &
https://cwe.mitre.org/data/definitions/284.html
CWE - CWE-284: Improper Access Control (4.17) Common Weakness Enumeration A community-developed list of SW
CWE - CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (
https://cwe.mitre.org/data/definitions/74.html
Elements in Output Used by a Downstream Component ('Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/284.html
CWE - CWE-284: Improper Access Control (4.18) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/352.html
CWE - CWE-352: Cross-Site Request Forgery (CSRF) (4.17) Common Weakness Enumeration A community-developed list of
https://cwe.mitre.org/data/definitions/138.html
CWE - CWE-138: Improper Neutralization of Special Elements (4.17) Common Weakness Enumeration A community-developed list
https://cwe.mitre.org/data/definitions/471.html
CWE - CWE-471: Modification of Assumed-Immutable Data (MAID) (4.17) Common Weakness Enumeration A community-developed
https://cwe.mitre.org/data/definitions/917.html
Special Elements used in an Expression Language Statement ('Expression Language Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/pdfs.html
types colored as specified below. Research View with Abstractions Highlighted Weakness Pillar Weakness Class Weakness Base Weakness Variant Compound Elements The
CWE - CWE-1349: CWE CATEGORY: OWASP Top Ten 2021 Category A05:2021 - Security Misconfiguration (4.17
https://cwe.mitre.org/data/definitions/1349.html
CWE-1349: CWE CATEGORY: OWASP Top Ten 2021 Category A05:2021 - Security Misconfiguration (4.17) Common Weakness Enumeration A community
CWE - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (
https://cwe.mitre.org/data/definitions/89.html
of Special Elements used in an SQL Command ('SQL Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/83.html
of Script in Attributes in a Web Page (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/476.html
CWE - CWE-476: NULL Pointer Dereference (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/399.html
CWE - CWE-399: CWE CATEGORY: Resource Management Errors (4.17) Common Weakness Enumeration A community-developed list of
CWE - CWE-75: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection
https://cwe.mitre.org/data/definitions/75.html
to Sanitize Special Elements into a Different Plane (Special Element Injection) (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/635.html
CWE-635: Weaknesses Originally Used by NVD from 2008 to 2016 (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/190.html
CWE - CWE-190: Integer Overflow or Wraparound (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/285.html
CWE - CWE-285: Improper Authorization (4.17) Common Weakness Enumeration A community-developed list of SW &
https://cwe.mitre.org/data/definitions/200.html
200: Exposure of Sensitive Information to an Unauthorized Actor (4.17) Common Weakness Enumeration A community
CWE - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (
https://cwe.mitre.org/data/definitions/89.html
of Special Elements used in an SQL Command ('SQL Injection') (4.18) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/23.html
CWE - CWE-23: Relative Path Traversal (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/1188.html
CWE-1188: Initialization of a Resource with an Insecure Default (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/93.html
CWE - CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') (4.17) Common Weakness Enumeration A community
CWE - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (
https://cwe.mitre.org/data/definitions/79.html
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/288.html
CWE - CWE-288: Authentication Bypass Using an Alternate Path or Channel (4.17) Common Weakness Enumeration A community-developed
https://cwe.mitre.org/data/definitions/91.html
CWE - CWE-91: XML Injection (aka Blind XPath Injection) (4.17) Common Weakness Enumeration A community-developed list of
https://cwe.mitre.org/data/definitions/610.html
Controlled Reference to a Resource in Another Sphere (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/400.html
CWE - CWE-400: Uncontrolled Resource Consumption (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/99.html
CWE - CWE-99: Improper Control of Resource Identifiers ('Resource Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/87.html
CWE - CWE-87: Improper Neutralization of Alternate XSS Syntax (4.17) Common Weakness Enumeration A community-developed
https://cwe.mitre.org/data/definitions/97.html
Neutralization of Server-Side Includes (SSI) Within a Web Page (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/453.html
CWE - CWE-453: Insecure Default Variable Initialization (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/86.html
