CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-911 | Improper Update of Reference Count | Base | Simple | Incomplete | |
| CWE-912 | Hidden Functionality | Class | Simple | Incomplete | |
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | Class | Simple | Incomplete | |
| CWE-914 | Improper Control of Dynamically-Identified Variables | Base | Simple | Incomplete | |
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | Base | Simple | Incomplete | |
| CWE-916 | Use of Password Hash With Insufficient Computational Effort | Base | Simple | Incomplete | |
| CWE-917 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') | Base | Simple | Incomplete | |
| CWE-918 | Server-Side Request Forgery (SSRF) | Base | Simple | Incomplete | |
| CWE-92 | DEPRECATED: Improper Sanitization of Custom Special Characters | Base | Simple | Deprecated | |
| CWE-920 | Improper Restriction of Power Consumption | Base | Simple | Incomplete | |
| CWE-921 | Storage of Sensitive Data in a Mechanism without Access Control | Base | Simple | Incomplete | |
| CWE-922 | Insecure Storage of Sensitive Information | Class | Simple | Incomplete | |
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | Class | Simple | Incomplete | |
| CWE-924 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel | Base | Simple | Incomplete | |
| CWE-925 | Improper Verification of Intent by Broadcast Receiver | Variant | Simple | Incomplete | |
| CWE-926 | Improper Export of Android Application Components | Variant | Simple | Incomplete | |
| CWE-927 | Use of Implicit Intent for Sensitive Communication | Variant | Simple | Incomplete | |
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | Base | Simple | Draft | |
| CWE-939 | Improper Authorization in Handler for Custom URL Scheme | Base | Simple | Incomplete | |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | Base | Simple | Draft |