| CWE |
Name |
|
Actions |
| CWE-326 |
Inadequate Encryption Strength |
|
|
| CWE-325 |
Missing Cryptographic Step |
|
|
| CWE-324 |
Use of a Key Past its Expiration Date |
|
|
| CWE-323 |
Reusing a Nonce, Key Pair in Encryption |
|
|
| CWE-322 |
Key Exchange without Entity Authentication |
|
|
| CWE-321 |
Use of Hard-coded Cryptographic Key |
|
|
| CWE-320 |
Key Management Errors |
|
|
| CWE-32 |
Path Traversal: '...' (Triple Dot) |
|
|
| CWE-319 |
Cleartext Transmission of Sensitive Information |
|
|
| CWE-318 |
Cleartext Storage of Sensitive Information in Executable |
|
|
| CWE-317 |
Cleartext Storage of Sensitive Information in GUI |
|
|
| CWE-316 |
Cleartext Storage of Sensitive Information in Memory |
|
|
| CWE-315 |
Cleartext Storage of Sensitive Information in a Cookie |
|
|
| CWE-314 |
Cleartext Storage in the Registry |
|
|
| CWE-313 |
Cleartext Storage in a File or on Disk |
|
|
| CWE-312 |
Cleartext Storage of Sensitive Information |
|
|
| CWE-311 |
Missing Encryption of Sensitive Data |
|
|
| CWE-310 |
Cryptographic Issues |
|
|
| CWE-31 |
Path Traversal: 'dir\..\..\filename' |
|
|
| CWE-309 |
Use of Password System for Primary Authentication |
|
|
| CWE-308 |
Use of Single-factor Authentication |
|
|
| CWE-307 |
Improper Restriction of Excessive Authentication Attempts |
|
|
| CWE-306 |
Missing Authentication for Critical Function |
|
|
| CWE-305 |
Authentication Bypass by Primary Weakness |
|
|
| CWE-304 |
Missing Critical Step in Authentication |
|
|
| CWE-303 |
Incorrect Implementation of Authentication Algorithm |
|
|
| CWE-302 |
Authentication Bypass by Assumed-Immutable Data |
|
|
| CWE-301 |
Reflection Attack in an Authentication Protocol |
|
|
| CWE-300 |
Channel Accessible by Non-Endpoint |
|
|
| CWE-30 |
Path Traversal: '\dir\..\filename' |
|
|
| CWE-3 |
DEPRECATED: Technology-specific Environment Issues |
|
|
| CWE-299 |
Improper Check for Certificate Revocation |
|
|
| CWE-298 |
Improper Validation of Certificate Expiration |
|
|
| CWE-297 |
Improper Validation of Certificate with Host Mismatch |
|
|
| CWE-296 |
Improper Following of a Certificate's Chain of Trust |
|
|
| CWE-295 |
Improper Certificate Validation |
|
|
| CWE-294 |
Authentication Bypass by Capture-replay |
|
|
| CWE-293 |
Using Referer Field for Authentication |
|
|
| CWE-292 |
DEPRECATED: Trusting Self-reported DNS Name |
|
|
| CWE-291 |
Reliance on IP Address for Authentication |
|
|