The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-281Improper Preservation of PermissionsBase112
CWE-282Improper Ownership ManagementClass28
CWE-283Unverified OwnershipBase26
CWE-284Improper Access ControlPillar4,852
CWE-285Improper AuthorizationClass1,390
CWE-286Incorrect User ManagementClass26
CWE-287Improper AuthenticationClass1,856
CWE-288Authentication Bypass Using an Alternate Path or ChannelBase590
CWE-289Authentication Bypass by Alternate NameBase36
CWE-29Path Traversal: '\..\filename'Variant63
CWE-290Authentication Bypass by SpoofingBase402
CWE-291Reliance on IP Address for AuthenticationVariant9
CWE-292DEPRECATED: Trusting Self-reported DNS NameVariant0
CWE-293Using Referer Field for AuthenticationVariant1
CWE-294Authentication Bypass by Capture-replayBase145
CWE-295Improper Certificate ValidationBase650
CWE-296Improper Following of a Certificate's Chain of TrustBase17
CWE-297Improper Validation of Certificate with Host MismatchVariant57
CWE-298Improper Validation of Certificate ExpirationVariant6
CWE-299Improper Check for Certificate RevocationBase13
Page 22 of 49 · 969 total