Categories (CWE)

Search

Categories (CWE)

CWE Name Actions
CWE-812 OWASP Top Ten 2010 Category A3 - Broken Authentication and Session Management
CWE-811 OWASP Top Ten 2010 Category A2 - Cross-Site Scripting (XSS)
CWE-810 OWASP Top Ten 2010 Category A1 - Injection
CWE-81 Improper Neutralization of Script in an Error Message Web Page
CWE-808 2010 Top 25 - Weaknesses On the Cusp
CWE-807 Reliance on Untrusted Inputs in a Security Decision
CWE-806 Buffer Access Using Size of Source Buffer
CWE-805 Buffer Access with Incorrect Length Value
CWE-804 Guessable CAPTCHA
CWE-803 2010 Top 25 - Porous Defenses
CWE-802 2010 Top 25 - Risky Resource Management
CWE-801 2010 Top 25 - Insecure Interaction Between Components
CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CWE-8 J2EE Misconfiguration: Entity Bean Declared Remote
CWE-799 Improper Control of Interaction Frequency
CWE-798 Use of Hard-coded Credentials
CWE-797 Only Filtering Special Elements at an Absolute Position
CWE-796 Only Filtering Special Elements Relative to a Marker
CWE-795 Only Filtering Special Elements at a Specified Location
CWE-794 Incomplete Filtering of Multiple Instances of Special Elements
CWE-793 Only Filtering One Instance of a Special Element
CWE-792 Incomplete Filtering of One or More Instances of Special Elements
CWE-791 Incomplete Filtering of Special Elements
CWE-790 Improper Filtering of Special Elements
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-789 Memory Allocation with Excessive Size Value
CWE-788 Access of Memory Location After End of Buffer
CWE-787 Out-of-bounds Write
CWE-786 Access of Memory Location Before Start of Buffer
CWE-785 Use of Path Manipulation Function without Maximum-sized Buffer
CWE-784 Reliance on Cookies without Validation and Integrity Checking in a Security Decision
CWE-783 Operator Precedence Logic Error
CWE-782 Exposed IOCTL with Insufficient Access Control
CWE-781 Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code
CWE-780 Use of RSA Algorithm without OAEP
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-779 Logging of Excessive Data
CWE-778 Insufficient Logging
CWE-777 Regular Expression without Anchors
CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')