of Invalid Characters in Identifiers in Web Pages (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/918.html
CWE - CWE-918: Server-Side Request Forgery (SSRF) (4.17) Common Weakness Enumeration A community-developed list of
https://cwe.mitre.org/data/definitions/85.html
CWE - CWE-85: Doubled Character XSS Manipulations (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/184.html
CWE - CWE-184: Incomplete List of Disallowed Inputs (4.17) Common Weakness Enumeration A community-developed list
https://cwe.mitre.org/data/definitions/81.html
Neutralization of Script in an Error Message Web Page (4.17) Common Weakness Enumeration A community
CWE - CWE-96: Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection
https://cwe.mitre.org/data/definitions/96.html
Neutralization of Directives in Statically Saved Code ('Static Code Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/643.html
CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection') (4.17) Common Weakness Enumeration A community
CWE - CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') (4
https://cwe.mitre.org/data/definitions/470.html
of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') (4.17) Common Weakness Enumeration A community
CWE - CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') (4
https://cwe.mitre.org/data/definitions/77.html
of Special Elements used in a Command ('Command Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/80.html
Script-Related HTML Tags in a Web Page (Basic XSS) (4.17) Common Weakness Enumeration A community
CWE - CWE-652: Improper Neutralization of Data within XQuery Expressions ('XQuery Injection') (4.17)
https://cwe.mitre.org/data/definitions/652.html
CWE-652: Improper Neutralization of Data within XQuery Expressions ('XQuery Injection') (4.17) Common Weakness Enumeration A community
CWE - CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') (
https://cwe.mitre.org/data/definitions/90.html
of Special Elements used in an LDAP Query ('LDAP Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/116.html
CWE - CWE-116: Improper Encoding or Escaping of Output (4.17) Common Weakness Enumeration A community-developed
https://cwe.mitre.org/data/definitions/94.html
94: Improper Control of Generation of Code ('Code Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/16.html
CWE - CWE-16: CWE CATEGORY: Configuration (4.18) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/452.html
CWE - CWE-452: CWE CATEGORY: Initialization and Cleanup Errors (4.17) Common Weakness Enumeration A community-developed
https://cwe.mitre.org/data/definitions/84.html
Neutralization of Encoded URI Schemes in a Web Page (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/644.html
644: Improper Neutralization of HTTP Headers for Scripting Syntax (4.17) Common Weakness Enumeration A community
CWE - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injecti
https://cwe.mitre.org/data/definitions/78.html
of Special Elements used in an OS Command ('OS Command Injection') (4.17) Common Weakness Enumeration A community
CWE - CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') (4.
https://cwe.mitre.org/data/definitions/88.html
Neutralization of Argument Delimiters in a Command ('Argument Injection') (4.17) Common Weakness Enumeration A community
CWE - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (
https://cwe.mitre.org/data/definitions/79.html
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (4.18) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/1224.html
CWE - CWE-1224: Improper Restriction of Write-Once Bit Fields (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/564.html
CWE - CWE-564: SQL Injection: Hibernate (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/20.html
CWE - CWE-20: Improper Input Validation (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/1419.html
CWE - CWE-1419: Incorrect Initialization of Resource (4.17) Common Weakness Enumeration A community-developed list of
https://cwe.mitre.org/data/definitions/1222.html
CWE-1222: Insufficient Granularity of Address Regions Protected by Register Locks (4.17) Common Weakness Enumeration A community
CWE - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injecti
https://cwe.mitre.org/data/definitions/78.html
of Special Elements used in an OS Command ('OS Command Injection') (4.18) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/16.html
CWE - CWE-16: CWE CATEGORY: Configuration (4.17) Common Weakness Enumeration A community-developed list of SW
CWE - CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Spl
https://cwe.mitre.org/data/definitions/113.html
of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/about/new_to_cwe.html
CWE - New to CWE Common Weakness Enumeration A community-developed list of SW & HW
