CWE — cumulative coverage
349 of 969 CWE items carry authoritative control / attack-technique coverage. Each control's verdict is the strongest single inbound mapping; the bar shows the spread and the row shows how many sources (and from which frameworks) contribute. Authoritative mappings only.
Methodology update (2026-07-25). A policy control that mandates a technical control is
no longer counted as partial coverage of it: a policy analyzes and blocks nothing, so it
provides none of that control's protective effect. Those cross-layer links are re-authored as a
distinct governs / implements governance relation, off the coverage scale. Coverage numbers for
policy-heavy families drop accordingly — the honest correction, not a regression. Explore both on
the framework map (governance toggle).
Base 210/539 · 210 covered
CWE-494Download of Code Without Integrity CheckFull20 src · CAPEC 12, DISA STIG Rhel 7 2, MITRE ATT&CK 2, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 8 1, DISA STIG Oracle Linux 8 1, DISA STIG Rhel 9 1
CWE-306Missing Authentication for Critical FunctionFull10 src · CAPEC 4, DISA STIG Rhel 8 2, DISA STIG Rhel 7 2, DISA STIG Oracle Linux 8 2
CWE-288Authentication Bypass Using an Alternate Path or ChannelFull9 src · DISA STIG Rhel 7 3, DISA STIG Oracle Linux 9 2, DISA STIG Oracle Linux 8 2, CAPEC 1, MITRE ATT&CK 1
CWE-347Improper Verification of Cryptographic SignatureFull9 src · DISA STIG Oracle Linux 9 2, DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 2, DISA STIG Rhel 8 1, DISA STIG Rhel 9 1, CAPEC 1
CWE-354Improper Validation of Integrity Check ValueFull9 src · DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 2, DISA STIG Rhel 8 2, CAPEC 2, DISA STIG Oracle Linux 9 1
CWE-757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')Full9 src · CAPEC 3, DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1, MITRE ATT&CK 1
CWE-295Improper Certificate ValidationFull8 src · DISA STIG Oracle Linux 8 3, DISA STIG Rhel 7 2, DISA STIG Rhel 8 2, CAPEC 1
CWE-1188Initialization of a Resource with an Insecure DefaultFull7 src · DISA STIG Rhel 7 1, DISA STIG Windows Server 2019 1, DISA STIG Ubuntu 22 04 1, DISA STIG Ubuntu 24 04 1, CAPEC 1, DISA STIG Windows Server 2016 1, DISA STIG Oracle Linux 8 1
CWE-328Use of Weak HashFull7 src · CAPEC 2, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2022 1, DISA STIG Windows 10 1, DISA STIG Windows Server 2019 1
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Full7 src · CAPEC 5, NIST CSF 2.0 2
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Full7 src · CAPEC 5, NIST CSF 2.0 2
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')Full7 src · CAPEC 5, NIST CSF 2.0 2
CWE-1240Use of a Cryptographic Primitive with a Risky ImplementationFull6 src · DISA STIG Oracle Linux 8 2, DISA STIG Rhel 8 2, DISA STIG Oracle Linux 9 1, CAPEC 1
CWE-223Omission of Security-relevant InformationFull4 src · DISA STIG Ubuntu 22 04 2, DISA STIG Ubuntu 24 04 2
CWE-296Improper Following of a Certificate's Chain of TrustFull4 src · DISA STIG Oracle Linux 8 1, DISA STIG Rhel 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1
CWE-419Unprotected Primary ChannelFull3 src · DISA STIG Oracle Linux 8 2, DISA STIG Oracle Linux 9 1
CWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')Full1 src · CAPEC 1
CWE-770Allocation of Resources Without Limits or ThrottlingMostly25 src · CAPEC 19, DISA STIG Oracle Linux 8 2, DISA STIG Oracle Linux 9 2, DISA STIG Rhel 8 1, MITRE ATT&CK 1
CWE-290Authentication Bypass by SpoofingMostly15 src · CAPEC 10, MITRE ATT&CK 2, DISA STIG Oracle Linux 8 1, DISA STIG Rhel 7 1, DISA STIG Rhel 8 1
CWE-654Reliance on a Single Factor in a Security DecisionMostly15 src · CAPEC 9, MITRE ATT&CK 3, DISA STIG Ubuntu 22 04 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1
