CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-837 | Improper Enforcement of a Single, Unique Action | Base | Simple | Incomplete | |
| CWE-838 | Inappropriate Encoding for Output Context | Base | Simple | Incomplete | |
| CWE-839 | Numeric Range Comparison Without Minimum Check | Base | Simple | Incomplete | |
| CWE-84 | Improper Neutralization of Encoded URI Schemes in a Web Page | Variant | Simple | Draft | |
| CWE-841 | Improper Enforcement of Behavioral Workflow | Class | Simple | Incomplete | |
| CWE-842 | Placement of User into Incorrect Group | Base | Simple | Incomplete | |
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | Base | Simple | Incomplete | |
| CWE-85 | Doubled Character XSS Manipulations | Variant | Simple | Draft | |
| CWE-86 | Improper Neutralization of Invalid Characters in Identifiers in Web Pages | Variant | Simple | Draft | |
| CWE-862 | Missing Authorization | Class | Simple | Incomplete | |
| CWE-863 | Incorrect Authorization | Class | Simple | Incomplete | |
| CWE-87 | Improper Neutralization of Alternate XSS Syntax | Variant | Simple | Draft | |
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | Base | Simple | Draft | |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Base | Simple | Stable | |
| CWE-9 | J2EE Misconfiguration: Weak Access Permissions for EJB Methods | Variant | Simple | Draft | |
| CWE-90 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') | Base | Simple | Draft | |
| CWE-908 | Use of Uninitialized Resource | Base | Simple | Incomplete | |
| CWE-909 | Missing Initialization of Resource | Class | Simple | Incomplete | |
| CWE-91 | XML Injection (aka Blind XPath Injection) | Base | Simple | Draft | |
| CWE-910 | Use of Expired File Descriptor | Base | Simple | Incomplete |