Tikslumo matavimas

Mes netvirtiname tikslumo. Mes jį įrodome.

Atkartojamas Cybseco deterministinio variklio matavimas su versijuojamu, rankomis pažymėtu korpusu: preciziškumas, atkūrimas ir F1 pagal CWE, pagal kalbą ir pagal analizės sluoksnį, kiekvieną sluoksnį, kurio nematuojame, įvardijant ir paaiškinant.

0.0%
Preciziškumas
0.0%
Atkūrimas
0
Korpuso atvejai
121 CWE · 22 lang
6
Klaidingai teigiami
931 true positives

Kiekvienas atvejis, kiekvienas srautas

Kiekvienas taškas yra korpuso atvejis; kiekviena linija seka nepatikimą įvestį iki jos panaudojimo vietos, nuspalvinta pagal pažeidžiamumo klasę. Ištisinė = aptikta, punktyrinė = sąžininga riba.

py_sqli_fstring · CWE-89py_sqli_interproc · CWE-89py_sqli_deep_interproc · CWE-89py_sqli_container · CWE-89py_sqli_attr · CWE-89py_sqli_container_return · CWE-89py_sqli_crossfile · CWE-89py_sqli_crossfile_star · CWE-89js_sqli_query · CWE-89js_sqli_concat · CWE-89ts_sqli_query · CWE-89php_sqli · CWE-89java_sqli · CWE-89go_sqli · CWE-89ruby_sqli · CWE-89rust_sqli · CWE-89shell_sqli · CWE-89csharp_sqli · CWE-89kotlin_sqli · CWE-89dart_sqli · CWE-89swift_sqli · CWE-89sql_dynamic · CWE-89py_sql · CWE-89js_sql · CWE-89ts_sql · CWE-89php_sql · CWE-89php_laravel_raw_sql · CWE-89rb_sql · CWE-89java_sql_jpql · CWE-89java_sql_jdbc · CWE-89scala_sql · CWE-89go_sql_injection · CWE-89csharp_raw_sql · CWE-89rust_sql_injection · CWE-89shell_sql_inj · CWE-89sql_injection_dynamic · CWE-89sql_update_no_where · CWE-89sql_delete_no_where · CWE-89swift_taint_sql · CWE-89dart_taint_sql · CWE-89w3_sql_89format · CWE-89llm_output_sql · CWE-89py_cmdi_ossystem · CWE-78py_cmdi_subprocess · CWE-78js_cmdi_childproc · CWE-78py_deep_crossfile · CWE-78js_cmdi_spawn_shell · CWE-78js_cmd_exec · CWE-78ts_cmd_exec · CWE-78php_cmd · CWE-78kotlin_cmd · CWE-78rust_cmd · CWE-78ruby_cmd · CWE-78go_cmd · CWE-78py_subprocess_shell · CWE-78py_os_system · CWE-78js_exec · CWE-78js_spawn_shell · CWE-78ts_exec · CWE-78php_command · CWE-78rb_command · CWE-78rb_backtick · CWE-78java_command · CWE-78scala_command · CWE-78go_os_command · CWE-78rust_command_injection · CWE-78shell_cmd_inj_ssh · CWE-78shell_rm_rf · CWE-78sql_os_command · CWE-78swift_taint_process · CWE-78dart_taint_process · CWE-78cs_os_command · CWE-78llm_output_shell · CWE-78c_command_injection_env · CWE-78c_command_injection_via_snprintf · CWE-78 · frontiercpp_system_command_injection · CWE-78py_ssrf_requests · CWE-918py_ssrf_interproc · CWE-918py_ssrf_paramflow · CWE-918py_ssrf_listflow · CWE-918py_ssrf_global · CWE-918py_ssrf_augassign · CWE-918py_ssrf_crossfile · CWE-918py_ssrf_crossfile_param · CWE-918py_ssrf_crossfile_star · CWE-918py_ssrf_str_transform · CWE-918 · frontierjs_ssrf_fetch · CWE-918ts_ssrf_fetch · CWE-918rust_ssrf · CWE-918py_ssrf · CWE-918js_ssrf · CWE-918ts_ssrf · CWE-918java_ssrf · CWE-918kotlin_ssrf · CWE-918go_ssrf · CWE-918sql_network_egress · CWE-918php_ssrf · CWE-918rb_ssrf · CWE-918cs_ssrf · CWE-918shell_ssrf_918 · CWE-918swift_ssrf_918 · CWE-918dart_ssrf_918 · CWE-918llm_output_ssrf · CWE-918py_pathtraversal_open · CWE-22py_pathtrav_var · CWE-22py_pathtrav_osremove · CWE-22py_pathtrav_interproc · CWE-22js_pathtrav_readfile · CWE-22ts_pathtrav_read · CWE-22rust_path · CWE-22ruby_path · CWE-22go_path · CWE-22java_path · CWE-22py_path · CWE-22js_path · CWE-22ts_path · CWE-22rb_path · CWE-22java_path_traversal · CWE-22kotlin_path_traversal · CWE-22go_path_traversal · CWE-22rust_path_traversal · CWE-22shell_path_inj · CWE-22shell_archive_extract · CWE-22swift_taint_filesystem · CWE-22dart_taint_filesystem · CWE-22cs_path_traversal · CWE-22sql_w4_path_22 · CWE-22llm_output_path · CWE-22c_path_traversal_cgi · CWE-22py_weakcrypto_md5 · CWE-327py_weakcrypto_des · CWE-327py_ecb_mode · CWE-327py_weakhash_sha1 · CWE-327js_weakcrypto_createcipher · CWE-327py_md5 · CWE-327py_sha1 · CWE-327php_weak_hash · CWE-327rb_weak_hash · CWE-327java_weak_crypto · CWE-327scala_weak_crypto · CWE-327go_weak_crypto · CWE-327sql_weak_hash · CWE-327swift_weak_hash · CWE-327dart_weak_hash · CWE-327ts_weakcrypto · CWE-327cs_weak_crypto · CWE-327rs_weak_crypto · CWE-327shell_weak_crypto_327 · CWE-327c_weak_hash_md5 · CWE-327cpp_weak_hash_md5 · CWE-327py_chmod_world · CWE-732go_file_permissions · CWE-732shell_chmod_broad · CWE-732sql_grant_public · CWE-732sql_grant_all · CWE-732php_perms_tp · CWE-732rb_perms_tp · CWE-732java_loose_permissions · CWE-732kt_loose_permissions · CWE-732scala_loose_permissions · CWE-732cs_file_permissions · CWE-732rust_file_permissions · CWE-732swift_cwe732_no_file_protection · CWE-732dart_cwe732_world_writable · CWE-732tf_public_snapshot · CWE-732k8s_writable_root_filesystem · CWE-732docker_world_writable · CWE-732gha_permissions_write_all · CWE-732gha_no_permissions · CWE-732c_world_writable_permissions · CWE-732java_hardcoded_secret · CWE-798go_hardcoded_secret · CWE-798csharp_hardcoded_secret · CWE-798php_hardcoded_secret · CWE-798shell_hardcoded_secret · CWE-798swift_hardcoded_secret · CWE-798tf_secret_inline · CWE-798rb_secret · CWE-798scala_hardcoded_secret · CWE-798dart_hardcoded_secret · CWE-798sql_hardcoded_cred · CWE-798kt_hardcoded_secret · CWE-798llm_api_key · CWE-798k8s_plaintext_secret · CWE-798docker_hardcoded_secret · CWE-798compose_hardcoded_secret · CWE-798compose_secret_mapping_form · CWE-798 · frontiergha_hardcoded_secret · CWE-798jenkins_hardcoded_secret · CWE-798cpp_hardcoded_secret · CWE-798js_xss_innerhtml · CWE-79js_xss_documentwrite · CWE-79py_markup_xss · CWE-79php_xss · CWE-79py_markup · CWE-79js_document_write · CWE-79js_innerhtml · CWE-79ts_innerhtml · CWE-79rb_render_inline · CWE-79rb_raw_xss · CWE-79kotlin_webview_xss · CWE-79scala_twirl_xss · CWE-79swift_taint_webview · CWE-79dart_taint_webview · CWE-79java_reflected_xss · CWE-79go_xss · CWE-79cs_xss · CWE-79rs_xss · CWE-79sh_w4_xss_79 · CWE-79tf_http_listener · CWE-319shell_cleartext_http · CWE-319dart_cleartext_http · CWE-319php_cleartext · CWE-319rb_cleartext · CWE-319java_cleartext · CWE-319kt_cleartext · CWE-319scala_cleartext · CWE-319go_cleartext · CWE-319cs_cleartext · CWE-319rs_cleartext · CWE-319sql_cleartext_319 · CWE-319py_cleartext_http · CWE-319js_cleartext_http · CWE-319ts_cleartext_http · CWE-319gitlab_dind_no_tls · CWE-319gitops_plaintext_source · CWE-319cloud_azure_storage_http_allowed · CWE-319cloud_gcp_sql_no_ssl · CWE-319tf_k8s_privileged · CWE-250shell_sudo_shell · CWE-250sql_security_definer · CWE-250sql_untrusted_lang · CWE-250llm_dangerous_tool · CWE-250llm_mcp_shell · CWE-250k8s_privileged_container · CWE-250k8s_runs_as_root · CWE-250k8s_dangerous_capability · CWE-250k8s_default_serviceaccount · CWE-250docker_no_user · CWE-250docker_user_root · CWE-250compose_privileged · CWE-250compose_docker_socket · CWE-250compose_dangerous_capability · CWE-250compose_user_root · CWE-250compose_capability_block_form · CWE-250 · frontiergitlab_privileged_service · CWE-250py_deser_pickle · CWE-502py_deser_yaml · CWE-502py_deser_marshal · CWE-502py_pickle · CWE-502py_yaml · CWE-502php_deserialize · CWE-502rb_deserialize · CWE-502java_deserialization · CWE-502kotlin_deserialization · CWE-502scala_deserialization · CWE-502csharp_binaryformatter · CWE-502rust_deserialize · CWE-502swift_insecure_unarchive · CWE-502go_unsafe_deser · CWE-502js_unsafe_deser · CWE-502ts_unsafe_deser · CWE-502llm_unsafe_switch · CWE-502py_ssl_noverify · CWE-295ts_tls_reject · CWE-295py_requests_noverify · CWE-295py_urllib3_warnings · CWE-295java_permissive_tls · CWE-295kotlin_trust_all_tls · CWE-295scala_trust_all_tls · CWE-295go_insecure_tls · CWE-295shell_tls_disabled · CWE-295swift_trust_all · CWE-295dart_trust_all · CWE-295js_tls_reject · CWE-295cs_tls_trust_all · CWE-295rs_tls_trust_all · CWE-295tf_insecure_tls · CWE-295docker_tls_verification_disabled · CWE-295ci_tls_verification_disabled · CWE-295py_openredirect_var · CWE-601py_openredirect_concat · CWE-601js_openredirect · CWE-601ts_openredirect · CWE-601py_redirect · CWE-601js_redirect · CWE-601php_redirect · CWE-601rb_redirect · CWE-601java_open_redirect · CWE-601go_open_redirect · CWE-601rust_open_redirect · CWE-601dart_taint_redirect · CWE-601kt_open_redirect · CWE-601scala_open_redirect · CWE-601cs_open_redirect · CWE-601swift_redirect_601 · CWE-601sh_w4_redirect_601 · CWE-601go_weak_tls_version · CWE-326tf_weak_tls_policy · CWE-326php_keysize_tp · CWE-326rb_keysize_tp · CWE-326java_weakkey · CWE-326kt_weakkey · CWE-326sc_weakkey · CWE-326rs_keysize_326 · CWE-326cs_keysize_326 · CWE-326w3_sw_326 · CWE-326w3_da_326 · CWE-326py_weak_rsa_key · CWE-326js_weak_key · CWE-326ts_weak_key · CWE-326sql_w4_cipher_326 · CWE-326sh_w4_keysize_326 · CWE-326cloud_azure_storage_weak_tls · CWE-326py_xxe_lxml · CWE-611py_xxe_flow · CWE-611py_xxe · CWE-611java_xxe · CWE-611php_xxe · CWE-611rb_xxe · CWE-611kt_xxe · CWE-611scala_xxe · CWE-611go_xxe · CWE-611cs_xxe · CWE-611swift_xxe_611 · CWE-611js_xxe · CWE-611ts_xxe · CWE-611rs_xxe_611 · CWE-611sql_w4_xxe_611 · CWE-611sh_w4_xxe_611 · CWE-611terraform_open_sg · CWE-284tf_open_sg · CWE-284tf_iam_wildcard · CWE-284csharp_allow_anonymous · CWE-284sql_tenant_no_rls · CWE-284sql_policy_no_check · CWE-284cloud_azure_storage_public_blobs · CWE-284cloud_azure_keyvault_public · CWE-284cloud_azure_aks_public_api · CWE-284cloud_azure_sql_public · CWE-284cloud_azure_nsg_ssh_open · CWE-284cloud_gcp_iam_public_member · CWE-284cloud_gcp_sql_open_to_world · CWE-284cloud_gcp_instance_public_ip · CWE-284cloud_gcp_serial_port_enabled · CWE-284cloud_cfn_s3_public_read · CWE-284php_weak_random · CWE-338java_weak_random · CWE-338go_insecure_random · CWE-338swift_weak_random · CWE-338ts_weak_random · CWE-338rb_random · CWE-338kt_weak_random · CWE-338scala_weak_random · CWE-338cs_weak_random · CWE-338rs_weak_random · CWE-338shell_weak_random_338 · CWE-338sql_weak_random_338 · CWE-338dart_weak_random_338 · CWE-338py_weak_random · CWE-338c_weak_random_token · CWE-338cpp_weak_random_key · CWE-338csharp_jwt_misconfig · CWE-347php_jwt · CWE-347rb_jwt · CWE-347java_jwt_no_verify · CWE-347java_jwt_alg_none · CWE-347kt_jwt_no_verify · CWE-347scala_jwt_no_verify · CWE-347go_jwt · CWE-347rs_jwt · CWE-347swift_jwt_347 · CWE-347dart_jwt_347 · CWE-347py_jwt_no_verify · CWE-347js_jwt_no_verify · CWE-347ts_jwt_no_verify · CWE-347sql_w4_jwt_347 · CWE-347sh_w4_jwt_347 · CWE-347py_codeexec_eval · CWE-94js_codeexec_eval · CWE-94rb_code · CWE-94java_code_injection · CWE-94kt_code_injection · CWE-94scala_code_injection · CWE-94go_code_injection · CWE-94cs_code_injection · CWE-94shell_source_remote_94 · CWE-94swift_nsexpr_94 · CWE-94sql_w4_code_94 · CWE-94w4_da_94 · CWE-94llm_output_exec · CWE-94gha_expression_injection · CWE-94azdo_expression_injection · CWE-94py_xpath_injection · CWE-643py_xpath · CWE-643rb_xpath_tp · CWE-643java_xpath_injection · CWE-643kt_xpath_injection · CWE-643scala_xpath_injection · CWE-643go_xpath_injection · CWE-643cs_xpath_injection · CWE-643rust_xpath_injection · CWE-643js_xpath_injection · CWE-643ts_xpath_injection · CWE-643php_xpath_tp · CWE-643sql_w4_xpath_643 · CWE-643sh_w4_xpath_643 · CWE-643w4_da_643 · CWE-643java_weak_password_encoder · CWE-916php_pwhash_tp · CWE-916rb_pwhash_tp · CWE-916java_weak_password_hash · CWE-916kt_weak_password_hash · CWE-916scala_weak_password_hash · CWE-916go_weak_password_hash · CWE-916cs_weak_password_hash · CWE-916rust_weak_password_hash · CWE-916swift_cwe916_weak_password_hash · CWE-916dart_cwe916_weak_password_hash · CWE-916py_weak_password_hash · CWE-916js_weak_password_hash · CWE-916ts_weak_password_hash · CWE-916sql_w4_pwhash_916 · CWE-916php_hardcoded_key_tp · CWE-321rb_hardcoded_key_tp · CWE-321java_hardcoded_key · CWE-321kt_hardcoded_key · CWE-321scala_hardcoded_key · CWE-321go_hardcoded_crypto_key · CWE-321cs_hardcoded_crypto_key · CWE-321rust_hardcoded_crypto_key · CWE-321shell_cwe321_hardcoded_key · CWE-321swift_cwe321_hardcoded_key · CWE-321dart_cwe321_hardcoded_key · CWE-321py_hardcoded_key · CWE-321js_hardcoded_key · CWE-321ts_hardcoded_key · CWE-321sql_w4_key_321 · CWE-321php_errexp_tp · CWE-209rb_errexp_tp · CWE-209java_errordisc · CWE-209kt_errordisc · CWE-209sc_errordisc · CWE-209go_errexpose_209 · CWE-209rs_errexpose_209 · CWE-209cs_errexpose_209 · CWE-209w3_sh_209 · CWE-209w3_sw_209 · CWE-209w3_da_209 · CWE-209py_debug_traceback · CWE-209js_error_stack · CWE-209ts_error_stack · CWE-209sql_w4_error_209 · CWE-209php_sessexp_tp · CWE-613rb_sessexp_tp · CWE-613java_sessionexp · CWE-613kt_sessionexp · CWE-613sc_sessionexp · CWE-613go_session_613 · CWE-613rs_session_613 · CWE-613cs_session_613 · CWE-613w3_sw_613 · CWE-613w3_da_613 · CWE-613py_jwt_no_expiry · CWE-613js_jwt_no_expiry · CWE-613ts_jwt_no_expiry · CWE-613sql_w4_session_613 · CWE-613sh_w4_session_613 · CWE-613java_sensitive_log · CWE-532kotlin_sensitive_log · CWE-532scala_sensitive_log · CWE-532rust_log_sensitive · CWE-532php_senslog_tp · CWE-532rb_senslog_tp · CWE-532go_sensitivelog_532 · CWE-532cs_sensitivelog_532 · CWE-532w3_sh_532 · CWE-532py_sensitive_log · CWE-532js_sensitive_log · CWE-532ts_sensitive_log · CWE-532gha_secret_echoed · CWE-532azdo_system_debug · CWE-532csharp_insecure_cookie · CWE-614php_cookie · CWE-614rb_cookie · CWE-614java_insecure_cookie · CWE-614kt_insecure_cookie · CWE-614scala_insecure_cookie · CWE-614go_insecure_cookie · CWE-614rs_insecure_cookie · CWE-614swift_cookie_614 · CWE-614py_insecure_cookie · CWE-614js_insecure_cookie · CWE-614ts_insecure_cookie · CWE-614w3_sh_614 · CWE-614w4_da_614 · CWE-614sql_sensitive_plaintext · CWE-312swift_userdefaults_secret · CWE-312dart_insecure_token_storage · CWE-312tf_ssm_cleartext · CWE-312php_clearstore_tp · CWE-312rb_storage_tp · CWE-312java_cleartext_store · CWE-312kt_cleartext_store · CWE-312sc_cleartext_store · CWE-312go_cleartext_312 · CWE-312rs_cleartext_312 · CWE-312cs_cleartext_312 · CWE-312w3_sh_312 · CWE-312w3_sw_312 · CWE-312php_upload_tp · CWE-434rb_upload_tp · CWE-434java_unrestricted_upload · CWE-434kt_unrestricted_upload · CWE-434scala_unrestricted_upload · CWE-434go_unrestricted_upload · CWE-434cs_unrestricted_upload · CWE-434rust_unrestricted_upload · CWE-434shell_cwe434_unrestricted_upload · CWE-434swift_cwe434_unrestricted_upload · CWE-434dart_cwe434_unrestricted_upload · CWE-434py_unrestricted_upload · CWE-434js_unrestricted_upload · CWE-434ts_unrestricted_upload · CWE-434php_loginjection_tp · CWE-117rb_loginjection_tp · CWE-117java_log_injection · CWE-117kt_log_injection · CWE-117scala_log_injection · CWE-117go_log_injection · CWE-117cs_log_injection · CWE-117rust_log_injection · CWE-117shell_cwe117_log_injection · CWE-117swift_cwe117_log_injection · CWE-117dart_cwe117_log_injection · CWE-117py_log_injection · CWE-117js_log_injection · CWE-117ts_log_injection · CWE-117py_redos · CWE-1333php_redos_tp · CWE-1333rb_redos_tp · CWE-1333java_redos · CWE-1333kt_redos · CWE-1333scala_redos · CWE-1333go_redos · CWE-1333cs_redos · CWE-1333rust_redos · CWE-1333js_redos · CWE-1333ts_redos · CWE-1333sql_w4_regex_1333 · CWE-1333w4_da_1333 · CWE-1333php_header_injection_tp · CWE-113rb_header_injection_tp · CWE-113java_header_injection · CWE-113kt_header_injection · CWE-113scala_header_injection · CWE-113go_header_injection · CWE-113cs_header_injection · CWE-113rust_header_injection · CWE-113shell_cwe113_header_injection · CWE-113swift_cwe113_header_injection · CWE-113dart_cwe113_header_injection · CWE-113js_header_injection · CWE-113ts_header_injection · CWE-113php_clickjacking_tp · CWE-1021rb_clickjacking_tp · CWE-1021java_clickjacking · CWE-1021kt_clickjacking · CWE-1021scala_clickjacking · CWE-1021go_clickjacking · CWE-1021cs_clickjacking · CWE-1021rust_clickjacking · CWE-1021swift_cwe1021_clickjacking · CWE-1021dart_cwe1021_clickjacking · CWE-1021py_clickjacking · CWE-1021js_clickjacking · CWE-1021ts_clickjacking · CWE-1021php_trustb_tp · CWE-501rb_trustb_tp · CWE-501java_trustboundary · CWE-501kt_trustboundary · CWE-501sc_trustboundary · CWE-501go_trustboundary_501 · CWE-501rs_trustboundary_501 · CWE-501cs_trustboundary_501 · CWE-501w3_sw_501 · CWE-501w3_da_501 · CWE-501py_session_trust · CWE-501js_session_trust · CWE-501ts_session_trust · CWE-501csharp_dynamic_linq · CWE-943php_nosql · CWE-943rb_nosql · CWE-943java_nosql_injection · CWE-943kt_nosql_injection · CWE-943scala_nosql_injection · CWE-943go_nosql · CWE-943rs_nosql · CWE-943py_nosql_where · CWE-943js_nosql_injection · CWE-943ts_nosql_injection · CWE-943w4_da_943 · CWE-943shell_net_inj · CWE-88php_arginj_tp · CWE-88rb_arginj_tp · CWE-88java_arginject · CWE-88kt_arginject · CWE-88sc_arginject · CWE-88go_arginj_88 · CWE-88rs_arginj_88 · CWE-88cs_arginj_88 · CWE-88js_arg_injection · CWE-88ts_arg_injection · CWE-88w4_da_88 · CWE-88sql_pwpolicy_521 · CWE-521tf_weak_password_policy · CWE-521php_pwpolicy_tp · CWE-521rb_pwpolicy_tp · CWE-521java_weakpwpolicy · CWE-521kt_weakpwpolicy · CWE-521sc_weakpwpolicy · CWE-521go_pwpolicy_521 · CWE-521rs_pwpolicy_521 · CWE-521cs_pwpolicy_521 · CWE-521sh_w4_weakpass_521 · CWE-521w4_da_521 · CWE-521php_sessfix_tp · CWE-384rb_sessfix_tp · CWE-384java_session_fixation · CWE-384kt_session_fixation · CWE-384scala_session_fixation · CWE-384go_session_fixation · CWE-384cs_session_fixation · CWE-384rust_session_fixation · CWE-384swift_cwe384_session_fixation · CWE-384dart_cwe384_session_fixation · CWE-384js_session_fixation · CWE-384ts_session_fixation · CWE-384php_xmlexp_tp · CWE-776rb_xmlexp_tp · CWE-776java_xxe_expansion · CWE-776kt_xxe_expansion · CWE-776sc_xxe_expansion · CWE-776go_xxe776 · CWE-776rs_xmlexp_776 · CWE-776cs_xmlexp_776 · CWE-776py_xxe_expansion · CWE-776js_xxe_expansion · CWE-776ts_xxe_expansion · CWE-776sh_w4_xmlbomb_776 · CWE-776py_ssti_jinja · CWE-1336py_ssti_flow_var · CWE-1336py_ssti · CWE-1336php_ssti · CWE-1336java_ssti · CWE-1336kt_ssti · CWE-1336scala_ssti · CWE-1336rs_ssti · CWE-1336js_ssti · CWE-1336ts_ssti · CWE-1336w4_da_1336 · CWE-1336tf_db_encryption · CWE-311php_cleartext311_tp · CWE-311rb_transport_tp · CWE-311java_cleartext_tx · CWE-311kt_cleartext_tx · CWE-311sc_cleartext_tx · CWE-311go_missingenc_311 · CWE-311rs_missingenc_311 · CWE-311cs_missingenc_311 · CWE-311w4_da_311 · CWE-311cloud_aws_ebs_no_encryption · CWE-311scala_reflect · CWE-470java_reflection · CWE-470kotlin_reflection · CWE-470scala_reflection · CWE-470csharp_reflection_load · CWE-470php_reflection_tp · CWE-470rb_reflection_tp · CWE-470go_reflection_470 · CWE-470sh_w4_indirect_470 · CWE-470w4_da_470 · CWE-470rb_mass_write · CWE-285php_authz_tp · CWE-285java_missingauthz · CWE-285kt_missingauthz · CWE-285sc_missingauthz · CWE-285go_authz_285 · CWE-285rs_authz_285 · CWE-285cs_authz_285 · CWE-285w3_sql_285 · CWE-285w4_da_285 · CWE-285rb_cors · CWE-942java_cors_wildcard · CWE-942go_cors_wildcard · CWE-942csharp_cors_wildcard · CWE-942php_cors · CWE-942rs_cors · CWE-942py_cors_wildcard · CWE-942js_cors_wildcard · CWE-942tf_cors_wildcard · CWE-942ts_cors_wildcard · CWE-942rust_async_blocking · CWE-400php_resource_tp · CWE-400rb_resource_tp · CWE-400java_resource · CWE-400kt_resource · CWE-400sc_resource · CWE-400go_resource_400 · CWE-400cs_resource_400 · CWE-400w3_sh_400 · CWE-400w3_sql_400 · CWE-400rb_ldap · CWE-90java_ldap_injection · CWE-90kt_ldap_injection · CWE-90scala_ldap_injection · CWE-90go_ldap · CWE-90cs_ldap · CWE-90rs_ldap · CWE-90py_ldap_injection · CWE-90sh_w4_ldap_90 · CWE-90w4_da_90 · CWE-90py_exec_user · CWE-95js_codeexec_vm · CWE-95py_dynimport_taint · CWE-95py_eval · CWE-95py_exec · CWE-95js_eval · CWE-95ts_eval · CWE-95php_eval · CWE-95shell_dynamic_eval · CWE-95tf_k8s_host_namespace · CWE-668csharp_open_swagger · CWE-668sql_remote_db · CWE-668k8s_host_network · CWE-668k8s_datastore_exposed · CWE-668docker_sensitive_port · CWE-668compose_host_network · CWE-668compose_host_namespace · CWE-668compose_sensitive_port_published · CWE-668php_laravel_mass_assign · CWE-915rb_permit_bang · CWE-915java_mass_assignment · CWE-915kt_mass_assignment · CWE-915scala_mass_assignment · CWE-915go_mass_assignment · CWE-915cs_mass_assignment · CWE-915rust_mass_assignment · CWE-915w4_da_915 · CWE-915java_improper_encoding · CWE-116php_encoding_tp · CWE-116rb_encoding_tp · CWE-116kt_improper_encoding · CWE-116sc_improper_encoding · CWE-116go_encoding_116 · CWE-116rs_encoding_116 · CWE-116cs_encoding_116 · CWE-116w4_da_116 · CWE-116php_wp_ajax_nonce · CWE-352rb_csrf · CWE-352java_csrf_disabled · CWE-352csharp_disable_antiforgery · CWE-352kt_csrf_disabled · CWE-352js_csrf_samesite · CWE-352ts_csrf_samesite · CWE-352w4_da_352 · CWE-352tf_iam_admin · CWE-269sql_cwe269_role_escalation · CWE-269k8s_privilege_escalation · CWE-269k8s_rbac_wildcard · CWE-269k8s_cluster_admin_binding · CWE-269cloud_azure_aks_rbac_disabled · CWE-269cloud_gcp_gke_legacy_abac · CWE-269tf_kms_short_deletion · CWE-693java_headers_disabled · CWE-693llm_safety_off · CWE-693compose_sandbox_disabled · CWE-693jenkins_agent_any · CWE-693cloud_azure_keyvault_no_purge_protection · CWE-693cloud_aws_rds_no_deletion_protection · CWE-693rust_static_mut · CWE-362java_race · CWE-362kt_race · CWE-362sc_race · CWE-362go_datarace_362 · CWE-362sh_w4_race_362 · CWE-362w4_da_362 · CWE-362rust_unbounded_channel · CWE-770tf_no_throttling · CWE-770sql_w4_recursion_770 · CWE-770sh_w4_unbounded_770 · CWE-770w4_da_770 · CWE-770k8s_no_resource_limits · CWE-770c_alloca_unbounded · CWE-770py_idor_object · CWE-639rb_idor_object · CWE-639js_idor_object · CWE-639java_idor_object · CWE-639php_idor_object · CWE-639csharp_idor_object · CWE-639go_idor_object · CWE-639php_wp_rest_open · CWE-862rb_authz · CWE-862tf_lambda_public · CWE-862w4_da_862 · CWE-862py_missing_authz · CWE-862java_missing_authz · CWE-862php_laravel_open_route · CWE-306csharp_signalr_no_auth · CWE-306rust_open_route · CWE-306tf_no_auth · CWE-306rb_missauth_tp · CWE-306w3_sql_306 · CWE-306sql_cwe522_weak_auth · CWE-522php_credprot_tp · CWE-522rb_credprot_tp · CWE-522go_credurl_522 · CWE-522cs_credurl_522 · CWE-522sh_w4_credperm_522 · CWE-522tf_no_minor_upgrade · CWE-1104llm_legacy_model · CWE-1104k8s_image_not_pinned · CWE-1104docker_image_not_pinned · CWE-1104gitlab_image_not_pinned · CWE-1104circleci_image_not_pinned · CWE-1104py_mktemp · CWE-377java_temp_file · CWE-377shell_predictable_temp · CWE-377w4_da_377 · CWE-377c_mktemp_race · CWE-377java_hardcoded_iv · CWE-329kt_hardcoded_iv · CWE-329scala_hardcoded_iv · CWE-329sql_w4_iv_329 · CWE-329sh_w4_nosalt_329 · CWE-329gha_action_unpinned · CWE-1357gha_action_mutable_ref · CWE-1357circleci_orb_mutable · CWE-1357argocd_mutable_target_revision · CWE-1357cloud_aws_ecr_mutable_tags · CWE-1357shell_pipe_to_shell · CWE-494docker_remote_code_execution · CWE-494docker_add_remote_url · CWE-494ci_remote_script_execution · CWE-494w3_sql_359 · CWE-359w3_sw_359 · CWE-359w3_da_359 · CWE-359sh_w4_pii_359 · CWE-359c_strcpy_unbounded · CWE-120c_sprintf_overflow · CWE-120c_strcat_unbounded · CWE-120cpp_strcpy_unbounded · CWE-120py_flask_debug · CWE-489php_debug_on · CWE-489w4_da_489 · CWE-489tf_logging_trail_off · CWE-778sql_w4_audit_778 · CWE-778sh_w4_audit_778 · CWE-778php_filesystem · CWE-73sql_file_write · CWE-73sql_file_read · CWE-73go_debug_endpoint · CWE-215csharp_debug_endpoint · CWE-215sh_w4_debug_215 · CWE-215go_integer_overflow · CWE-190rust_integer_overflow · CWE-190cs_intoverflow_190 · CWE-190llm_remote_prompt · CWE-829gha_pull_request_target_checkout · CWE-829gitlab_remote_include · CWE-829py_weak_random_token · CWE-330js_weak_random · CWE-330php_lfi · CWE-98sh_w4_rfi_98 · CWE-98tf_kms_rotation · CWE-320csharp_weak_dataprotection · CWE-320rb_default_scope · CWE-1284sh_w4_quantity_1284 · CWE-1284rb_hosts · CWE-20c_scanf_unbounded · CWE-20scala_unsafe_cast · CWE-704swift_force_cast · CWE-704go_unsafe_pkg · CWE-119rust_unsafe_taint · CWE-119go_panic_exposed · CWE-248swift_force_try · CWE-248shell_ignored_failure · CWE-703w4_da_703 · CWE-703sql_select_star · CWE-1050sql_leading_wildcard · CWE-1050swift_taint_urlopen · CWE-939dart_taint_urllaunch · CWE-939swift_webview_js_bridge · CWE-749dart_webview_js_bridge · CWE-749shell_cred_in_url · CWE-598w4_da_598 · CWE-598js_prototype_pollution · CWE-1321ts_prototype_pollution · CWE-1321tf_default_admin_user · CWE-1188tf_imdsv1 · CWE-16php_var_injection · CWE-621java_jndi · CWE-74java_spel · CWE-917kotlin_intent · CWE-926kotlin_globalscope · CWE-664rust_transmute · CWE-843rust_get_unchecked · CWE-125rust_mem_zeroed · CWE-457rust_lock_across_await · CWE-667rust_detached_task · CWE-665shell_ssh_no_hostkey · CWE-322sql_plaintext_password · CWE-256sql_dirty_read · CWE-662shell_secret_arg · CWE-214tf_mfa_disabled · CWE-308tf_log_validation · CWE-354tf_public_ip · CWE-1327tf_unrestricted_nacl · CWE-923tf_kms_wildcard_policy · CWE-266tf_public_bucket_policy · CWE-1220tf_cloudfront_http · CWE-419tf_force_destroy · CWE-404tf_public_redshift · CWE-497sql_w4_header_807 · CWE-807sql_w4_setconfig_15 · CWE-15sh_w4_toctou_367 · CWE-367llm_indirect_injection · CWE-77llm_secret_in_prompt · CWE-200k8s_hostpath_volume · CWE-552docker_no_healthcheck · CWE-754c_gets_unbounded · CWE-242c_strncpy_no_terminator · CWE-170c_format_string_argv · CWE-134cpp_missing_virtual_destructor · CWE-1079897891822327732798793192505022956013266112843383479464391632120961353261431243411713331131021501943885213847761336311470285942400909566891511635226969336277063986230652211043773291357494359120489778732151908293309832012842070411924870310509397495981321118816621749179266648431254576676653222566622143083541327923266122041940449780715367772005527542421701341079Nepatikima įvestis
Aptikta Sąžininga riba (dokumentuota) 546 Saugūs atvejai · 6 FP

