CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-338 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | Base | Simple | Draft | |
| CWE-339 | Small Seed Space in PRNG | Variant | Simple | Draft | |
| CWE-34 | Path Traversal: '....//' | Variant | Simple | Incomplete | |
| CWE-340 | Generation of Predictable Numbers or Identifiers | Class | Simple | Incomplete | |
| CWE-341 | Predictable from Observable State | Base | Simple | Draft | |
| CWE-342 | Predictable Exact Value from Previous Values | Base | Simple | Draft | |
| CWE-343 | Predictable Value Range from Previous Values | Base | Simple | Draft | |
| CWE-344 | Use of Invariant Value in Dynamically Changing Context | Base | Simple | Draft | |
| CWE-345 | Insufficient Verification of Data Authenticity | Class | Simple | Draft | |
| CWE-346 | Origin Validation Error | Class | Simple | Draft | |
| CWE-347 | Improper Verification of Cryptographic Signature | Base | Simple | Draft | |
| CWE-348 | Use of Less Trusted Source | Base | Simple | Draft | |
| CWE-349 | Acceptance of Extraneous Untrusted Data With Trusted Data | Base | Simple | Draft | |
| CWE-35 | Path Traversal: '.../...//' | Variant | Simple | Incomplete | |
| CWE-350 | Reliance on Reverse DNS Resolution for a Security-Critical Action | Variant | Simple | Draft | |
| CWE-351 | Insufficient Type Distinction | Base | Simple | Draft | |
| CWE-352 | Cross-Site Request Forgery (CSRF) | Compound | Composite | Stable | |
| CWE-353 | Missing Support for Integrity Check | Base | Simple | Draft | |
| CWE-354 | Improper Validation of Integrity Check Value | Base | Simple | Draft | |
| CWE-356 | Product UI does not Warn User of Unsafe Actions | Base | Simple | Incomplete |