The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-30Path Traversal: '\dir\..\filename'Variant1
CWE-300Channel Accessible by Non-EndpointClass49
CWE-301Reflection Attack in an Authentication ProtocolBase1
CWE-302Authentication Bypass by Assumed-Immutable DataBase42
CWE-303Incorrect Implementation of Authentication AlgorithmBase91
CWE-304Missing Critical Step in AuthenticationBase39
CWE-305Authentication Bypass by Primary WeaknessBase152
CWE-306Missing Authentication for Critical FunctionBase1,877
CWE-307Improper Restriction of Excessive Authentication AttemptsBase410
CWE-308Use of Single-factor AuthenticationBase13
CWE-309Use of Password System for Primary AuthenticationBase1
CWE-31Path Traversal: 'dir\..\..\filename'Variant0
CWE-311Missing Encryption of Sensitive DataClass274
CWE-312Cleartext Storage of Sensitive InformationBase330
CWE-313Cleartext Storage in a File or on DiskVariant31
CWE-314Cleartext Storage in the RegistryVariant1
CWE-315Cleartext Storage of Sensitive Information in a CookieVariant6
CWE-316Cleartext Storage of Sensitive Information in MemoryVariant33
CWE-317Cleartext Storage of Sensitive Information in GUIVariant7
CWE-318Cleartext Storage of Sensitive Information in ExecutableVariant1
Page 23 of 49 · 969 total