OverviewCVE DiscoveryCWE Discovery

CWE Discovery

The Common Weakness Enumeration Discovery Index shows platform-wide data of instances, and severity and remediation time distributions. CWE data extracted every 24 hours.
CWE IDNameNumber of reports
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')108,451
CWE-200Exposure of Sensitive Information to an Unauthorized Actor76,229
CWE-284Improper Access Control42,753
CWE-639Authorization Bypass Through User-Controlled Key25,978
CWE-657Violation of Secure Design Principles22,155
CWE-287Improper Authentication21,802
CWE-601URL Redirection to Untrusted Site ('Open Redirect')15,878
CWE-352Cross-Site Request Forgery (CSRF)15,586
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11,223
CWE-94Improper Control of Generation of Code ('Code Injection')8,494
CWE-918Server-Side Request Forgery (SSRF)8,092
CWE-285Improper Authorization6,770
CWE-307Improper Restriction of Excessive Authentication Attempts6,686
CWE-400Uncontrolled Resource Consumption6,393
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')6,249
CWE-922Insecure Storage of Sensitive Information5,604
CWE-20Improper Input Validation5,408
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5,006
CWE-312Cleartext Storage of Sensitive Information4,960
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')4,699
CWE-610Externally Controlled Reference to a Resource in Another Sphere4,566
CWE-215Insertion of Sensitive Information Into Debugging Code4,546
CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)4,219
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer4,066
CWE-99Improper Control of Resource Identifiers ('Resource Injection')3,747
1-25 of 968