CWE Top 25 Most Dangerous Software Weaknesses (2024)
CWE Top 25 2024: Authentication and Credentials

CWE Top 25 Most Dangerous Software Weaknesses (2024) CWE-306: Missing Authentication for Critical Function

Rank 25 in the 2024 CWE Top 25 (frequency x severity of CVEs). The software does not perform any authentication for functionality that requires a provable user identity or consumes significant resources.

Other controls in CWE Top 25 2024: Authentication and Credentials

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.