The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1385Missing Origin Validation in WebSocketsVariant34
CWE-1386Insecure Operation on Windows Junction / Mount PointBase15
CWE-1389Incorrect Parsing of Numbers with Different RadicesBase6
CWE-1390Weak AuthenticationClass80
CWE-1391Use of Weak CredentialsClass46
CWE-1392Use of Default CredentialsBase100
CWE-1393Use of Default PasswordBase40
CWE-1394Use of Default Cryptographic KeyBase18
CWE-1395Dependency on Vulnerable Third-Party ComponentClass41
CWE-14Compiler Removal of Code to Clear BuffersVariant10
CWE-140Improper Neutralization of DelimitersBase20
CWE-141Improper Neutralization of Parameter/Argument DelimitersVariant11
CWE-1419Incorrect Initialization of ResourceClass8
CWE-142Improper Neutralization of Value DelimitersVariant3
CWE-1420Exposure of Sensitive Information during Transient ExecutionBase4
CWE-1421Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient ExecutionBase4
CWE-1422Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient ExecutionBase1
CWE-1423Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient ExecutionBase6
CWE-1426Improper Validation of Generative AI OutputBase3
CWE-1427Improper Neutralization of Input Used for LLM PromptingBase11
Page 14 of 49 · 969 total