Aprėptis pagal analizės sluoksnį

Kiekvienas Cybseco tiekiamas sluoksnis čia išvardytas, matuotas ar ne. Kiekvienas skaičius apima tik savo eilutės sluoksnį. Skaitykite visą metodiką

Sluoksniai, kurių šis matavimas nematuoja

Cybseco juos tiekia. Nė vienas skaičius aukščiau jų neaprašo, ir štai kodėl.

  • Dependency vulnerabilities (SCA) — Produced by external scanners that read a live vulnerability database. Their output changes when the database changes, with no change to Cybseco, so a precision figure measured today would describe the database rather than the engine and would not reproduce tomorrow.
  • Standalone secret scanning — Gitleaks is an external binary and is not installed for this benchmark. Hardcoded credentials found by Cybseco's own analyzers are measured, inside the code and CI/CD layers, under CWE-798 and CWE-532.
  • Third-party SAST (Semgrep, Bandit) — An external ruleset Cybseco orchestrates but does not author. Measuring it would report Semgrep's accuracy, not Cybseco's.
  • Licence compliance policy — A policy decision about a project's licences, not a judgement about its code. The corpus labels vulnerabilities, so a licence finding has nothing to be right or wrong against here.
  • LLM-assisted analysis — Its output depends on a model and a prompt rather than on the engine, and it is not part of the deterministic result this benchmark measures.
  • Graph, attack paths, decision engine — A different kind of claim: these produce paths and plans, not findings, so precision and recall over labelled lines cannot express them. The methodology page explains what could be measured, and which of these cannot honestly be reduced to a percentage at all. Publishing a number before the method is settled is how a benchmark stops being evidence.

Kas matuojama

SluoksnisKorpuso atvejaiSaugūs atvejaiTPFPFNMatuoti radiniaiPreciziškumasAtkūrimas
Application code (18 languages)130649781000810100.0%100.0%
Terraform (HCL semantics)431033103497.1%100.0%
Cloud IaC rules (AWS, Azure, GCP)267190019100.0%100.0%
Kubernetes manifests206140014100.0%100.0%
Dockerfile166100010100.0%100.0%
Docker Compose1569009100.0%100.0%
CI/CD pipelines (7 platforms)30822102395.7%100.0%
LLM and AI agent integration code241014401877.8%100.0%

Matuoti radiniai yra teisingai teigiami plius klaidingai teigiami: radinių skaičius, iš kurio buvo apskaičiuotas tos eilutės preciziškumas. Sluoksnis su nedaug radinių turi atitinkamai plačią paklaidą abiem kryptimis. 100,0 % iš devynių radinių ir 100,0 % iš aštuonių šimtų yra tas pats skaičius, bet ne tas pats įrodymas.

LLM ir DI agentų integracijos kodo sluoksnis analizuoja pačios programos integracijos kodą ieškodamas LLM ir agentų klaidų. Tai nėra jokio Cybseco viduje esančio dirbtinio intelekto matas: šis matavimas paleidžia deterministinį variklį be modelio cikle.

Žinomi klaidingai teigiami

Radiniai, kuriuos variklis pateikia kode, kuris nėra pažeidžiamas. Jie skaičiuojami prieš aukščiau nurodytą preciziškumą, o ne pašalinami iš jo.

  • CWE-798 cybseco-cicd — `DEPLOY_TOKEN = credentials('deploy-token')` is the documented Jenkins idiom for *not* committing a credential: it binds a value stored in the credential store. The rule sees NAME = <call> and reports a hardcoded secret.
  • CWE-284 cybseco-terraform — The rule reads source_address_prefix and destination_address_prefix into one list and fires if any entry is `*`. Here the wildcard is the destination, which on an inbound NSG rule means 'anywhere inside the protected scope'; the source is a bastion subnet, 10.1.0.0/24.
  • CWE-78 cybseco-llm — The completion is used as a key into a table of commands the developer wrote, and a key outside the table is refused before the call. Nothing the model emits becomes a command. This is the recommended mitigation for the vulnerability the rule looks for.
  • CWE-89 cybseco-llm — The SQL text is a constant; the model only selects which named query to run, and the value travels as a bound parameter. The rule fires on a completion and a query execution appearing in the same function.
  • CWE-918 cybseco-llm — The host is compared against a frozen allow-list and the request is refused otherwise, so metadata endpoints and internal services are unreachable. The rule does not see the check between the completion and the request.
  • CWE-200 cybseco-llm — `page_token` is a pagination cursor. The sensitive-name pattern matches the word `token` regardless of what it holds.

Aprėptis pagal CWE

Aptikimo dalis pagal pažeidžiamumo klasę, klaidingai teigiamus įskaičiuojant, o ne nurašant prielaida.

