The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1287Improper Validation of Specified Type of InputBase143
CWE-1288Improper Validation of Consistency within InputBase28
CWE-1289Improper Validation of Unsafe Equivalence in InputBase32
CWE-129Improper Validation of Array IndexVariant312
CWE-1290Incorrect Decoding of Security IdentifiersBase0
CWE-1291Public Key Re-Use for Signing both Debug and Production CodeBase1
CWE-1292Incorrect Conversion of Security IdentifiersBase0
CWE-1293Missing Source Correlation of Multiple Independent DataBase0
CWE-1294Insecure Security Identifier MechanismClass1
CWE-1295Debug Messages Revealing Unnecessary InformationBase21
CWE-1296Incorrect Chaining or Granularity of Debug ComponentsBase0
CWE-1297Unprotected Confidential Information on Device is Accessible by OSAT VendorsBase0
CWE-1298Hardware Logic Contains Race ConditionsBase2
CWE-1299Missing Protection Mechanism for Alternate Hardware InterfaceBase10
CWE-13ASP.NET Misconfiguration: Password in Configuration FileVariant0
CWE-130Improper Handling of Length Parameter InconsistencyBase95
CWE-1300Improper Protection of Physical Side ChannelsBase34
CWE-1301Insufficient or Incomplete Data Removal within Hardware ComponentBase2
CWE-1302Missing Source Identifier in Entity Transactions on a System-On-Chip (SOC)Base0
CWE-1303Non-Transparent Sharing of Microarchitectural ResourcesBase5
Page 11 of 49 · 969 total