Rank | ID | Name | Score | CVEs in KEV | Rank Change vs. 2023 |
---|---|---|---|---|---|
1 | CWE-787 | Out-of-bounds Write | 75.59 | 18 | +2 |
2 | CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | 24.91 | 6 | +6 |
3 | CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 24.27 | 6 | +2 |
4 | CWE-94 | Improper Control of Generation of Code ('Code Injection') | 23.64 | 7 | +29 |
5 | CWE-502 | Deserialization of Untrusted Data | 23.07 | 5 | +1 |
6 | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 19.52 | 5 | +3 |
7 | CWE-306 | Missing Authentication for Critical Function | 17.60 | 6 | +3 |
8 | CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 15.62 | 4 | +3 |
9 | CWE-416 | Use After Free | 15.43 | 5 | -8 |
10 | CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | 14.90 | 4 | +5 |
Use of the Common Weakness Enumeration (CWE™) and the associated references from this website are subject to the Terms of Use. CWE is sponsored by the U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and managed by the Homeland Security Systems Engineering and Development Institute (HSSEDI) which is operated by The MITRE Corporation (MITRE). Copyright © 2006–2025, The MITRE Corporation. CWE, CWSS, CWRAF, and the CWE logo are trademarks of The MITRE Corporation.