The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1048Invokable Control Element with Large Number of Outward CallsBase0
CWE-1049Excessive Data Query Operations in a Large Data TableBase3
CWE-105Struts: Form Field Without ValidatorVariant0
CWE-1050Excessive Platform Resource Consumption within a LoopBase15
CWE-1051Initialization with Hard-Coded Network Resource Configuration DataBase1
CWE-1052Excessive Use of Hard-Coded Literals in InitializationBase0
CWE-1053Missing Documentation for DesignBase0
CWE-1054Invocation of a Control Element at an Unnecessarily Deep Horizontal LayerBase0
CWE-1055Multiple Inheritance from Concrete ClassesBase1
CWE-1056Invokable Control Element with Variadic ParametersBase0
CWE-1057Data Access Operations Outside of Expected Data Manager ComponentBase1
CWE-1058Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member ElementBase0
CWE-1059Insufficient Technical DocumentationClass3
CWE-106Struts: Plug-in Framework not in UseVariant0
CWE-1060Excessive Number of Inefficient Server-Side Data AccessesBase0
CWE-1061Insufficient EncapsulationClass0
CWE-1062Parent Class with References to Child ClassBase0
CWE-1063Creation of Class Instance within a Static Code BlockBase0
CWE-1064Invokable Control Element with Signature Containing an Excessive Number of ParametersBase0
CWE-1065Runtime Resource Management Control Element in a Component Built to Run on Application ServersBase0
Page 2 of 49 · 969 total