CWE-250Execution with Unnecessary PrivilegesMostly9 src · CAPEC 3, NIST CSF 2.0 1, DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1
CWE-307Improper Restriction of Excessive Authentication AttemptsMostly9 src · CAPEC 6, DISA STIG Rhel 7 2, MITRE ATT&CK 1
CWE-778Insufficient LoggingMostly9 src · DISA STIG Rhel 8 4, DISA STIG Oracle Linux 8 2, NIST CSF 2.0 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1
CWE-266Incorrect Privilege AssignmentMostly8 src · DISA STIG Ubuntu 24 04 2, DISA STIG Ubuntu 22 04 2, DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 8 1, DISA STIG Rhel 9 1
CWE-276Incorrect Default PermissionsMostly8 src · DISA STIG Windows Server 2016 2, DISA STIG Windows Server 2019 2, DISA STIG Windows Server 2022 2, CAPEC 1, MITRE ATT&CK 1
CWE-325Missing Cryptographic StepMostly8 src · DISA STIG Oracle Linux 8 2, DISA STIG Rhel 8 1, DISA STIG Ubuntu 22 04 1, DISA STIG Ubuntu 24 04 1, DISA STIG Oracle Linux 9 1, CAPEC 1, DISA STIG Rhel 7 1
CWE-348Use of Less Trusted SourceMostly8 src · CAPEC 4, DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 7 1, MITRE ATT&CK 1
CWE-353Missing Support for Integrity CheckMostly8 src · DISA STIG Oracle Linux 8 3, CAPEC 3, DISA STIG Rhel 8 1, MITRE ATT&CK 1
CWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereMostly8 src · CAPEC 2, DISA STIG Oracle Linux 8 2, DISA STIG Rhel 8 1, DISA STIG Ubuntu 22 04 1, DISA STIG Ubuntu 24 04 1, MITRE ATT&CK 1
CWE-1220Insufficient Granularity of Access ControlMostly7 src · NIST CSF 2.0 2, CAPEC 2, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2022 1, MITRE ATT&CK 1
CWE-842Placement of User into Incorrect GroupMostly7 src · DISA STIG Windows Server 2016 2, DISA STIG Windows Server 2019 2, DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2022 1
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Mostly6 src · CAPEC 5, NIST CSF 2.0 1
CWE-1125Excessive Attack SurfaceMostly5 src · DISA STIG Rhel 7 2, DISA STIG Oracle Linux 8 2, DISA STIG Rhel 8 1
CWE-1241Use of Predictable Algorithm in Random Number GeneratorMostly5 src · DISA STIG Oracle Linux 8 2, DISA STIG Rhel 8 2, CAPEC 1
CWE-212Improper Removal of Sensitive Information Before Storage or TransferMostly5 src · DISA STIG Oracle Linux 8 3, DISA STIG Rhel 8 1, DISA STIG Oracle Linux 9 1
CWE-312Cleartext Storage of Sensitive InformationMostly5 src · DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 8 1, MITRE ATT&CK 1, CAPEC 1
CWE-331Insufficient EntropyMostly5 src · DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 1, DISA STIG Rhel 8 1, CAPEC 1
CWE-749Exposed Dangerous Method or FunctionMostly5 src · DISA STIG Ubuntu 22 04 3, CAPEC 1, DISA STIG Ubuntu 24 04 1
CWE-1204Generation of Weak Initialization Vector (IV)Mostly4 src · DISA STIG Rhel 7 1, CAPEC 1, DISA STIG Oracle Linux 8 1, DISA STIG Rhel 8 1
CWE-649Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity CheckingMostly4 src · DISA STIG Rhel 8 2, CAPEC 1, DISA STIG Oracle Linux 9 1
CWE-924Improper Enforcement of Message Integrity During Transmission in a Communication ChannelMostly4 src · DISA STIG Oracle Linux 8 4
CWE-94Improper Control of Generation of Code ('Code Injection')Mostly4 src · CAPEC 3, NIST CSF 2.0 1
CWE-1269Product Released in Non-Release ConfigurationMostly3 src · DISA STIG Rhel 7 1, DISA STIG Oracle Linux 8 1, MITRE ATT&CK 1
CWE-1274Improper Access Control for Volatile Memory Containing Boot CodeMostly3 src · CAPEC 2, NIST CSF 2.0 1
CWE-281Improper Preservation of PermissionsMostly3 src · DISA STIG Windows Server 2022 2, DISA STIG Windows Server 2019 1
CWE-304Missing Critical Step in AuthenticationMostly3 src · DISA STIG Rhel 7 2, DISA STIG Ubuntu 22 04 1