CWE-8942 TP · 1 FP
SQL injection
CWE-7833 TP · 1 FP
Command injection
CWE-2226 TP · 0 FP
Path traversal
CWE-91826 TP · 1 FP
SSRF
CWE-32721 TP · 0 FP
Weak crypto
CWE-73220 TP · 0 FP
Weak permissions
CWE-31919 TP · 0 FP
CWE-7919 TP · 0 FP
XSS
CWE-79819 TP · 1 FP
CWE-25017 TP · 0 FP
CWE-29517 TP · 0 FP
TLS verification
CWE-32617 TP · 0 FP
CWE-50217 TP · 0 FP
Unsafe deserialization
CWE-60117 TP · 0 FP
Open redirect
CWE-28416 TP · 1 FP
Access misconfiguration
CWE-33816 TP · 0 FP
Weak randomness
CWE-34716 TP · 0 FP
CWE-61116 TP · 0 FP
XXE
CWE-20915 TP · 0 FP
CWE-32115 TP · 0 FP
CWE-61315 TP · 0 FP
CWE-64315 TP · 0 FP
XPath injection
CWE-91615 TP · 0 FP
CWE-9415 TP · 0 FP
Code injection
CWE-11714 TP · 0 FP
CWE-31214 TP · 0 FP
CWE-43414 TP · 0 FP
CWE-53214 TP · 0 FP
CWE-61414 TP · 0 FP
CWE-102113 TP · 0 FP
CWE-11313 TP · 0 FP
CWE-133313 TP · 0 FP
ReDoS
CWE-50113 TP · 0 FP
CWE-38412 TP · 0 FP
CWE-52112 TP · 0 FP
CWE-77612 TP · 0 FP
CWE-8812 TP · 0 FP
CWE-94312 TP · 0 FP
CWE-133611 TP · 0 FP
Template injection
CWE-31111 TP · 0 FP
CWE-28510 TP · 0 FP
CWE-40010 TP · 0 FP
CWE-47010 TP · 0 FP
Unsafe reflection
CWE-9010 TP · 0 FP
CWE-94210 TP · 0 FP
CWE-1169 TP · 0 FP
CWE-6689 TP · 0 FP
CWE-9159 TP · 0 FP
CWE-959 TP · 0 FP
Code injection
CWE-3528 TP · 0 FP
CWE-2697 TP · 0 FP
CWE-3627 TP · 0 FP
CWE-6397 TP · 0 FP
CWE-6937 TP · 0 FP
CWE-7707 TP · 0 FP
CWE-11046 TP · 0 FP
CWE-3066 TP · 0 FP
CWE-5226 TP · 0 FP
CWE-8626 TP · 0 FP
CWE-13575 TP · 0 FP
CWE-3295 TP · 0 FP
CWE-3775 TP · 0 FP
Insecure temp file
CWE-1204 TP · 0 FP
CWE-3594 TP · 0 FP
CWE-4944 TP · 0 FP
CWE-7784 TP · 0 FP
CWE-1903 TP · 0 FP
CWE-2153 TP · 0 FP
CWE-4893 TP · 0 FP
Debug enabled
CWE-733 TP · 0 FP
CWE-8293 TP · 0 FP
CWE-10502 TP · 0 FP
CWE-1192 TP · 0 FP
CWE-12842 TP · 0 FP
CWE-13212 TP · 0 FP
CWE-202 TP · 0 FP
CWE-2482 TP · 0 FP
CWE-3202 TP · 0 FP
CWE-3302 TP · 0 FP
Weak randomness
CWE-5982 TP · 0 FP
CWE-7032 TP · 0 FP
CWE-7042 TP · 0 FP
CWE-7492 TP · 0 FP
CWE-9392 TP · 0 FP
CWE-982 TP · 0 FP
File inclusion
CWE-10791 TP · 0 FP
CWE-11881 TP · 0 FP
CWE-12201 TP · 0 FP
CWE-1251 TP · 0 FP
CWE-13271 TP · 0 FP
CWE-1341 TP · 0 FP
CWE-151 TP · 0 FP
CWE-161 TP · 0 FP
CWE-1701 TP · 0 FP
CWE-2001 TP · 1 FP
CWE-2141 TP · 0 FP
CWE-2421 TP · 0 FP
CWE-2561 TP · 0 FP
CWE-2661 TP · 0 FP
CWE-3081 TP · 0 FP
CWE-3221 TP · 0 FP
CWE-3541 TP · 0 FP
CWE-3671 TP · 0 FP
CWE-4041 TP · 0 FP
CWE-4191 TP · 0 FP
CWE-4571 TP · 0 FP
CWE-4971 TP · 0 FP
CWE-5521 TP · 0 FP
CWE-6211 TP · 0 FP
CWE-6621 TP · 0 FP
CWE-6641 TP · 0 FP
CWE-6651 TP · 0 FP
CWE-6671 TP · 0 FP
CWE-741 TP · 0 FP
CWE-7541 TP · 0 FP
CWE-771 TP · 0 FP
Command injection
CWE-8071 TP · 0 FP
CWE-8431 TP · 0 FP
CWE-9171 TP · 0 FP
CWE-9231 TP · 0 FP
CWE-9261 TP · 0 FP

Duomenų srautų formos, kurias variklis seka

Tas pats užterštumo (taint) patvirtinimas galioja kiekvienam iš šių srautų ir per failus.

› Intra-procedural› Inter-procedural (return)› Multi-level helpers› Parameter taint› Container elements› Instance attributes› Module globals› Augmented assignment› Embedded source› Cross-file (import)› Cross-file (wildcard)› Cross-file (parameter)

Aprėptis: deterministinis vietinis ir semantinis variklis, jokių išorinių skaitytuvų, jokio LLM, tas pats variklis, kuris visur pristatomas identiškas. Norite pamatyti jį su savo kodu? Užsisakyti demonstraciją.

Pamatykite, kaip Cybseco analizuoja realią sistemą

Peržiūrėkite interaktyvią demonstraciją, tada paprašykite vadovaujamo bandomojo laikotarpio savo komandai.