数据管理终端
← 返回分析系统

CWE 弱点

查询就绪
CWE ID名称抽象级别结构状态操作
CWE-911Improper Update of Reference CountBaseSimpleIncomplete
CWE-912Hidden FunctionalityClassSimpleIncomplete
CWE-913Improper Control of Dynamically-Managed Code ResourcesClassSimpleIncomplete
CWE-914Improper Control of Dynamically-Identified VariablesBaseSimpleIncomplete
CWE-915Improperly Controlled Modification of Dynamically-Determined Object AttributesBaseSimpleIncomplete
CWE-916Use of Password Hash With Insufficient Computational EffortBaseSimpleIncomplete
CWE-917Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')BaseSimpleIncomplete
CWE-918Server-Side Request Forgery (SSRF)BaseSimpleIncomplete
CWE-92DEPRECATED: Improper Sanitization of Custom Special CharactersBaseSimpleDeprecated
CWE-920Improper Restriction of Power ConsumptionBaseSimpleIncomplete
CWE-921Storage of Sensitive Data in a Mechanism without Access ControlBaseSimpleIncomplete
CWE-922Insecure Storage of Sensitive InformationClassSimpleIncomplete
CWE-923Improper Restriction of Communication Channel to Intended EndpointsClassSimpleIncomplete
CWE-924Improper Enforcement of Message Integrity During Transmission in a Communication ChannelBaseSimpleIncomplete
CWE-925Improper Verification of Intent by Broadcast ReceiverVariantSimpleIncomplete
CWE-926Improper Export of Android Application ComponentsVariantSimpleIncomplete
CWE-927Use of Implicit Intent for Sensitive CommunicationVariantSimpleIncomplete
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')BaseSimpleDraft
CWE-939Improper Authorization in Handler for Custom URL SchemeBaseSimpleIncomplete
CWE-94Improper Control of Generation of Code ('Code Injection')BaseSimpleDraft
TOTAL 969 / PAGE 48 OF 49