CWE-338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)Mostly3 src · DISA STIG Oracle Linux 8 1, DISA STIG Ubuntu 22 04 1, DISA STIG Rhel 8 1
CWE-289Authentication Bypass by Alternate NameMostly2 src · DISA STIG Oracle Linux 8 1, DISA STIG Rhel 7 1
CWE-342Predictable Exact Value from Previous ValuesMostly2 src · DISA STIG Oracle Linux 8 1, DISA STIG Rhel 8 1
CWE-349Acceptance of Extraneous Untrusted Data With Trusted DataMostly1 src · DISA STIG Oracle Linux 8 1
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')Mostly1 src · CAPEC 1
CWE-829Inclusion of Functionality from Untrusted Control SpherePartial23 src · CAPEC 11, MITRE ATT&CK 6, DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 7 1, DISA STIG Rhel 8 1, DISA STIG Rhel 9 1, DISA STIG Windows 10 1
CWE-309Use of Password System for Primary AuthenticationPartial19 src · CAPEC 12, MITRE ATT&CK 6, DISA STIG Oracle Linux 8 1
CWE-552Files or Directories Accessible to External PartiesPartial12 src · MITRE ATT&CK 8, CAPEC 2, DISA STIG Oracle Linux 8 2
CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')Partial11 src · CAPEC 11
CWE-205Observable Behavioral DiscrepancyPartial7 src · CAPEC 2, DISA STIG Oracle Linux 8 2, MITRE ATT&CK 2, DISA STIG Oracle Linux 9 1
CWE-267Privilege Defined With Unsafe ActionsPartial7 src · DISA STIG Ubuntu 22 04 3, MITRE ATT&CK 2, CAPEC 1, DISA STIG Oracle Linux 9 1
CWE-226Sensitive Information in Resource Not Removed Before ReusePartial6 src · CAPEC 1, DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 8 1, DISA STIG Rhel 9 1, MITRE ATT&CK 1
CWE-268Privilege ChainingPartial6 src · DISA STIG Ubuntu 22 04 1, DISA STIG Ubuntu 24 04 1, DISA STIG Windows 10 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1
CWE-359Exposure of Private Personal Information to an Unauthorized ActorPartial6 src · CAPEC 4, DISA STIG Ubuntu 22 04 1, DISA STIG Ubuntu 24 04 1
CWE-509Replicating Malicious Code (Virus or Worm)Partial6 src · DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1, DISA STIG Oracle Linux 8 1
CWE-280Improper Handling of Insufficient Permissions or PrivilegesPartial5 src · DISA STIG Rhel 9 2, DISA STIG Oracle Linux 8 2, DISA STIG Oracle Linux 9 1
CWE-123Write-what-where ConditionPartial4 src · DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Oracle Linux 8 1, DISA STIG Rhel 8 1
CWE-1295Debug Messages Revealing Unnecessary InformationPartial4 src · CAPEC 1, DISA STIG Windows 10 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1
CWE-272Least Privilege ViolationPartial4 src · CAPEC 1, DISA STIG Ubuntu 24 04 1, DISA STIG Windows 10 1, DISA STIG Windows Server 2022 1
CWE-427Uncontrolled Search Path ElementPartial4 src · CAPEC 2, DISA STIG Oracle Linux 8 1, MITRE ATT&CK 1
CWE-1068Inconsistency Between Implementation and Documented DesignPartial3 src · DISA STIG Rhel 7 2, DISA STIG Oracle Linux 8 1
CWE-274Improper Handling of Insufficient PrivilegesPartial3 src · DISA STIG Oracle Linux 9 2, DISA STIG Rhel 9 1
CWE-508Non-Replicating Malicious CodePartial3 src · DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1
CWE-538Insertion of Sensitive Information into Externally-Accessible File or DirectoryPartial3 src · CAPEC 1, DISA STIG Oracle Linux 8 1, DISA STIG Rhel 8 1
CWE-1050Excessive Platform Resource Consumption within a LoopPartial2 src · DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1
CWE-1104Use of Unmaintained Third Party ComponentsPartial2 src · DISA STIG Oracle Linux 8 1, NIST CSF 2.0 1
CWE-1256Improper Restriction of Software Interfaces to Hardware FeaturesPartial2 src · NIST CSF 2.0 2
CWE-1258Exposure of Sensitive System Information Due to Uncleared Debug InformationPartial2 src · CAPEC 2
CWE-1264Hardware Logic with Insecure De-Synchronization between Control and Data ChannelsPartial2 src · CAPEC 2
