| CWE-1004: SENSITIVE COOKIE WITHOUT 'HTTPONLY' FLAG | 11 items |
| CWE-1104: USE of UNMAINTAINED THIRD PARTY COMPONENTS | 2 items |
| CWE-113: IMPROPER NEUTRALIZATION of CRLF SEQUENCES in HTTP HEADERS ('HTTP REQUEST/RESPONSE SPLITTING') | 2 items |
| CWE-116: IMPROPER ENCODING or ESCAPING of OUTPUT | 9 items |
| CWE-1236: IMPROPER NEUTRALIZATION of FORMULA ELEMENTS in a CSV FILE | 3 items |
| CWE-1275: SENSITIVE COOKIE WITH IMPROPER SAMESITE ATTRIBUTE | 5 items |
| CWE-1333: INEFFICIENT REGULAR EXPRESSION COMPLEXITY | 6 items |
| CWE-1336: IMPROPER NEUTRALIZATION of SPECIAL ELEMENTS USED in a TEMPLATE ENGINE | 2 items |
| CWE-134: USE of EXTERNALLY-CONTROLLED FORMAT STRING | 3 items |
| CWE-16: CWE CATEGORY: CONFIGURATION | 4 items |
| CWE-183: PERMISSIVE LIST of ALLOWED INPUTS | 3 items |
| CWE-20: IMPROPER INPUT VALIDATION | 7 items |
| CWE-200: EXPOSURE of SENSITIVE INFORMATION to an UNAUTHORIZED ACTOR | 19 items |
| CWE-22: IMPROPER LIMITATION of a PATHNAME to a RESTRICTED DIRECTORY ('PATH TRAVERSAL') | 24 items |
| CWE-223: OMISSION of SECURITY-RELEVANT INFORMATION | 2 items |
| CWE-242: USE of INHERENTLY DANGEROUS FUNCTION | 2 items |
| CWE-250: EXECUTION WITH UNNECESSARY PRIVILEGES | 14 items |
| CWE-262: NOT USING PASSWORD AGING | 2 items |
| CWE-264: CWE CATEGORY: PERMISSIONS, PRIVILEGES, and ACCESS CONTROLS | 2 items |
| CWE-269: IMPROPER PRIVILEGE MANAGEMENT | 10 items |
| CWE-276: INCORRECT DEFAULT PERMISSIONS | 4 items |
| CWE-284: IMPROPER ACCESS CONTROL | 124 items |
| CWE-285: IMPROPER AUTHORIZATION | 3 items |
| CWE-287: IMPROPER AUTHENTICATION | 10 items |
| CWE-295: IMPROPER CERTIFICATE VALIDATION | 12 items |
| CWE-300: CHANNEL ACCESSIBLE by NON-ENDPOINT | 2 items |
| CWE-306: MISSING AUTHENTICATION for CRITICAL FUNCTION | 2 items |
| CWE-310: CWE CATEGORY: CRYPTOGRAPHIC ISSUES | 3 items |
| CWE-311: MISSING ENCRYPTION of SENSITIVE DATA | 21 items |
| CWE-319: CLEARTEXT TRANSMISSION of SENSITIVE INFORMATION | 77 items |
| CWE-320: CWE CATEGORY: KEY MANAGEMENT ERRORS | 51 items |
| CWE-321: USE of HARD-CODED CRYPTOGRAPHIC KEY | 2 items |
| CWE-322: KEY EXCHANGE WITHOUT ENTITY AUTHENTICATION | 2 items |
| CWE-323: REUSING a NONCE, KEY PAIR in ENCRYPTION | 3 items |
| CWE-326: INADEQUATE ENCRYPTION STRENGTH | 47 items |
| CWE-327: USE of a BROKEN or RISKY CRYPTOGRAPHIC ALGORITHM | 57 items |
| CWE-328: USE of WEAK HASH | 11 items |
| CWE-329: GENERATION of PREDICTABLE IV WITH CBC MODE | 2 items |
| CWE-330: USE of INSUFFICIENTLY RANDOM VALUES | 3 items |
| CWE-338: USE of CRYPTOGRAPHICALLY WEAK PSEUDO-RANDOM NUMBER GENERATOR (PRNG) | 4 items |
| CWE-345: INSUFFICIENT VERIFICATION of DATA AUTHENTICITY | 7 items |
| CWE-346: ORIGIN VALIDATION ERROR | 5 items |
| CWE-347: IMPROPER VERIFICATION of CRYPTOGRAPHIC SIGNATURE | 2 items |
| CWE-352: CROSS-SITE REQUEST FORGERY (CSRF) | 21 items |
| CWE-400: UNCONTROLLED RESOURCE CONSUMPTION | 3 items |
| CWE-416: USE AFTER FREE | 2 items |
| CWE-441: UNINTENDED PROXY or INTERMEDIARY ('CONFUSED DEPUTY') | 2 items |
| CWE-444: INCONSISTENT INTERPRETATION of HTTP REQUESTS ('HTTP REQUEST/RESPONSE SMUGGLING') | 3 items |
| CWE-470: USE of EXTERNALLY-CONTROLLED INPUT to SELECT CLASSES or CODE ('UNSAFE REFLECTION') | 3 items |
