Authentication Bypass | |
Authentication Bypass by Primary Weakness | |
Missing Synchronization | |
Improper Access Control | |
Resource Exhaustion | |
Information Exposure | |
Directory Traversal | |
Inefficient Regular Expression Complexity | |
Inefficient Regular Expression Complexity | |
Inefficient Regular Expression Complexity | |
Open Redirect | |
Improperly Implemented Security Check for Standard | |
Improper Access Control | |
Incorrect Calculation of Buffer Size | |
Improper Input Validation | |
Resource Exhaustion | |
Resource Exhaustion | |
Incorrect Regular Expression | |
Cross-site Scripting (XSS) | |
Improper Input Validation | |
Resource Exhaustion | |
Resource Exhaustion | |
Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
Improper Input Validation | |
Improper Input Validation | |
Deserialization of Untrusted Data | |
Deserialization of Untrusted Data | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
NULL Pointer Dereference | |
NULL Pointer Dereference | |
Uncontrolled Recursion | |
Uncontrolled Recursion | |
OS Command Injection | |
OS Command Injection | |
OS Command Injection | |
Missing Authorization | |
Integer Overflow or Wraparound | |
Integer Overflow or Wraparound | |
Resource Exhaustion | |
Improper Verification of Cryptographic Signature | |
Improper Verification of Cryptographic Signature | |
Improper Check for Dropped Privileges | |
Improper Check for Dropped Privileges | |
Resource Exhaustion | |
Integer Overflow or Wraparound | |
Integer Overflow or Wraparound | |
Arbitrary Code Injection | |
Arbitrary Code Injection | |
Improper Validation of Array Index | |
Resource Exhaustion | |
Improper Input Validation | |
Access of Resource Using Incompatible Type ('Type Confusion') | |
Access of Resource Using Incompatible Type ('Type Confusion') | |
Access of Resource Using Incompatible Type ('Type Confusion') | |
Authorization Bypass Through User-Controlled Key | |
Authorization Bypass Through User-Controlled Key | |
Authorization Bypass Through User-Controlled Key | |
Authorization Bypass Through User-Controlled Key | |
Authorization Bypass Through User-Controlled Key | |
Authorization Bypass Through User-Controlled Key | |
Resource Exhaustion | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
OS Command Injection | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Improper Input Validation | |
Improper Input Validation | |
Improper Input Validation | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Improper Input Validation | |
External Control of Assumed-Immutable Web Parameter | |
External Control of Assumed-Immutable Web Parameter | |
Inefficient Regular Expression Complexity | |
Allocation of Resources Without Limits or Throttling | |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
Resource Exhaustion | |
Open Redirect | |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
Incorrect Implementation of Authentication Algorithm | |
Incorrect Implementation of Authentication Algorithm | |
Information Exposure | |
Information Exposure | |
Inefficient Regular Expression Complexity | |
Inefficient Regular Expression Complexity | |
Resource Exhaustion | |
Resource Exhaustion | |
Authentication Bypass | |
Authentication Bypass | |
Inefficient Regular Expression Complexity | |
Inefficient Regular Expression Complexity | |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
Inefficient Regular Expression Complexity | |
Inefficient Regular Expression Complexity | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Improper Authentication | |
Improper Authentication | |
Resource Exhaustion | |
Resource Exhaustion | |
Open Redirect | |
Open Redirect | |
Insufficient Entropy | |
Insufficient Entropy | |
Exposure of Private Information ('Privacy Violation') | |
Improper Privilege Management | |
Time-of-check Time-of-use (TOCTOU) | |
Time-of-check Time-of-use (TOCTOU) | |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
Overly Restrictive Regular Expression | |
Overly Restrictive Regular Expression | |
Overly Restrictive Regular Expression | |
Overly Restrictive Regular Expression | |
Allocation of Resources Without Limits or Throttling | |
Allocation of Resources Without Limits or Throttling | |
Integer Overflow or Wraparound | |
Integer Overflow or Wraparound | |
Buffer Overflow | |
Buffer Overflow | |
Directory Traversal | |
Directory Traversal | |
Missing Release of Resource after Effective Lifetime | |
Missing Release of Resource after Effective Lifetime | |
Cleartext Storage of Sensitive Information | |
Cleartext Storage of Sensitive Information | |
Cross-site Scripting (XSS) | |
Resource Exhaustion | |
Resource Exhaustion | |
Information Exposure | |
Information Exposure | |
Unchecked Return Value | |
Unchecked Return Value | |
Incorrect Authorization | |
Incorrect Authorization | |
Integer Overflow or Wraparound | |
Integer Overflow or Wraparound | |
Incorrect Authorization | |
Incorrect Authorization | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Request Forgery (CSRF) | |
Cross-site Request Forgery (CSRF) | |
Information Exposure | |
Information Exposure | |
Open Redirect | |
Open Redirect | |
Directory Traversal | |
Directory Traversal | |
Directory Traversal | |
Directory Traversal | |
Information Exposure | |
Information Exposure | |
Resource Exhaustion | |
Improper Input Validation | |
Improper Input Validation | |
Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
Improper Input Validation | |
Improper Input Validation | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Authorization Bypass Through User-Controlled Key | |
Authorization Bypass Through User-Controlled Key | |
Authorization Bypass Through User-Controlled Key | |
Resource Exhaustion | |
Link Following | |
Link Following | |
Race Condition | |
Directory Traversal | |
Directory Traversal | |
Improper Input Validation | |
Resource Exhaustion | |
Improper Input Validation | |
Improper Input Validation | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Misinterpretation of Input | |
Misinterpretation of Input | |
Misinterpretation of Input | |
Misinterpretation of Input | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Modification of Assumed-Immutable Data (MAID) | |
Modification of Assumed-Immutable Data (MAID) | |
Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
Arbitrary Argument Injection | |
Arbitrary Argument Injection | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Incorrect Permission Assignment for Critical Resource | |
Incorrect Permission Assignment for Critical Resource | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Incorrect Permission Assignment for Critical Resource | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Modification of Assumed-Immutable Data (MAID) | |
Modification of Assumed-Immutable Data (MAID) | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Improper Input Validation | |
Server-Side Request Forgery (SSRF) | |
Server-Side Request Forgery (SSRF) | |
Incorrect Calculation | |
Incorrect Calculation | |
Incorrect Calculation | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Improper Certificate Validation | |
Improper Certificate Validation | |
Improper Certificate Validation | |
Race Condition | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Resource Exhaustion | |
Resource Exhaustion | |
Resource Exhaustion | |
Improper Input Validation | |
Arbitrary Code Injection | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Arbitrary Code Injection | |
Missing Authorization | |
Missing Authorization | |
Missing Authorization | |
Allocation of Resources Without Limits or Throttling | |
Resource Exhaustion | |
Improper Handling of Length Parameter Inconsistency | |
Resource Exhaustion | |
Improper Input Validation | |