The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-201Insertion of Sensitive Information Into Sent DataBase388
CWE-202Exposure of Sensitive Information Through Data QueriesBase34
CWE-203Observable DiscrepancyBase193
CWE-204Observable Response DiscrepancyBase173
CWE-205Observable Behavioral DiscrepancyBase2
CWE-206Observable Internal Behavioral DiscrepancyVariant1
CWE-207Observable Behavioral Discrepancy With Equivalent ProductsVariant1
CWE-208Observable Timing DiscrepancyBase170
CWE-209Generation of Error Message Containing Sensitive InformationBase372
CWE-210Self-generated Error Message Containing Sensitive InformationBase4
CWE-211Externally-Generated Error Message Containing Sensitive InformationBase0
CWE-212Improper Removal of Sensitive Information Before Storage or TransferBase68
CWE-213Exposure of Sensitive Information Due to Incompatible PoliciesBase32
CWE-214Invocation of Process Using Visible Sensitive InformationBase30
CWE-215Insertion of Sensitive Information Into Debugging CodeBase19
CWE-216DEPRECATED: Containment Errors (Container Errors)Class4
CWE-217DEPRECATED: Failure to Protect Stored Data from ModificationBase0
CWE-218DEPRECATED: Failure to provide confidentiality for stored dataBase0
CWE-219Storage of File with Sensitive Data Under Web RootVariant5
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Base4,759
Page 18 of 49 · 969 total