The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)Base131
CWE-339Small Seed Space in PRNGVariant2
CWE-34Path Traversal: '....//'Variant0
CWE-340Generation of Predictable Numbers or IdentifiersClass52
CWE-341Predictable from Observable StateBase12
CWE-342Predictable Exact Value from Previous ValuesBase6
CWE-343Predictable Value Range from Previous ValuesBase5
CWE-344Use of Invariant Value in Dynamically Changing ContextBase3
CWE-345Insufficient Verification of Data AuthenticityClass451
CWE-346Origin Validation ErrorClass381
CWE-347Improper Verification of Cryptographic SignatureBase545
CWE-348Use of Less Trusted SourceBase66
CWE-349Acceptance of Extraneous Untrusted Data With Trusted DataBase39
CWE-35Path Traversal: '.../...//'Variant172
CWE-350Reliance on Reverse DNS Resolution for a Security-Critical ActionVariant23
CWE-351Insufficient Type DistinctionBase14
CWE-352Cross-Site Request Forgery (CSRF)Compound5,281
CWE-353Missing Support for Integrity CheckBase37
CWE-354Improper Validation of Integrity Check ValueBase95
CWE-356Product UI does not Warn User of Unsafe ActionsBase29
Page 25 of 49 · 969 total