Categories (CWE)

Search

Categories (CWE)

CWE Name Actions
CWE-655 Insufficient Psychological Acceptability
CWE-654 Reliance on a Single Factor in a Security Decision
CWE-653 Improper Isolation or Compartmentalization
CWE-652 Improper Neutralization of Data within XQuery Expressions ('XQuery Injection')
CWE-651 Exposure of WSDL File Containing Sensitive Information
CWE-650 Trusting HTTP Permission Methods on the Server Side
CWE-65 Windows Hard Link
CWE-649 Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking
CWE-648 Incorrect Use of Privileged APIs
CWE-647 Use of Non-Canonical URL Paths for Authorization Decisions
CWE-646 Reliance on File Name or Extension of Externally-Supplied File
CWE-645 Overly Restrictive Account Lockout Mechanism
CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax
CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')
CWE-642 External Control of Critical State Data
CWE-641 Improper Restriction of Names for Files and Other Resources
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
CWE-64 Windows Shortcut Following (.LNK)
CWE-639 Authorization Bypass Through User-Controlled Key
CWE-638 Not Using Complete Mediation
CWE-637 Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')
CWE-636 Not Failing Securely ('Failing Open')
CWE-634 DEPRECATED: Weaknesses that Affect System Processes
CWE-633 DEPRECATED: Weaknesses that Affect Memory
CWE-632 DEPRECATED: Weaknesses that Affect Files or Directories
CWE-63 DEPRECATED: Windows Path Link Problems
CWE-628 Function Call with Incorrectly Specified Arguments
CWE-627 Dynamic Variable Evaluation
CWE-626 Null Byte Interaction Error (Poison Null Byte)
CWE-625 Permissive Regular Expression
CWE-624 Executable Regular Expression Error
CWE-623 Unsafe ActiveX Control Marked Safe For Scripting
CWE-622 Improper Validation of Function Hook Arguments
CWE-621 Variable Extraction Error
CWE-620 Unverified Password Change
CWE-62 UNIX Hard Link
CWE-619 Dangling Database Cursor ('Cursor Injection')
CWE-618 Exposed Unsafe ActiveX Method
CWE-617 Reachable Assertion
CWE-616 Incomplete Identification of Uploaded File Variables (PHP)