| 1 |
Allocation of resources without limits or throttling |
| 2 |
Array index underflow |
| 3 |
Authentication bypass |
| 4 |
Authentication bypass by primary weakness |
| 5 |
Authentication bypass using an alternate path or channel |
| 6 |
Blind sql injection |
| 7 |
Brute force |
| 8 |
Buffer over read |
| 9 |
Buffer under read |
| 10 |
Buffer underflow |
| 11 |
Business logic errors |
| 12 |
Cache poisoning |
| 13 |
Classic buffer overflow |
| 14 |
Cleartext storage in a file or on disk |
| 15 |
Cleartext storage of sensitive information |
| 16 |
Cleartext transmission of sensitive information |
| 17 |
Client side enforcement of server side security |
| 18 |
Code injection |
| 19 |
Command injection generic |
| 20 |
Concurrent execution using shared resource with improper synchronization |
| 21 |
Content spoofing |
| 22 |
Crlf injection |
| 23 |
Cross site request forgery csrf |
| 24 |
Cross site scripting xss |
| 25 |
Cross site scripting xss dom |
| 26 |
Cross site scripting xss generic |
| 27 |
Cross site scripting xss reflected |
| 28 |
Cross site scripting xss stored |
| 29 |
Cryptographic issues generic |
| 30 |
Deserialization of untrusted data |
| 31 |
Double free |
| 32 |
Download of code without integrity check |
| 33 |
Embedded malicious code |
| 34 |
Encoding error |
| 35 |
Execution with unnecessary privileges |
| 36 |
Expected behavior violation |
| 37 |
Exposed dangerous method or function |
| 38 |
Exposure of sensitive information due to incompatible policies |
| 39 |
External control of critical state data |
| 40 |
External control of file name or path |
| 41 |
Externally controlled reference to a resource in another sphere |
| 42 |
Failure to sanitize special elements into a different plane special element injection |
| 43 |
File and directory information exposure |
| 44 |
Forced browsing |
| 45 |
Free of memory not on the heap |
| 46 |
Heap overflow |
| 47 |
Http request smuggling |
| 48 |
Http response splitting |
| 49 |
Improper access control generic |
| 50 |
Improper authentication generic |
| 51 |
Improper authorization |
| 52 |
Improper certificate validation |
| 53 |
Improper check for certificate revocation |
| 54 |
Improper check or handling of exceptional conditions |
| 55 |
Improper export of android application components |
| 56 |
Improper following of a certificate |
| 57 |
Improper handling of insufficient permissions or privileges |
| 58 |
Improper handling of url encoding hex encoding |
| 59 |
Improper input validation |
| 60 |
Improper neutralization of escape |
| 61 |
Improper neutralization of http headers for scripting syntax |
| 62 |
Improper neutralization of script related html tags in a web page basic xss |
| 63 |
Improper null termination |
| 64 |
Improper privilege management |
| 65 |
Improper removal of sensitive information before storage or transfer |
| 66 |
Improper restriction of authentication attempts |
| 67 |
Improper synchronization |
| 68 |
Improper validation of certificate with host mismatch |
| 69 |
Improper verification of cryptographic signature |
| 70 |
Inadequate encryption strength |
| 71 |
Inclusion of functionality from untrusted control sphere |
| 72 |
Inconsistency between implementation and documented design |
| 73 |
Incorrect authorization |
| 74 |
Incorrect calculation of buffer size |
| 75 |
Incorrect permission assignment for critical resource |
| 76 |
Information disclosure |
| 77 |
Information exposure through an error message |
| 78 |
Information exposure through debug information |
| 79 |
Information exposure through directory listing |
| 80 |
Information exposure through sent data |
| 81 |
Information exposure through timing discrepancy |
| 82 |
Insecure direct object reference idor |
| 83 |
Insecure storage of sensitive information |
| 84 |
Insecure temporary file |
| 85 |
Insufficient session expiration |
| 86 |
Insufficient verification of data authenticity |
| 87 |
Insufficiently protected credentials |
| 88 |
Integer overflow |
| 89 |
Integer underflow |
| 90 |
Key exchange without entity authentication |
| 91 |
Ldap injection |
| 92 |
Leftover debug code backdoor |
| 93 |
Llm01 |
| 94 |
Llm02 |
| 95 |
Llm06 |
| 96 |
Malware |
| 97 |
Man in the middle |
| 98 |
Memory corruption generic |
| 99 |
Misconfiguration |
| 100 |
Misinterpretation of input |
| 101 |
Missing authentication for critical function |
| 102 |
Missing authorization |
| 103 |
Missing critical step in authentication |
| 104 |
Missing encryption of sensitive data |
| 105 |
Missing required cryptographic step |
| 106 |
Modification of assumed immutable data maid |
| 107 |
Null pointer dereference |
| 108 |
Off by one error |
| 109 |
Open redirect |
| 110 |
Os command injection |
| 111 |
Out of bounds read |
| 112 |
Password in configuration file |
| 113 |
Path traversal |
| 114 |
Path traversal |
| 115 |
Path traversal |
| 116 |
Phishing |
| 117 |
Php local file inclusion |
| 118 |
Plaintext storage of a password |
| 119 |
Privacy violation |
| 120 |
Privilege escalation |
| 121 |
Relative path traversal |
| 122 |
Reliance on cookies without validation and integrity checking in a security decision |
| 123 |
Reliance on reverse dns resolution for a security critical action |
| 124 |
Reliance on untrusted inputs in a security decision |
| 125 |
Remote file inclusion |
| 126 |
Resource injection |
| 127 |
Reusing a nonce |
| 128 |
Security through obscurity |
| 129 |
Server side request forgery |
| 130 |
Server side request forgery ssrf |
| 131 |
Session fixation |
| 132 |
Sql injection |
| 133 |
Stack overflow |
| 134 |
Storing passwords in a recoverable format |
| 135 |
Time of check time of use toctou race condition |
| 136 |
Type confusion |
| 137 |
Ui redressing clickjacking |
| 138 |
Unchecked error condition |
| 139 |
Uncontrolled recursion |
| 140 |
Uncontrolled resource consumption |
| 141 |
Unprotected transport of credentials |
| 142 |
Unrestricted upload of file with dangerous type |
| 143 |
Untrusted search path |
| 144 |
Unverified password change |
| 145 |
Use after free |
| 146 |
Use of a broken or risky cryptographic algorithm |
| 147 |
Use of a key past its expiration date |
| 148 |
Use of cache containing sensitive information |
| 149 |
Use of cryptographically weak pseudo random number generator prng |
| 150 |
Use of default credentials |
| 151 |
Use of externally controlled format string |
| 152 |
Use of hard coded credentials |
| 153 |
Use of hard coded cryptographic key |
| 154 |
Use of hard coded password |
| 155 |
Use of incorrectly resolved name or reference |
| 156 |
Use of inherently dangerous function |
| 157 |
Use of insufficiently random values |
| 158 |
User interface ui misrepresentation of critical information |
| 159 |
Using components with known vulnerabilities |
| 160 |
Violation of secure design principles |
| 161 |
Weak cryptography for passwords |
| 162 |
Weak password recovery mechanism for forgotten password |
| 163 |
Wrap around error |
| 164 |
Write what where condition |
| 165 |
Xml entity expansion |
| 166 |
Xml external entities xxe |
| 167 |
Xml injection |