CWE Research Context
Browse Common Weakness Enumeration context connected to published Atomicorp CVE research and active WAF protections. CVE pages provide the direct finding for a specific vulnerability.
This is a selected set of published research examples, not a complete list of Atomicorp protections. Absence of a CWE or CVE does not imply absence of protection against that weakness or attack method.
| CWE | Weakness | Published CVEs | Products | Active Atomicorp rules |
|---|---|---|---|---|
| CWE-19 | Common Weakness Enumeration category | 1 | 1 | 1 |
| CWE-20 | Improper Input Validation | 72 | 62 | 76 |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 759 | 658 | 114 |
| CWE-23 | Relative Path Traversal | 15 | 14 | 6 |
| CWE-24 | Path Traversal: '../filedir' | 5 | 5 | 6 |
| CWE-27 | Path Traversal: 'dir/../../filename' | 1 | 1 | 3 |
| CWE-28 | Path Traversal: '..\filedir' | 1 | 1 | 2 |
| CWE-29 | Path Traversal: '..\filename' | 11 | 5 | 9 |
| CWE-32 | Path Traversal: '…' (Triple Dot) | 1 | 1 | 1 |
| CWE-35 | Path Traversal: '…/…//' | 3 | 3 | 4 |
| CWE-36 | Absolute Path Traversal | 6 | 6 | 8 |
| CWE-44 | Path Equivalence: 'file.name' (Internal Dot) | 1 | 1 | 1 |
| CWE-50 | Path Equivalence: '//multiple/leading/slash' | 1 | 1 | 1 |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | 2 | 2 | 13 |
| CWE-73 | External Control of File Name or Path | 38 | 34 | 43 |
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 349 | 164 | 67 |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | 140 | 78 | 39 |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 367 | 221 | 69 |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 1435 | 1034 | 106 |
| CWE-80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 13 | 12 | 17 |
| CWE-81 | Improper Neutralization of Script in an Error Message Web Page | 1 | 1 | 1 |
| CWE-83 | Improper Neutralization of Script in Attributes in a Web Page | 3 | 3 | 16 |
| CWE-87 | Improper Neutralization of Alternate XSS Syntax | 6 | 2 | 14 |
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | 3 | 3 | 13 |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 1026 | 644 | 90 |
| CWE-91 | XML Injection (aka Blind XPath Injection) | 2 | 2 | 5 |
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | 7 | 7 | 26 |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | 276 | 204 | 109 |
| CWE-95 | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') | 10 | 8 | 17 |
| CWE-98 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | 18 | 18 | 16 |
| CWE-112 | Missing XML Validation | 1 | 1 | 2 |
| CWE-113 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') | 3 | 3 | 4 |
| CWE-116 | Improper Encoding or Escaping of Output | 10 | 10 | 17 |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | 4 | 4 | 9 |
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | 3 | 2 | 15 |
| CWE-121 | Stack-based Buffer Overflow | 4 | 2 | 12 |
| CWE-125 | Out-of-bounds Read | 1 | 1 | 2 |
| CWE-158 | Improper Neutralization of Null Byte or NUL Character | 1 | 1 | 4 |
| CWE-178 | Improper Handling of Case Sensitivity | 1 | 1 | 1 |
| CWE-180 | Incorrect Behavior Order: Validate Before Canonicalize | 2 | 2 | 10 |
| CWE-183 | Permissive List of Allowed Inputs | 2 | 2 | 20 |
| CWE-184 | Incomplete List of Disallowed Inputs | 5 | 5 | 23 |
| CWE-187 | Partial String Comparison | 1 | 1 | 9 |
| CWE-189 | Common Weakness Enumeration category | 1 | 1 | 5 |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 81 | 73 | 79 |
