Skip to main content

CWEs that violate the CWE Top 25 standard

Important

Support for the 2025 version will begin on June 30, 2026.

The following table lists the CWEs that violate the CWE Top 25 standard. Only the supported CWEs on the most recent list will cause an application to fail a policy that includes the Auto-Update CWE Top 25 policy rule.

CWE IDCWE nameStatic supportDynamic supportVeracode severityYears on list
22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')XX3 - Medium2019-2025
23Relative Path Traversal2019-2025
73External Control of File Name or PathX3 - Medium2019-2025
77Improper Neutralization of Special Elements used in a Command ('Command Injection')X5 - Very High (Critical)2021-2025
78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')XX5 - Very High (Critical)2019-2025
79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')XX3 - Medium2019-2025
80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)XX3 - Medium2019-2025
81Improper Neutralization of Script in an Error Message Web Page3 - Medium2019-2025
83Improper Neutralization of Script in Attributes in a Web PageX3 - Medium2019-2025
86Improper Neutralization of Invalid Characters in Identifiers in Web PagesX3 - Medium2019-2025
89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')XX4 - High2019-2025
90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')X3 - Medium2019-2025
91XML Injection (aka Blind XPath Injection)XX3 - Medium2019-2020, 2022-2025
94Improper Control of Generation of Code ('Code Injection')X3 - Medium2019-2020, 2022-2025
95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')XX5 - Very High (Critical)2019-2020, 2022-2025
98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')XX4 - High2019-2020, 2022-2025
103Struts: Incomplete validate() Method DefinitionX3 - Medium2019-2025
104Struts: Form Bean Does Not Extend Validation ClassX3 - Medium2019-2025
112Missing XML ValidationX3 - Medium2019-2025
119Improper Restriction of Operations within the Bounds of a Memory Buffer2019-2024
120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5 - Very High (Critical)2019-2025
121Stack-based Buffer OverflowX5 - Very High (Critical)2019-2025
122Heap-based Buffer Overflow5 - Very High (Critical)2025
125Out-of-bounds ReadX3 - Medium2019-2025
131Incorrect Calculation of Buffer Size2019-2024
135Incorrect Calculation of Multi-Byte String LengthX5 - Very High (Critical)2019-2024
185Incorrect Regular ExpressionX2 - Low2019-2020, 2022-2025
190Integer Overflow or WraparoundX5 - Very High (Critical)2019-2024
200Exposure of Sensitive Information to an Unauthorized ActorXX2 - Low2019-2021, 2024-2025
201Insertion of Sensitive Information Into Sent DataX2 - Low2019-2021, 2024-2025
209Generation of Error Message Containing Sensitive InformationXX2 - Low2019-2021, 2024-2025
215Insertion of Sensitive Information Into Debugging CodeXX2 - Low2019-2021, 2024-2025
259Use of Hard-coded PasswordXX3 - Medium2019-2024
269Improper Privilege Management3 - Medium2019-2020, 2023-2024
272Least Privilege ViolationX3 - Medium2019-2020, 2023-2024
276Incorrect Default Permissions3 - Medium2021-2023
284Improper Access ControlX3 - Medium2025
285Improper AuthorizationX3 - Medium2019-2020, 2023-2024
287Improper AuthenticationXX4 - High2019-2024
295Improper Certificate ValidationX3 - Medium2019
306Missing Authentication for Critical Function3 - Medium2020-2025
321Use of Hard-coded Cryptographic KeyXX3 - Medium2019-2024
346Origin Validation ErrorX3 - Medium2019-2020, 2023-2024
350Reliance on Reverse DNS Resolution for a Security-Critical ActionX3 - Medium2019-2020, 2023-2024
352Cross-Site Request Forgery (CSRF)XX3 - Medium2019-2025
359Exposure of Private Personal Information to an Unauthorized ActorXX2 - Low2019-2021, 2024-2025
362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2022-2023
366Race Condition within a ThreadX3 - Medium2022-2023
367Time-of-check Time-of-use (TOCTOU) Race ConditionX3 - Medium2022-2023
400Uncontrolled Resource Consumption2 - Low2019-2020, 2022, 2024
416Use After FreeX2 - Low2019-2025
426Untrusted Search PathX3 - Medium2019
427Uncontrolled Search Path ElementX3 - Medium2019
434Unrestricted Upload of File with Dangerous TypeX4 - High2019-2025
470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')X3 - Medium2019-2025
476NULL Pointer Dereference2 - Low2019-2025
497Exposure of Sensitive System Information to an Unauthorized Control SphereX2 - Low2019-2021, 2024-2025
498Cloneable Class Containing Sensitive Information2 - Low2019-2021, 2024-2025
502Deserialization of Untrusted DataXX3 - Medium2019-2025
522Insufficiently Protected CredentialsXX3 - Medium2020-2021
526Cleartext Storage of Sensitive Information in an Environment VariableX2 - Low2019-2021, 2024-2025
530Exposure of Backup File to an Unauthorized Control SphereX2 - Low2019-2021, 2024-2025
538Insertion of Sensitive Information into Externally-Accessible File or DirectoryX2 - Low2019-2021, 2024-2025
548Exposure of Information Through Directory ListingX2 - Low2019-2021, 2024-2025
564SQL Injection: HibernateX4 - High2019-2025
566Authorization Bypass Through User-Controlled SQL Primary KeyX3 - Medium2019-2020, 2023-2024
601URL Redirection to Untrusted Site ('Open Redirect')XX3 - Medium2019-2025
611Improper Restriction of XML External Entity ReferenceXX3 - Medium2019-2022
615Inclusion of Sensitive Information in Source Code CommentsX2 - Low2019-2021, 2024-2025
618Exposed Unsafe ActiveX MethodX5 - Very High (Critical)2019-2025
639Authorization Bypass Through User-Controlled KeyX4 - High2019-2020, 2023-2025
665Improper InitializationX2 - Low2019-2021, 2024-2025
693Protection Mechanism FailureXX3 - Medium2019-2024
708Incorrect Ownership AssignmentX4 - High2019-2020, 2023-2024
732Incorrect Permission Assignment for Critical ResourceX3 - Medium2019-2021
770Allocation of Resources Without Limits or Throttling2025
772Missing Release of Resource after Effective Lifetime2019
787Out-of-bounds WriteX3 - Medium2019-2025
798Use of Hard-coded CredentialsX3 - Medium2019-2024
830Inclusion of Web Functionality from an Untrusted SourceX2 - Low2019-2020, 2022-2025
862Missing AuthorizationX2 - Low2020-2025
863Incorrect Authorization2023-2025
915Improperly Controlled Modification of Dynamically-Determined Object AttributesX3 - Medium2019-2025
918Server-Side Request Forgery (SSRF)XX3 - Medium2019-2025
942Permissive Cross-domain Security Policy with Untrusted DomainsX3 - Medium2019-2020, 2023-2024
1174ASP.NET Misconfiguration: Improper Model ValidationX2 - Low2019-2025