The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-319Cleartext Transmission of Sensitive InformationBase421
CWE-32Path Traversal: '...' (Triple Dot)Variant2
CWE-321Use of Hard-coded Cryptographic KeyVariant309
CWE-322Key Exchange without Entity AuthenticationBase25
CWE-323Reusing a Nonce, Key Pair in EncryptionBase43
CWE-324Use of a Key Past its Expiration DateBase20
CWE-325Missing Cryptographic StepBase58
CWE-326Inadequate Encryption StrengthClass147
CWE-327Use of a Broken or Risky Cryptographic AlgorithmClass343
CWE-328Use of Weak HashBase85
CWE-329Generation of Predictable IV with CBC ModeVariant11
CWE-33Path Traversal: '....' (Multiple Dot)Variant0
CWE-330Use of Insufficiently Random ValuesClass152
CWE-331Insufficient EntropyBase85
CWE-332Insufficient Entropy in PRNGVariant5
CWE-333Improper Handling of Insufficient Entropy in TRNGVariant1
CWE-334Small Space of Random ValuesBase14
CWE-335Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)Base16
CWE-336Same Seed in Pseudo-Random Number Generator (PRNG)Variant3
CWE-337Predictable Seed in Pseudo-Random Number Generator (PRNG)Variant13
Page 24 of 49 · 969 total