| CWE |
Name |
|
Actions |
| CWE-362 |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
|
|
| CWE-361 |
7PK - Time and State |
|
|
| CWE-360 |
Trust of System Event Data |
|
|
| CWE-36 |
Absolute Path Traversal |
|
|
| CWE-359 |
Exposure of Private Personal Information to an Unauthorized Actor |
|
|
| CWE-358 |
Improperly Implemented Security Check for Standard |
|
|
| CWE-357 |
Insufficient UI Warning of Dangerous Operations |
|
|
| CWE-356 |
Product UI does not Warn User of Unsafe Actions |
|
|
| CWE-355 |
User Interface Security Issues |
|
|
| CWE-354 |
Improper Validation of Integrity Check Value |
|
|
| CWE-353 |
Missing Support for Integrity Check |
|
|
| CWE-352 |
Cross-Site Request Forgery (CSRF) |
|
|
| CWE-351 |
Insufficient Type Distinction |
|
|
| CWE-350 |
Reliance on Reverse DNS Resolution for a Security-Critical Action |
|
|
| CWE-35 |
Path Traversal: '.../...//' |
|
|
| CWE-349 |
Acceptance of Extraneous Untrusted Data With Trusted Data |
|
|
| CWE-348 |
Use of Less Trusted Source |
|
|
| CWE-347 |
Improper Verification of Cryptographic Signature |
|
|
| CWE-346 |
Origin Validation Error |
|
|
| CWE-345 |
Insufficient Verification of Data Authenticity |
|
|
| CWE-344 |
Use of Invariant Value in Dynamically Changing Context |
|
|
| CWE-343 |
Predictable Value Range from Previous Values |
|
|
| CWE-342 |
Predictable Exact Value from Previous Values |
|
|
| CWE-341 |
Predictable from Observable State |
|
|
| CWE-340 |
Generation of Predictable Numbers or Identifiers |
|
|
| CWE-34 |
Path Traversal: '....//' |
|
|
| CWE-339 |
Small Seed Space in PRNG |
|
|
| CWE-338 |
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
|
|
| CWE-337 |
Predictable Seed in Pseudo-Random Number Generator (PRNG) |
|
|
| CWE-336 |
Same Seed in Pseudo-Random Number Generator (PRNG) |
|
|
| CWE-335 |
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) |
|
|
| CWE-334 |
Small Space of Random Values |
|
|
| CWE-333 |
Improper Handling of Insufficient Entropy in TRNG |
|
|
| CWE-332 |
Insufficient Entropy in PRNG |
|
|
| CWE-331 |
Insufficient Entropy |
|
|
| CWE-330 |
Use of Insufficiently Random Values |
|
|
| CWE-33 |
Path Traversal: '....' (Multiple Dot) |
|
|
| CWE-329 |
Generation of Predictable IV with CBC Mode |
|
|
| CWE-328 |
Use of Weak Hash |
|
|
| CWE-327 |
Use of a Broken or Risky Cryptographic Algorithm |
|
|