CWE-1268Policy Privileges are not Assigned Consistently Between Control and Data AgentsPartial2 src · CAPEC 1, NIST CSF 2.0 1
CWE-1278Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging TechniquesPartial2 src · CAPEC 2
CWE-213Exposure of Sensitive Information Due to Incompatible PoliciesPartial2 src · DISA STIG Ubuntu 24 04 1, DISA STIG Windows Server 2019 1
CWE-283Unverified OwnershipPartial2 src · DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1
CWE-305Authentication Bypass by Primary WeaknessPartial2 src · DISA STIG Ubuntu 22 04 1, DISA STIG Ubuntu 24 04 1
CWE-335Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)Partial2 src · DISA STIG Oracle Linux 8 1, DISA STIG Rhel 8 1
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')Partial2 src · CAPEC 2
CWE-59Improper Link Resolution Before File Access ('Link Following')Partial2 src · CAPEC 1, MITRE ATT&CK 1
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')Partial2 src · CAPEC 2
CWE-96Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')Partial2 src · CAPEC 2
CWE-1051Initialization with Hard-Coded Network Resource Configuration DataPartial1 src · NIST CSF 2.0 1
CWE-1100Insufficient Isolation of System-Dependent FunctionsPartial1 src · DISA STIG Oracle Linux 9 1
CWE-1316Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected RangesPartial1 src · CAPEC 1
CWE-1342Information Exposure through Microarchitectural State after Transient ExecutionPartial1 src · CAPEC 1
CWE-379Creation of Temporary File in Directory with Insecure PermissionsPartial1 src · DISA STIG Oracle Linux 8 1
CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')Partial1 src · CAPEC 1
Class 69/114 · 69 covered
CWE-732Incorrect Permission Assignment for Critical ResourceFull20 src · CAPEC 7, MITRE ATT&CK 6, DISA STIG Windows Server 2016 2, DISA STIG Windows Server 2019 2, DISA STIG Windows Server 2022 2, DISA STIG Oracle Linux 8 1
CWE-311Missing Encryption of Sensitive DataFull19 src · CAPEC 9, NIST CSF 2.0 2, MITRE ATT&CK 2, DISA STIG Windows Server 2019 1, DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 8 1, DISA STIG Rhel 9 1, DISA STIG Windows Server 2016 1
CWE-327Use of a Broken or Risky Cryptographic AlgorithmFull14 src · CAPEC 7, DISA STIG Windows 10 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1, DISA STIG Oracle Linux 8 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1, NIST CSF 2.0 1
CWE-506Embedded Malicious CodeFull9 src · MITRE ATT&CK 4, CAPEC 3, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1
CWE-200Exposure of Sensitive Information to an Unauthorized ActorMostly77 src · CAPEC 39, MITRE ATT&CK 16, NIST CSF 2.0 15, DISA STIG Ubuntu 24 04 2, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1, DISA STIG Ubuntu 22 04 1, DISA STIG Windows 10 1
CWE-1357Reliance on Insufficiently Trustworthy ComponentMostly26 src · NIST CSF 2.0 18, DISA STIG Oracle Linux 9 3, DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 2, DISA STIG Rhel 8 1
CWE-285Improper AuthorizationMostly26 src · CAPEC 12, NIST CSF 2.0 4, MITRE ATT&CK 4, DISA STIG Rhel 7 3, DISA STIG Oracle Linux 8 2, DISA STIG Rhel 8 1
CWE-345Insufficient Verification of Data AuthenticityMostly26 src · CAPEC 12, MITRE ATT&CK 6, DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 2, DISA STIG Rhel 8 2, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1
CWE-287Improper AuthenticationMostly25 src · CAPEC 9, NIST CSF 2.0 6, DISA STIG Rhel 7 3, DISA STIG Ubuntu 24 04 2, MITRE ATT&CK 2, DISA STIG Ubuntu 22 04 1, DISA STIG Oracle Linux 8 1, DISA STIG Rhel 8 1
CWE-300Channel Accessible by Non-EndpointMostly14 src · CAPEC 8, DISA STIG Oracle Linux 8 4, DISA STIG Oracle Linux 9 1, MITRE ATT&CK 1
CWE-114Process ControlMostly12 src · DISA STIG Oracle Linux 8 3, CAPEC 2, MITRE ATT&CK 2, DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1