| CWE-201 | Insertion of Sensitive Information Into Sent Data | 1 | 1 | 3 |
| CWE-203 | Observable Discrepancy | 1 | 1 | 2 |
| CWE-206 | Observable Internal Behavioral Discrepancy | 1 | 1 | 3 |
| CWE-209 | Generation of Error Message Containing Sensitive Information | 1 | 1 | 2 |
| CWE-233 | Improper Handling of Parameters | 1 | 1 | 3 |
| CWE-253 | Incorrect Check of Function Return Value | 1 | 1 | 9 |
| CWE-255 | Common Weakness Enumeration category | 4 | 3 | 8 |
| CWE-259 | Use of Hard-coded Password | 2 | 2 | 2 |
| CWE-264 | Common Weakness Enumeration category | 9 | 7 | 19 |
| CWE-266 | Incorrect Privilege Assignment | 2 | 2 | 14 |
| CWE-269 | Improper Privilege Management | 13 | 13 | 26 |
| CWE-276 | Incorrect Default Permissions | 1 | 1 | 1 |
| CWE-284 | Improper Access Control | 51 | 45 | 55 |
| CWE-285 | Improper Authorization | 11 | 11 | 41 |
| CWE-287 | Improper Authentication | 38 | 38 | 71 |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | 10 | 10 | 30 |
| CWE-290 | Authentication Bypass by Spoofing | 3 | 3 | 6 |
| CWE-294 | Authentication Bypass by Capture-replay | 1 | 1 | 2 |
| CWE-295 | Improper Certificate Validation | 2 | 1 | 19 |
| CWE-303 | Incorrect Implementation of Authentication Algorithm | 1 | 1 | 1 |
| CWE-305 | Authentication Bypass by Primary Weakness | 2 | 2 | 4 |
| CWE-306 | Missing Authentication for Critical Function | 61 | 57 | 84 |
| CWE-310 | Common Weakness Enumeration category | 2 | 1 | 1 |
| CWE-312 | Cleartext Storage of Sensitive Information | 1 | 1 | 1 |
| CWE-319 | Cleartext Transmission of Sensitive Information | 1 | 1 | 1 |
| CWE-326 | Inadequate Encryption Strength | 2 | 1 | 2 |
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | 3 | 3 | 9 |
| CWE-345 | Insufficient Verification of Data Authenticity | 8 | 8 | 21 |
| CWE-346 | Origin Validation Error | 1 | 1 | 4 |
| CWE-352 | Cross-Site Request Forgery (CSRF) | 41 | 40 | 73 |
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | 2 | 2 | 5 |
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | 7 | 7 | 11 |
| CWE-384 | Session Fixation | 2 | 2 | 10 |
| CWE-400 | Uncontrolled Resource Consumption | 3 | 3 | 8 |
| CWE-416 | Use After Free | 3 | 2 | 3 |
| CWE-420 | Unprotected Alternate Channel | 1 | 1 | 1 |
| CWE-424 | Improper Protection of Alternate Path | 1 | 1 | 1 |
| CWE-425 | Direct Request ('Forced Browsing') | 6 | 6 | 16 |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | 143 | 133 | 76 |
| CWE-436 | Interpretation Conflict | 1 | 1 | 2 |
| CWE-441 | Unintended Proxy or Intermediary ('Confused Deputy') | 5 | 5 | 15 |
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | 5 | 5 | 28 |
| CWE-470 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 4 | 3 | 12 |
| CWE-472 | External Control of Assumed-Immutable Web Parameter | 1 | 1 | 4 |
| CWE-473 | PHP External Variable Modification | 1 | 1 | 2 |
| CWE-489 | Active Debug Code | 1 | 1 | 1 |
| CWE-494 | Download of Code Without Integrity Check | 1 | 1 | 10 |
| CWE-501 | Trust Boundary Violation | 1 | 1 | 12 |
| CWE-502 | Deserialization of Untrusted Data | 48 | 41 | 44 |
| CWE-521 | Weak Password Requirements | 1 | 1 | 7 |
| CWE-522 | Insufficiently Protected Credentials | 6 | 5 | 9 |
| CWE-532 | Insertion of Sensitive Information into Log File | 4 | 4 | 1 |
| CWE-534 | DEPRECATED: Information Exposure Through Debug Log Files | 1 | 1 | 3 |
| CWE-538 | Insertion of Sensitive Information into Externally-Accessible File or Directory | 1 | 1 | 1 |
| CWE-551 | Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | 1 | 1 | 1 |
