CWE TOP25备份

1. 静态检查使用的CWE top25规则

网站如下:

CWE - 2023 CWE Top 25 Most Dangerous Software Weaknesses (mitre.org)

2. 展开列表如下 

1 Out-of-bounds Write
CWE-787CVEs in KEV: 70Rank Last Year: 1

2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79CVEs in KEV: 4Rank Last Year: 2

3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89CVEs in KEV: 6Rank Last Year: 3

4 Use After Free
CWE-416CVEs in KEV: 44Rank Last Year: 7 (up 3) upward trend

5 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78CVEs in KEV: 23Rank Last Year: 6 (up 1) upward trend

6 Improper Input Validation
CWE-20CVEs in KEV: 35Rank Last Year: 4 (down 2) downward trend

7 Out-of-bounds Read
CWE-125CVEs in KEV: 2Rank Last Year: 5 (down 2) downward trend

8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22CVEs in KEV: 16Rank Last Year: 8

9 Cross-Site Request Forgery (CSRF)
CWE-352CVEs in KEV: 0Rank Last Year: 9

10 Unrestricted Upload of File with Dangerous Type
CWE-434CVEs in KEV: 5Rank Last Year: 10

11 Missing Authorization
CWE-862CVEs in KEV: 0Rank Last Year: 16 (up 5) upward trend

12 NULL Pointer Dereference
CWE-476CVEs in KEV: 0Rank Last Year: 11 (down 1) downward trend

13 Improper Authentication
CWE-287CVEs in KEV: 10Rank Last Year: 14 (up 1) upward trend

14 Integer Overflow or Wraparound
CWE-190CVEs in KEV: 4Rank Last Year: 13 (down 1) downward trend

15 Deserialization of Untrusted Data
CWE-502CVEs in KEV: 14Rank Last Year: 12 (down 3) downward trend

16 Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-77CVEs in KEV: 4Rank Last Year: 17 (up 1) upward trend

17 Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-119CVEs in KEV: 7Rank Last Year: 19 (up 2) upward trend

18 Use of Hard-coded Credentials
CWE-798CVEs in KEV: 2Rank Last Year: 15 (down 3) downward trend

19 Server-Side Request Forgery (SSRF)
CWE-918CVEs in KEV: 16Rank Last Year: 21 (up 2) upward trend

20 Missing Authentication for Critical Function
CWE-306CVEs in KEV: 8Rank Last Year: 18 (down 2) downward trend

21 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-362CVEs in KEV: 8Rank Last Year: 22 (up 1) upward trend

22 Improper Privilege Management
CWE-269CVEs in KEV: 5Rank Last Year: 29 (up 7) upward trend

23 Improper Control of Generation of Code ('Code Injection')
CWE-94CVEs in KEV: 6Rank Last Year: 25 (up 2) upward trend

24 Incorrect Authorization
CWE-863CVEs in KEV: 0Rank Last Year: 28 (up 4) upward trend

25 Incorrect Default Permissions
CWE-276CVEs in KEV: 0Rank Last Year: 20 (down 5) downward trend

  • 20
    点赞
  • 15
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

青草地溪水旁

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值