https://cwe.mitre.org/data/definitions/1220.html
CWE - CWE-1220: Insufficient Granularity of Access Control (4.17) Common Weakness Enumeration A community-developed list
https://cwe.mitre.org/data/definitions/1191.html
1191: On-Chip Debug and Test Interface With Improper Access Control (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/slices/1000.html
CWE - VIEW SLICE: CWE-1000: Research Concepts (4.17) Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/definitions/1003.html
CWE-1003: Weaknesses for Simplified Mapping of Published Vulnerabilities (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/definitions/601.html
CWE - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/about/index.html
CWE - About CWE Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/data/definitions/933.html
CWE - CWE-933: CWE CATEGORY: OWASP Top Ten 2013 Category A5 - Security Misconfiguration (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/data/index.html
CWE - CWE List Version 4.17 Common Weakness Enumeration A community-developed list of SW & HW
https://cwe.mitre.org/about/history.html
CWE - About - CWE History Common Weakness Enumeration A community-developed list of SW & HW weaknesses that
CWE - CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
https://cwe.mitre.org/data/definitions/95.html
Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/documents/cwe_usage/guidance.html
CWE - CVE → CWE Mapping "Root Cause Mapping" Guidance Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/about/faq.html
a set of other entries that share a common characteristic. Pillar Weakness – Highest-level weakness that
https://cwe.mitre.org/data/definitions/1032.html
CWE - CWE-1032: CWE CATEGORY: OWASP Top Ten 2017 Category A6 - Security Misconfiguration (4.17) Common Weakness Enumeration A community
CWE - CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote
https://cwe.mitre.org/data/definitions/98.html
for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') (4.17) Common Weakness Enumeration A community
https://cwe.mitre.org/documents/glossary/index.html
Slice Special Element Sphere of Control Technology Technology-Specific Trailing Trigger Point Unexpected Variant Weakness View Vulnerability Weakness Back
https://cwe.mitre.org/news/podcast.html
CWE - Podcast Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/about/user_stories.html
CWE - User Stories Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/community/board.html
CWE - CWE Board Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/data/definitions/1194.html
CWE - CWE-1194: Hardware Design (4.17) Common Weakness Enumeration A community-developed list of SW &
https://cwe.mitre.org/top25/archive/2023/2023_kev_list.html
CWE - 2023 CWE Top 10 KEV Weaknesses Common Weakness Enumeration A community-developed list of SW &
https://cwe.mitre.org/data/definitions/100.html
CWE - CWE-100: CWE CATEGORY: DEPRECATED: Technology-Specific Input Validation Problems (4.17) Common Weakness Enumeration A community-developed
https://cwe.mitre.org/data/definitions/699.html
CWE - CWE-699: Software Development (4.17) Common Weakness Enumeration A community-developed list of SW &
https://cwe.mitre.org/documents/cwe_usage/quick_tips.html
CWE - CVE → CWE "Root Cause Mapping" Quick Tips Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/data/downloads.html
CWE - Downloads Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/scoring/lists/2021_CWE_MIHW.html
Does the weakness require hardware modifications to mitigate it? How frequently is this weakness detected during design? How
https://cwe.mitre.org/about/documents.html
CWE - Documents Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/top25/archive/2021/2021_cwe_top25.html
since the inability to cause significant harm by exploiting a weakness means that weakness should
https://cwe.mitre.org/data/archive.html
CWE - Archive Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/compatible/index.html
CWE - CWE Capability Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/find/index.html
CWE - Search the CWE Web Site Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/documents/cwe_usage/mapping_examples.html
CWE - CVE → CWE Mapping Guidance - Examples Common Weakness Enumeration A community-developed list of SW & HW
https://cwe.mitre.org/community/registration.html
CWE - A Discussion List Sign-Up Common Weakness Enumeration A community-developed list of SW
https://cwe.mitre.org/community/index.html
CWE - Community Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/data/reports.html
CWE - Reports Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can
https://cwe.mitre.org/news/archives/index.html
CWE - Archive Common Weakness Enumeration A community-developed list of SW & HW weaknesses that can