CWE-269Improper Privilege ManagementMostly12 src · NIST CSF 2.0 4, CAPEC 3, DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1
CWE-1391Use of Weak CredentialsMostly11 src · NIST CSF 2.0 6, DISA STIG Oracle Linux 8 3, DISA STIG Rhel 7 1, DISA STIG Rhel 8 1
CWE-330Use of Insufficiently Random ValuesMostly11 src · DISA STIG Oracle Linux 8 3, DISA STIG Rhel 8 3, CAPEC 3, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1
CWE-923Improper Restriction of Communication Channel to Intended EndpointsMostly10 src · CAPEC 4, DISA STIG Oracle Linux 8 2, DISA STIG Rhel 8 2, MITRE ATT&CK 1, DISA STIG Rhel 7 1
CWE-657Violation of Secure Design PrinciplesMostly8 src · DISA STIG Windows Server 2016 2, DISA STIG Windows Server 2019 2, DISA STIG Windows Server 2022 2, DISA STIG Ubuntu 24 04 1, DISA STIG Ubuntu 22 04 1
CWE-668Exposure of Resource to Wrong SphereMostly8 src · DISA STIG Oracle Linux 8 2, DISA STIG Windows 11 1, DISA STIG Windows Server 2019 1, DISA STIG Rhel 7 1, DISA STIG Windows 10 1, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2022 1
CWE-642External Control of Critical State DataMostly7 src · DISA STIG Oracle Linux 9 2, CAPEC 2, DISA STIG Oracle Linux 8 1, MITRE ATT&CK 1, DISA STIG Rhel 7 1
CWE-1390Weak AuthenticationMostly6 src · DISA STIG Rhel 7 1, DISA STIG Rhel 8 1, DISA STIG Ubuntu 22 04 1, DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Oracle Linux 8 1
CWE-326Inadequate Encryption StrengthMostly6 src · CAPEC 2, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 8 1, DISA STIG Rhel 9 1, DISA STIG Windows Server 2016 1
CWE-405Asymmetric Resource Consumption (Amplification)Mostly6 src · DISA STIG Oracle Linux 8 2, DISA STIG Oracle Linux 9 2, DISA STIG Rhel 8 2
CWE-653Improper Isolation or CompartmentalizationMostly6 src · DISA STIG Rhel 9 2, DISA STIG Oracle Linux 9 1, DISA STIG Windows 10 1, DISA STIG Windows 11 1, DISA STIG Windows Server 2016 1
CWE-862Missing AuthorizationMostly6 src · DISA STIG Rhel 7 2, DISA STIG Oracle Linux 8 2, CAPEC 1, MITRE ATT&CK 1
CWE-1263Improper Physical Access ControlMostly5 src · DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 2, CAPEC 1
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')Mostly5 src · CAPEC 5
CWE-340Generation of Predictable Numbers or IdentifiersMostly4 src · DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 1, DISA STIG Rhel 8 1
CWE-863Incorrect AuthorizationMostly4 src · DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 1, DISA STIG Rhel 8 1
CWE-754Improper Check for Unusual or Exceptional ConditionsMostly3 src · DISA STIG Oracle Linux 8 2, DISA STIG Oracle Linux 9 1
CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')Mostly2 src · CAPEC 2
CWE-402Transmission of Private Resources into a New Sphere ('Resource Leak')Mostly2 src · DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')Partial30 src · CAPEC 29, MITRE ATT&CK 1
CWE-119Improper Restriction of Operations within the Bounds of a Memory BufferPartial12 src · CAPEC 12
CWE-451User Interface (UI) Misrepresentation of Critical InformationPartial12 src · MITRE ATT&CK 7, CAPEC 5
CWE-424Improper Protection of Alternate PathPartial6 src · CAPEC 2, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1, DISA STIG Ubuntu 22 04 1, DISA STIG Ubuntu 24 04 1
CWE-410Insufficient Resource PoolPartial5 src · DISA STIG Oracle Linux 9 2, DISA STIG Rhel 8 2, DISA STIG Oracle Linux 8 1
CWE-282Improper Ownership ManagementPartial3 src · CAPEC 1, DISA STIG Windows Server 2016 1, MITRE ATT&CK 1
CWE-922Insecure Storage of Sensitive InformationPartial3 src · DISA STIG Windows Server 2016 2, DISA STIG Windows Server 2019 1
CWE-610Externally Controlled Reference to a Resource in Another SpherePartial2 src · CAPEC 1, DISA STIG Oracle Linux 8 1