| CWE-552 | Files or Directories Accessible to External Parties | 16 | 16 | 15 |
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | 67 | 58 | 39 |
| CWE-602 | Client-Side Enforcement of Server-Side Security | 1 | 1 | 1 |
| CWE-610 | Externally Controlled Reference to a Resource in Another Sphere | 3 | 3 | 14 |
| CWE-611 | Improper Restriction of XML External Entity Reference | 38 | 35 | 34 |
| CWE-625 | Permissive Regular Expression | 1 | 1 | 7 |
| CWE-639 | Authorization Bypass Through User-Controlled Key | 10 | 10 | 34 |
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | 2 | 2 | 12 |
| CWE-641 | Improper Restriction of Names for Files and Other Resources | 1 | 1 | 12 |
| CWE-644 | Improper Neutralization of HTTP Headers for Scripting Syntax | 2 | 2 | 13 |
| CWE-665 | Improper Initialization | 2 | 2 | 7 |
| CWE-668 | Exposure of Resource to Wrong Sphere | 3 | 3 | 4 |
| CWE-669 | Incorrect Resource Transfer Between Spheres | 1 | 1 | 4 |
| CWE-674 | Uncontrolled Recursion | 1 | 1 | 6 |
| CWE-693 | Protection Mechanism Failure | 1 | 1 | 10 |
| CWE-697 | Incorrect Comparison | 1 | 1 | 7 |
| CWE-698 | Execution After Redirect (EAR) | 2 | 2 | 5 |
| CWE-704 | Incorrect Type Conversion or Cast | 1 | 1 | 4 |
| CWE-705 | Incorrect Control Flow Scoping | 1 | 1 | 5 |
| CWE-706 | Use of Incorrectly-Resolved Name or Reference | 4 | 4 | 5 |
| CWE-707 | Improper Neutralization | 3 | 2 | 2 |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | 4 | 4 | 25 |
| CWE-755 | Improper Handling of Exceptional Conditions | 1 | 1 | 3 |
| CWE-770 | Allocation of Resources Without Limits or Throttling | 2 | 2 | 7 |
| CWE-776 | Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | 1 | 1 | 1 |
| CWE-787 | Out-of-bounds Write | 5 | 5 | 4 |
| CWE-791 | Incomplete Filtering of Special Elements | 2 | 2 | 10 |
| CWE-798 | Use of Hard-coded Credentials | 12 | 12 | 38 |
| CWE-824 | Access of Uninitialized Pointer | 1 | 1 | 4 |
| CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | 13 | 11 | 20 |
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | 1 | 1 | 12 |
| CWE-862 | Missing Authorization | 38 | 36 | 62 |
| CWE-863 | Incorrect Authorization | 14 | 14 | 35 |
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | 5 | 5 | 15 |
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2 | 2 | 16 |
| CWE-917 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') | 8 | 6 | 14 |
| CWE-918 | Server-Side Request Forgery (SSRF) | 318 | 245 | 79 |
| CWE-942 | Permissive Cross-domain Security Policy with Untrusted Domains | 2 | 2 | 11 |
| CWE-1021 | Improper Restriction of Rendered UI Layers or Frames | 1 | 1 | 1 |
| CWE-1188 | Initialization of a Resource with an Insecure Default | 4 | 4 | 23 |
| CWE-1220 | Insufficient Granularity of Access Control | 1 | 1 | 4 |
| CWE-1258 | Exposure of Sensitive System Information Due to Uncleared Debug Information | 1 | 1 | 1 |
| CWE-1284 | Improper Validation of Specified Quantity in Input | 1 | 1 | 1 |
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | 1 | 1 | 5 |
| CWE-1287 | Improper Validation of Specified Type of Input | 1 | 1 | 2 |
| CWE-1289 | Improper Validation of Unsafe Equivalence in Input | 1 | 1 | 1 |
| CWE-1321 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | 1 | 1 | 7 |
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | 13 | 12 | 21 |
| CWE-1390 | Weak Authentication | 1 | 1 | 1 |
| CWE-1391 | Use of Weak Credentials | 1 | 1 | 1 |
| CWE-1392 | Use of Default Credentials | 1 | 1 | 12 |