Most exploited weaknesses
The ten weaknesses linked to the most CISA KEV-listed CVEs in the Threadlinqs catalog.
- CWE-22 Path Traversal21 KEV · 124 CVEs
- CWE-787 Out-of-bounds Write21 KEV · 74 CVEs
- CWE-94 Code Injection20 KEV · 88 CVEs
- CWE-287 Improper Authentication20 KEV · 72 CVEs
- CWE-502 Deserialization of Untrusted Data20 KEV · 66 CVEs
- CWE-416 Use After Free18 KEV · 95 CVEs
- CWE-78 OS Command Injection18 KEV · 72 CVEs
- CWE-306 Missing Authentication for Critical Function17 KEV · 79 CVEs
- CWE-20 Improper Input Validation12 KEV · 66 CVEs
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer12 KEV · 34 CVEs
Pillar weaknesses
2 pillar-level weaknesses, most-mapped first.
Class weaknesses
27 class-level weaknesses, most-mapped first.
- CWE-862 Missing Authorization80 CVEs
- CWE-287 Improper Authentication72 CVEs
- CWE-74 Injection71 CVEs
- CWE-20 Improper Input Validation66 CVEs
- CWE-863 Incorrect Authorization56 CVEs
- CWE-400 Uncontrolled Resource Consumption50 CVEs
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor42 CVEs
- CWE-77 Command Injection39 CVEs
- CWE-269 Improper Privilege Management38 CVEs
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer34 CVEs
- CWE-285 Improper Authorization28 CVEs
- CWE-362 Race Condition17 CVEs
- CWE-345 Insufficient Verification of Data Authenticity12 CVEs
- CWE-346 Origin Validation Error10 CVEs
- CWE-506 Embedded Malicious Code9 CVEs
- CWE-674 Uncontrolled Recursion9 CVEs
- CWE-522 Insufficiently Protected Credentials8 CVEs
- CWE-732 Incorrect Permission Assignment for Critical Resource8 CVEs
- CWE-441 Confused Deputy6 CVEs
- CWE-669 Incorrect Resource Transfer Between Spheres6 CVEs
- CWE-754 Improper Check for Unusual or Exceptional Conditions6 CVEs
- CWE-116 Improper Encoding or Escaping of Output5 CVEs
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm5 CVEs
- CWE-1390 Weak Authentication5 CVEs
- CWE-436 Interpretation Conflict4 CVEs
- CWE-451 User Interface (UI) Misrepresentation of Critical Information3 CVEs
- CWE-668 Exposure of Resource to Wrong Sphere3 CVEs
Base weaknesses
53 base-level weaknesses, most-mapped first.
- CWE-79 Cross-site Scripting125 CVEs
- CWE-22 Path Traversal124 CVEs
- CWE-89 SQL Injection101 CVEs
- CWE-94 Code Injection88 CVEs
- CWE-306 Missing Authentication for Critical Function79 CVEs
- CWE-918 SSRF76 CVEs
- CWE-787 Out-of-bounds Write74 CVEs
- CWE-78 OS Command Injection72 CVEs
- CWE-125 Out-of-bounds Read69 CVEs
- CWE-502 Deserialization of Untrusted Data66 CVEs
- CWE-639 Authorization Bypass Through User-Controlled Key49 CVEs
- CWE-190 Integer Overflow or Wraparound37 CVEs
- CWE-434 Unrestricted Upload of File with Dangerous Type31 CVEs
- CWE-770 Allocation of Resources Without Limits or Throttling27 CVEs
- CWE-347 Improper Verification of Cryptographic Signature24 CVEs
- CWE-476 NULL Pointer Dereference23 CVEs
- CWE-843 Type Confusion22 CVEs
- CWE-59 Link Following21 CVEs
- CWE-266 Incorrect Privilege Assignment19 CVEs
- CWE-288 Authentication Bypass Using an Alternate Path or Channel18 CVEs
- CWE-120 Classic Buffer Overflow16 CVEs
- CWE-295 Improper Certificate Validation15 CVEs
- CWE-73 External Control of File Name or Path14 CVEs
- CWE-798 Use of Hard-coded Credentials14 CVEs
- CWE-908 Use of Uninitialized Resource14 CVEs
- CWE-617 Reachable Assertion13 CVEs
- CWE-290 Authentication Bypass by Spoofing12 CVEs
- CWE-601 Open Redirect12 CVEs
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition9 CVEs
- CWE-23 Relative Path Traversal8 CVEs
- CWE-88 Argument Injection8 CVEs
- CWE-444 HTTP Request/Response Smuggling8 CVEs
- CWE-613 Insufficient Session Expiration8 CVEs
- CWE-822 Untrusted Pointer Dereference8 CVEs
- CWE-294 Authentication Bypass by Capture-replay7 CVEs
- CWE-1188 Initialization of a Resource with an Insecure Default7 CVEs
- CWE-459 Incomplete Cleanup6 CVEs
- CWE-1284 Improper Validation of Specified Quantity in Input6 CVEs
- CWE-93 CRLF Injection5 CVEs
- CWE-494 Download of Code Without Integrity Check5 CVEs
- CWE-807 Reliance on Untrusted Inputs in a Security Decision5 CVEs
- CWE-1220 Insufficient Granularity of Access Control5 CVEs
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine5 CVEs
- CWE-209 Generation of Error Message Containing Sensitive Information4 CVEs
- CWE-276 Incorrect Default Permissions4 CVEs
- CWE-305 Authentication Bypass by Primary Weakness4 CVEs
- CWE-307 Improper Restriction of Excessive Authentication Attempts4 CVEs
- CWE-359 Exposure of Private Personal Information to an Unauthorized Actor4 CVEs
- CWE-532 Insertion of Sensitive Information into Log File4 CVEs
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere4 CVEs
- CWE-835 Infinite Loop4 CVEs
- CWE-319 Cleartext Transmission of Sensitive Information3 CVEs
- CWE-648 Incorrect Use of Privileged APIs3 CVEs
Variant weaknesses
9 variant-level weaknesses, most-mapped first.
- CWE-416 Use After Free95 CVEs
- CWE-122 Heap-based Buffer Overflow54 CVEs
- CWE-121 Stack-based Buffer Overflow28 CVEs
- CWE-401 Missing Release of Memory after Effective Lifetime12 CVEs
- CWE-321 Use of Hard-coded Cryptographic Key10 CVEs
- CWE-95 Eval Injection5 CVEs
- CWE-1321 Prototype Pollution5 CVEs
- CWE-35 Path Traversal: '.../...//'3 CVEs
- CWE-415 Double Free3 CVEs
Compound weaknesses
2 compound-level weaknesses, most-mapped first.
- CWE-352 CSRF12 CVEs
- CWE-384 Session Fixation3 CVEs