| Rank | ID | Name | Score | CVEs in KEV | Rank Change vs. 2023 |
|---|---|---|---|---|---|
| 26 | CWE-770 | Allocation of Resources Without Limits or Throttling | 2.65 | 0 | +3 |
| 27 | CWE-668 | Exposure of Resource to Wrong Sphere | 2.56 | 0 | +13 |
| 28 | CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2.10 | 0 | +19 |
| 29 | CWE-427 | Uncontrolled Search Path Element | 2.08 | 0 | -2 |
| 30 | CWE-639 | Authorization Bypass Through User-Controlled Key | 2.05 | 0 | +8 |
| 31 | CWE-532 | Insertion of Sensitive Information into Log File | 1.99 | 0 | +14 |
| 32 | CWE-732 | Incorrect Permission Assignment for Critical Resource | 1.94 | 0 | -1 |
| 33 | CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | 1.85 | 0 | -1 |
| 34 | CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | 1.75 | 2 | -13 |
| 35 | CWE-522 | Insufficiently Protected Credentials | 1.71 | 0 | 0 |
| 36 | CWE-276 | Incorrect Default Permissions | 1.68 | 0 | -11 |
| 37 | CWE-203 | Observable Discrepancy | 1.61 | 0 | +14 |
| 38 | CWE-59 | Improper Link Resolution Before File Access ('Link Following') | 1.40 | 0 | +1 |
| 39 | CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | 1.38 | 6 | +7 |
| 40 | CWE-312 | Cleartext Storage of Sensitive Information | 1.37 | 0 | +3 |
Use of the Common Weakness Enumeration (CWE™) and the associated references from this website are subject to the Terms of Use. CWE is sponsored by the U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and managed by the Homeland Security Systems Engineering and Development Institute (HSSEDI) which is operated by The MITRE Corporation (MITRE). Copyright © 2006–2025, The MITRE Corporation. CWE, CWSS, CWRAF, and the CWE logo are trademarks of The MITRE Corporation.