| | | | | Very High | Total Very High | | QC-VHIGH | |
| | | Very High | | Recursive unix signal handler | | QC-CWE??? | |
| | | Very High | | OS command injection | | QC-CWE078 | |
| | | Very High | | Basic XSS | | QC-CWE080 | |
| | | Very High | | SQL Injection | | QC-CWE089 | |
| | | Very High | | Insufficient control of directives in dynamically evaluated code | | QC-CWE095 | |
| | | Very High | | Insufficient control of filename for include / require statement | | QC-CWE098 | |
| | | Very High | | Ressource injection | | QC-CWE099 | |
| | | Very High | | division by ZERO | | QC-CWE369 | |
| | | Very High | | Unrestricted lock of critical ressource, deadlock | | QC-CWE412 | |
| | | Very High | | Use of externally-controlled (unsafe reflection) | | QC-CWE470 | |
| | | Very High | | call to Thread run() instead of start() | | QC-CWE572 | |
| | | Very High | | variable extraction error | | QC-CWE621 | |
| | | Very High | | executable regular expression error | | QC-CWE624 | |
| | | | High | | Insufficient control of directives in statically saved code | | QC-CWE096 | |
| | | High | | null pointer reference | | QC-CWE476 | |
| | | High | | Omitted Break Statement in Switch | | QC-CWE484 | |
| | | High | | condition NEVER true | | QC-CWE570 | |
| | | High | | Incomplete identification of uploaded file | | QC-CWE616 | |
| | | Medium | Total Medium | | QC-MEDIUM | |
| | | | Medium | | Detection of error condition without action | | QC-CWE390 | |
| | | Medium | | Failure de report error in status code | | QC-CWE392 | |
| | | Medium | | Assigning instead of comparing | | QC-CWE481 | |
| | | Medium | | Critical public variable without final modifier | | QC-CWE493 | |
| | | Medium | | Return inside finally block | | QC-CWE584 | |
| | | | Low | | return type of function is not tested | | QC-CWE252 | |
| | | Low | | Static public field not marked final | | QC-CWE500 | |
| | | Low | | Array declared public, final and static | | QC-CWE582 | |
| | | Low | | The software contains an empty synchronized block | | QC-CWE585 | |
| | | Low | | Null byte interaction error on | | QC-CWE626 | |
| | | Low | | Dynamic variable evaluation for variable | | QC-CWE627 | |
| | |