CWE-75Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)Partial2 src · CAPEC 2
CWE-913Improper Control of Dynamically-Managed Code ResourcesPartial2 src · DISA STIG Windows 10 1, DISA STIG Windows 11 1
Variant 57/299 · 57 covered
CWE-258Empty Password in Configuration FileFull6 src · DISA STIG Oracle Linux 8 2, DISA STIG Oracle Linux 9 2, DISA STIG Rhel 7 2
CWE-313Cleartext Storage in a File or on DiskFull4 src · DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 8 1, DISA STIG Rhel 9 1
CWE-98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')Full1 src · CAPEC 1
CWE-333Improper Handling of Insufficient Entropy in TRNGMostly6 src · DISA STIG Oracle Linux 8 3, DISA STIG Rhel 8 2, DISA STIG Oracle Linux 9 1
CWE-539Use of Persistent Cookies Containing Sensitive InformationMostly6 src · CAPEC 4, MITRE ATT&CK 2
CWE-277Insecure Inherited PermissionsMostly5 src · DISA STIG Windows Server 2016 2, DISA STIG Windows Server 2019 2, DISA STIG Windows Server 2022 1
CWE-337Predictable Seed in Pseudo-Random Number Generator (PRNG)Mostly3 src · DISA STIG Oracle Linux 8 3
CWE-416Use After FreeMostly3 src · DISA STIG Rhel 9 1, DISA STIG Oracle Linux 8 1, DISA STIG Rhel 8 1
CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')Mostly2 src · CAPEC 2
CWE-230Improper Handling of Missing ValuesPartial6 src · DISA STIG Oracle Linux 8 4, DISA STIG Rhel 7 1, DISA STIG Ubuntu 24 04 1
CWE-318Cleartext Storage of Sensitive Information in ExecutablePartial6 src · CAPEC 2, DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1, DISA STIG Rhel 9 1, MITRE ATT&CK 1
CWE-314Cleartext Storage in the RegistryPartial3 src · CAPEC 1, DISA STIG Oracle Linux 8 1, MITRE ATT&CK 1
CWE-370Missing Check for Certificate Revocation after Initial CheckPartial3 src · CAPEC 1, DISA STIG Rhel 7 1, DISA STIG Ubuntu 24 04 1
CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)Partial3 src · CAPEC 3
CWE-121Stack-based Buffer OverflowPartial2 src · DISA STIG Oracle Linux 8 1, DISA STIG Oracle Linux 9 1
CWE-591Sensitive Data Storage in Improperly Locked MemoryPartial2 src · NIST CSF 2.0 1, DISA STIG Oracle Linux 8 1
CWE-86Improper Neutralization of Invalid Characters in Identifiers in Web PagesPartial2 src · CAPEC 2
CWE-1222Insufficient Granularity of Address Regions Protected by Register LocksPartial1 src · CAPEC 1
CWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')Partial1 src · CAPEC 1
CWE-207Observable Behavioral Discrepancy With Equivalent ProductsPartial1 src · DISA STIG Oracle Linux 8 1
CWE-316Cleartext Storage of Sensitive Information in MemoryPartial1 src · DISA STIG Oracle Linux 9 1
CWE-528Exposure of Core Dump File to an Unauthorized Control SpherePartial1 src · DISA STIG Oracle Linux 8 1
Pillar 7/10 · 7 covered
CWE-284Improper Access ControlMostly52 src · CAPEC 17, MITRE ATT&CK 17, NIST CSF 2.0 10, DISA STIG Oracle Linux 9 2, DISA STIG Oracle Linux 8 2, DISA STIG Rhel 7 2, DISA STIG Rhel 8 2
CWE-693Protection Mechanism FailureMostly31 src · CAPEC 17, MITRE ATT&CK 6, DISA STIG Windows 10 2, DISA STIG Oracle Linux 8 2, DISA STIG Windows Server 2016 1, DISA STIG Windows Server 2019 1, DISA STIG Windows Server 2022 1, DISA STIG Windows 11 1
CWE-664Improper Control of a Resource Through its LifetimeMostly16 src · MITRE ATT&CK 8, CAPEC 5, DISA STIG Windows Server 2016 2, DISA STIG Windows Server 2019 1
CWE-691Insufficient Control Flow ManagementPartial3 src · CAPEC 1, DISA STIG Windows 10 1, DISA STIG Windows 11 1
Compound 6/7 · 6 covered
"Cumulative" here means breadth of corroboration, not summed coverage: overlapping partial mappings are NOT added up into "full". The headline per control is the best-attested single mapping, shown alongside the count and source frameworks behind it.