Skip to main content

CWEs that violate the CWE Top 25 standard

The following table lists the CWEs that violate the CWE Top 25 standard. Only the supported CWEs on the most recent list will cause an application to fail a policy that includes the Auto-Update CWE Top 25 policy rule.

CWE IDCWE nameSAST supportDAST supportVeracode severityYears on list
22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')YesYes3 - Medium2019-2025
23Relative Path TraversalNoNoN/A2019-2025
73External Control of File Name or PathYesNo3 - Medium2019-2025
77Improper Neutralization of Special Elements used in a Command ('Command Injection')YesNo5 - Very High (Critical)2021-2025
78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')YesYes5 - Very High (Critical)2019-2025
79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')YesYes3 - Medium2019-2025
80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)YesYes3 - Medium2019-2025
81Improper Neutralization of Script in an Error Message Web PageNoNo3 - Medium2019-2025
83Improper Neutralization of Script in Attributes in a Web PageNoYes3 - Medium2019-2025
86Improper Neutralization of Invalid Characters in Identifiers in Web PagesYesNo3 - Medium2019-2025
89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')YesYes4 - High2019-2025
90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')YesNo3 - Medium2019-2025
91XML Injection (aka Blind XPath Injection)YesYes3 - Medium2019-2020, 2022-2025
94Improper Control of Generation of Code ('Code Injection')YesNo3 - Medium2019-2020, 2022-2025
95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')YesYes5 - Very High (Critical)2019-2020, 2022-2025
98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')YesYes4 - High2019-2020, 2022-2025
103Struts: Incomplete validate() Method DefinitionYesNo3 - Medium2019-2025
104Struts: Form Bean Does Not Extend Validation ClassYesNo3 - Medium2019-2025
112Missing XML ValidationYesNo3 - Medium2019-2025
119Improper Restriction of Operations within the Bounds of a Memory BufferNoNoN/A2019-2024
120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')NoNo5 - Very High (Critical)2019-2025
121Stack-based Buffer OverflowYesNo5 - Very High (Critical)2019-2025
122Heap-based Buffer OverflowNoNo5 - Very High (Critical)2025
125Out-of-bounds ReadYesNo3 - Medium2019-2025
131Incorrect Calculation of Buffer SizeNoNoN/A2019-2024
135Incorrect Calculation of Multi-Byte String LengthYesNo5 - Very High (Critical)2019-2024
185Incorrect Regular ExpressionYesNo2 - Low2019-2020, 2022-2025
190Integer Overflow or WraparoundYesNo5 - Very High (Critical)2019-2024
200Exposure of Sensitive Information to an Unauthorized ActorYesYes2 - Low2019-2021, 2024-2025
201Insertion of Sensitive Information Into Sent DataYesNo2 - Low2019-2021, 2024-2025
209Generation of Error Message Containing Sensitive InformationYesYes2 - Low2019-2021, 2024-2025
215Insertion of Sensitive Information Into Debugging CodeYesYes2 - Low2019-2021, 2024-2025
259Use of Hard-coded PasswordYesYes3 - Medium2019-2024
269Improper Privilege ManagementNoNo3 - Medium2019-2020, 2023-2024
272Least Privilege ViolationYesNo3 - Medium2019-2020, 2023-2024
276Incorrect Default PermissionsNoNo3 - Medium2021-2023
284Improper Access ControlYesNo3 - Medium2025
285Improper AuthorizationYesNo3 - Medium2019-2020, 2023-2024
287Improper AuthenticationYesYes4 - High2019-2024
295Improper Certificate ValidationYesNo3 - Medium2019
306Missing Authentication for Critical FunctionNoNo3 - Medium2020-2025
321Use of Hard-coded Cryptographic KeyYesYes3 - Medium2019-2024
346Origin Validation ErrorYesNo3 - Medium2019-2020, 2023-2024
350Reliance on Reverse DNS Resolution for a Security-Critical ActionYesNo3 - Medium2019-2020, 2023-2024
352Cross-Site Request Forgery (CSRF)YesYes3 - Medium2019-2025
359Exposure of Private Personal Information to an Unauthorized ActorYesYes2 - Low2019-2021, 2024-2025
362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')NoNoN/A2022-2023
366Race Condition within a ThreadYesNo3 - Medium2022-2023
367Time-of-check Time-of-use (TOCTOU) Race ConditionYesNo3 - Medium2022-2023
400Uncontrolled Resource ConsumptionNoNo2 - Low2019-2020, 2022, 2024
416Use After FreeYesNo2 - Low2019-2025
426Untrusted Search PathYesNo3 - Medium2019
427Uncontrolled Search Path ElementYesNo3 - Medium2019
434Unrestricted Upload of File with Dangerous TypeNoYes4 - High2019-2025
470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')YesNo3 - Medium2019-2025
476NULL Pointer DereferenceNoNo2 - Low2019-2025
497Exposure of Sensitive System Information to an Unauthorized Control SphereYesNo2 - Low2019-2021, 2024-2025
498Cloneable Class Containing Sensitive InformationNoNo2 - Low2019-2021, 2024-2025
502Deserialization of Untrusted DataYesYes3 - Medium2019-2025
522Insufficiently Protected CredentialsYesYes3 - Medium2020-2021
526Cleartext Storage of Sensitive Information in an Environment VariableNoYes2 - Low2019-2021, 2024-2025
530Exposure of Backup File to an Unauthorized Control SphereNoYes2 - Low2019-2021, 2024-2025
538Insertion of Sensitive Information into Externally-Accessible File or DirectoryNoYes2 - Low2019-2021, 2024-2025
548Exposure of Information Through Directory ListingNoYes2 - Low2019-2021, 2024-2025
564SQL Injection: HibernateYesNo4 - High2019-2025
566Authorization Bypass Through User-Controlled SQL Primary KeyYesNo3 - Medium2019-2020, 2023-2024
601URL Redirection to Untrusted Site ('Open Redirect')YesYes3 - Medium2019-2025
611Improper Restriction of XML External Entity ReferenceYesYes3 - Medium2019-2022
615Inclusion of Sensitive Information in Source Code CommentsYesNo2 - Low2019-2021, 2024-2025
618Exposed Unsafe ActiveX MethodYesNo5 - Very High (Critical)2019-2025
639Authorization Bypass Through User-Controlled KeyYesNo4 - High2019-2020, 2023-2025
665Improper InitializationYesNo2 - Low2019-2021, 2024-2025
693Protection Mechanism FailureYesYes3 - Medium2019-2024
708Incorrect Ownership AssignmentYesNo4 - High2019-2020, 2023-2024
732Incorrect Permission Assignment for Critical ResourceYesNo3 - Medium2019-2021
770Allocation of Resources Without Limits or ThrottlingNoNoN/A2025
772Missing Release of Resource after Effective LifetimeNoNoN/A2019
787Out-of-bounds WriteYesNo3 - Medium2019-2025
798Use of Hard-coded CredentialsYesNo3 - Medium2019-2024
830Inclusion of Web Functionality from an Untrusted SourceNoYes2 - Low2019-2020, 2022-2025
862Missing AuthorizationNoYes2 - Low2020-2025
863Incorrect AuthorizationNoNoN/A2023-2025
915Improperly Controlled Modification of Dynamically-Determined Object AttributesYesNo3 - Medium2019-2025
918Server-Side Request Forgery (SSRF)YesYes3 - Medium2019-2025
942Permissive Cross-domain Security Policy with Untrusted DomainsYesNo3 - Medium2019-2020, 2023-2024
1174ASP.NET Misconfiguration: Improper Model ValidationYesNo2 - Low2019-2025