The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1269Product Released in Non-Release ConfigurationBase2
CWE-127Buffer Under-readVariant8
CWE-1270Generation of Incorrect Security TokensBase9
CWE-1271Uninitialized Value on Reset for Registers Holding Security SettingsBase0
CWE-1272Sensitive Information Uncleared Before Debug/Power State TransitionBase1
CWE-1273Device Unlock Credential SharingBase0
CWE-1274Improper Access Control for Volatile Memory Containing Boot CodeBase7
CWE-1275Sensitive Cookie with Improper SameSite AttributeVariant27
CWE-1276Hardware Child Block Incorrectly Connected to Parent SystemBase0
CWE-1277Firmware Not UpdateableBase1
CWE-1278Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging TechniquesBase1
CWE-1279Cryptographic Operations are run Before Supporting Units are ReadyBase3
CWE-128Wrap-around ErrorBase4
CWE-1280Access Control Check Implemented After Asset is AccessedBase2
CWE-1281Sequence of Processor Instructions Leads to Unexpected BehaviorBase6
CWE-1282Assumed-Immutable Data is Stored in Writable MemoryBase8
CWE-1283Mutable Attestation or Measurement Reporting DataBase3
CWE-1284Improper Validation of Specified Quantity in InputBase247
CWE-1285Improper Validation of Specified Index, Position, or Offset in InputBase55
CWE-1286Improper Validation of Syntactic Correctness of InputBase86
Page 10 of 49 · 969 total