CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-30 | Path Traversal: '\dir\..\filename' | Variant | Simple | Draft | |
| CWE-300 | Channel Accessible by Non-Endpoint | Class | Simple | Draft | |
| CWE-301 | Reflection Attack in an Authentication Protocol | Base | Simple | Draft | |
| CWE-302 | Authentication Bypass by Assumed-Immutable Data | Base | Simple | Incomplete | |
| CWE-303 | Incorrect Implementation of Authentication Algorithm | Base | Simple | Draft | |
| CWE-304 | Missing Critical Step in Authentication | Base | Simple | Draft | |
| CWE-305 | Authentication Bypass by Primary Weakness | Base | Simple | Draft | |
| CWE-306 | Missing Authentication for Critical Function | Base | Simple | Draft | |
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | Base | Simple | Draft | |
| CWE-308 | Use of Single-factor Authentication | Base | Simple | Draft | |
| CWE-309 | Use of Password System for Primary Authentication | Base | Simple | Draft | |
| CWE-31 | Path Traversal: 'dir\..\..\filename' | Variant | Simple | Draft | |
| CWE-311 | Missing Encryption of Sensitive Data | Class | Simple | Draft | |
| CWE-312 | Cleartext Storage of Sensitive Information | Base | Simple | Draft | |
| CWE-313 | Cleartext Storage in a File or on Disk | Variant | Simple | Draft | |
| CWE-314 | Cleartext Storage in the Registry | Variant | Simple | Draft | |
| CWE-315 | Cleartext Storage of Sensitive Information in a Cookie | Variant | Simple | Draft | |
| CWE-316 | Cleartext Storage of Sensitive Information in Memory | Variant | Simple | Draft | |
| CWE-317 | Cleartext Storage of Sensitive Information in GUI | Variant | Simple | Draft | |
| CWE-318 | Cleartext Storage of Sensitive Information in Executable | Variant | Simple | Draft |