| CWE-489: ACTIVE DEBUG CODE | 11 items |
| CWE-502: DESERIALIZATION of UNTRUSTED DATA | 41 items |
| CWE-521: WEAK PASSWORD REQUIREMENTS | 3 items |
| CWE-522: INSUFFICIENTLY PROTECTED CREDENTIALS | 19 items |
| CWE-532: INSERTION of SENSITIVE INFORMATION INTO LOG FILE | 3 items |
| CWE-538: INSERTION of SENSITIVE INFORMATION INTO EXTERNALLY-ACCESSIBLE FILE or DIRECTORY | 2 items |
| CWE-540: INCLUSION of SENSITIVE INFORMATION in SOURCE CODE | 4 items |
| CWE-548: EXPOSURE of INFORMATION THROUGH DIRECTORY LISTING | 3 items |
| CWE-601: URL REDIRECTION to UNTRUSTED SITE ('OPEN REDIRECT') | 17 items |
| CWE-611: IMPROPER RESTRICTION of XML EXTERNAL ENTITY REFERENCE | 29 items |
| CWE-614: SENSITIVE COOKIE in HTTPS SESSION WITHOUT 'SECURE' ATTRIBUTE | 13 items |
| CWE-643: IMPROPER NEUTRALIZATION of DATA WITHIN XPATH EXPRESSIONS ('XPATH INJECTION') | 2 items |
| CWE-668: EXPOSURE of RESOURCE to WRONG SPHERE | 2 items |
| CWE-676: USE of POTENTIALLY DANGEROUS FUNCTION | 6 items |
| CWE-682: INCORRECT CALCULATION | 4 items |
| CWE-688: FUNCTION CALL WITH INCORRECT VARIABLE or REFERENCE as ARGUMENT | 2 items |
| CWE-693: PROTECTION MECHANISM FAILURE | 2 items |
| CWE-704: INCORRECT TYPE CONVERSION or CAST | 5 items |
| CWE-706: USE of INCORRECTLY-RESOLVED NAME or REFERENCE | 4 items |
| CWE-73: EXTERNAL CONTROL of FILE NAME or PATH | 4 items |
| CWE-732: INCORRECT PERMISSION ASSIGNMENT for CRITICAL RESOURCE | 15 items |
| CWE-74: IMPROPER NEUTRALIZATION of SPECIAL ELEMENTS in OUTPUT USED by a DOWNSTREAM COMPONENT ('INJECTION') | 2 items |
| CWE-778: INSUFFICIENT LOGGING | 9 items |
| CWE-78: IMPROPER NEUTRALIZATION of SPECIAL ELEMENTS USED in an OS COMMAND ('OS COMMAND INJECTION') | 58 items |
| CWE-780: USE of RSA ALGORITHM WITHOUT OAEP | 2 items |
| CWE-79: IMPROPER NEUTRALIZATION of INPUT DURING WEB PAGE GENERATION ('CROSS-SITE SCRIPTING') | 128 items |
| CWE-798: USE of HARD-CODED CREDENTIALS | 239 items |
| CWE-807: RELIANCE on UNTRUSTED INPUTS in a SECURITY DECISION | 4 items |
| CWE-837: IMPROPER ENFORCEMENT of a SINGLE, UNIQUE ACTION | 2 items |
| CWE-841: IMPROPER ENFORCEMENT of BEHAVIORAL WORKFLOW | 7 items |
| CWE-862: MISSING AUTHORIZATION | 2 items |
| CWE-89: IMPROPER NEUTRALIZATION of SPECIAL ELEMENTS USED in an SQL COMMAND ('SQL INJECTION') | 79 items |
| CWE-90: IMPROPER NEUTRALIZATION of SPECIAL ELEMENTS USED in an LDAP QUERY ('LDAP INJECTION') | 4 items |
| CWE-913: IMPROPER CONTROL of DYNAMICALLY-MANAGED CODE RESOURCES | 4 items |
| CWE-915: IMPROPERLY CONTROLLED MODIFICATION of DYNAMICALLY-DETERMINED OBJECT ATTRIBUTES | 15 items |
| CWE-918: SERVER-SIDE REQUEST FORGERY (SSRF) | 39 items |
| CWE-922: INSECURE STORAGE of SENSITIVE INFORMATION | 2 items |
| CWE-93: IMPROPER NEUTRALIZATION of CRLF SEQUENCES ('CRLF INJECTION') | 2 items |
| CWE-94: IMPROPER CONTROL of GENERATION of CODE ('CODE INJECTION') | 43 items |
| CWE-942: PERMISSIVE CROSS-DOMAIN POLICY WITH UNTRUSTED DOMAINS | 5 items |
| CWE-943: IMPROPER NEUTRALIZATION of SPECIAL ELEMENTS in DATA QUERY LOGIC | 5 items |
| CWE-95: IMPROPER NEUTRALIZATION of DIRECTIVES in DYNAMICALLY EVALUATED CODE ('EVAL INJECTION') | 31 items |
| CWE-96: IMPROPER NEUTRALIZATION of DIRECTIVES in STATICALLY SAVED CODE ('STATIC CODE INJECTION') | 6 items |