CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-622 | Improper Validation of Function Hook Arguments | Variant | Simple | Draft | |
| CWE-623 | Unsafe ActiveX Control Marked Safe For Scripting | Variant | Simple | Draft | |
| CWE-624 | Executable Regular Expression Error | Base | Simple | Incomplete | |
| CWE-625 | Permissive Regular Expression | Base | Simple | Draft | |
| CWE-626 | Null Byte Interaction Error (Poison Null Byte) | Variant | Simple | Draft | |
| CWE-627 | Dynamic Variable Evaluation | Variant | Simple | Incomplete | |
| CWE-628 | Function Call with Incorrectly Specified Arguments | Base | Simple | Draft | |
| CWE-636 | Not Failing Securely ('Failing Open') | Class | Simple | Draft | |
| CWE-637 | Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism') | Class | Simple | Draft | |
| CWE-638 | Not Using Complete Mediation | Class | Simple | Draft | |
| CWE-639 | Authorization Bypass Through User-Controlled Key | Base | Simple | Incomplete | |
| CWE-64 | Windows Shortcut Following (.LNK) | Variant | Simple | Incomplete | |
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | Base | Simple | Incomplete | |
| CWE-641 | Improper Restriction of Names for Files and Other Resources | Base | Simple | Incomplete | |
| CWE-642 | External Control of Critical State Data | Class | Simple | Draft | |
| CWE-643 | Improper Neutralization of Data within XPath Expressions ('XPath Injection') | Base | Simple | Incomplete | |
| CWE-644 | Improper Neutralization of HTTP Headers for Scripting Syntax | Variant | Simple | Incomplete | |
| CWE-645 | Overly Restrictive Account Lockout Mechanism | Base | Simple | Incomplete | |
| CWE-646 | Reliance on File Name or Extension of Externally-Supplied File | Variant | Simple | Incomplete | |
| CWE-647 | Use of Non-Canonical URL Paths for Authorization Decisions | Variant | Simple | Incomplete |