The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-24Path Traversal: '../filedir'Variant104
CWE-240Improper Handling of Inconsistent Structural ElementsBase4
CWE-241Improper Handling of Unexpected Data TypeBase29
CWE-242Use of Inherently Dangerous FunctionBase11
CWE-243Creation of chroot Jail Without Changing Working DirectoryVariant0
CWE-244Improper Clearing of Heap Memory Before Release ('Heap Inspection')Variant17
CWE-245J2EE Bad Practices: Direct Management of ConnectionsVariant0
CWE-246J2EE Bad Practices: Direct Use of SocketsVariant0
CWE-247DEPRECATED: Reliance on DNS Lookups in a Security DecisionBase0
CWE-248Uncaught ExceptionBase252
CWE-249DEPRECATED: Often Misused: Path ManipulationVariant6
CWE-25Path Traversal: '/../filedir'Variant13
CWE-250Execution with Unnecessary PrivilegesBase317
CWE-252Unchecked Return ValueBase97
CWE-253Incorrect Check of Function Return ValueBase24
CWE-256Plaintext Storage of a PasswordBase182
CWE-257Storing Passwords in a Recoverable FormatBase63
CWE-258Empty Password in Configuration FileVariant9
CWE-259Use of Hard-coded PasswordVariant166
CWE-26Path Traversal: '/dir/../filename'Variant13
Page 20 of 49 · 969 total