The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1428Reliance on HTTP instead of HTTPSBase2
CWE-1429Missing Security-Relevant Feedback for Unexecuted Operations in Hardware InterfaceBase0
CWE-143Improper Neutralization of Record DelimitersVariant1
CWE-1431Driving Intermediate Cryptographic State/Results to Hardware Module OutputsBase0
CWE-1434Insecure Setting of Generative AI/ML Model Inference ParametersBase0
CWE-144Improper Neutralization of Line DelimitersVariant3
CWE-145Improper Neutralization of Section DelimitersVariant1
CWE-146Improper Neutralization of Expression/Command DelimitersVariant10
CWE-147Improper Neutralization of Input TerminatorsVariant5
CWE-148Improper Neutralization of Input LeadersVariant3
CWE-149Improper Neutralization of Quoting SyntaxVariant5
CWE-15External Control of System or Configuration SettingBase70
CWE-150Improper Neutralization of Escape, Meta, or Control SequencesVariant73
CWE-151Improper Neutralization of Comment DelimitersVariant0
CWE-152Improper Neutralization of Macro SymbolsVariant0
CWE-153Improper Neutralization of Substitution CharactersVariant5
CWE-154Improper Neutralization of Variable Name DelimitersVariant1
CWE-155Improper Neutralization of Wildcards or Matching SymbolsVariant17
CWE-156Improper Neutralization of WhitespaceVariant4
CWE-157Failure to Sanitize Paired DelimitersVariant2
Page 15 of 49 · 969 total