The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-378Creation of Temporary File With Insecure PermissionsBase42
CWE-379Creation of Temporary File in Directory with Insecure PermissionsBase62
CWE-38Path Traversal: '\absolute\pathname\here'Variant1
CWE-382J2EE Bad Practices: Use of System.exit()Variant0
CWE-383J2EE Bad Practices: Direct Use of ThreadsVariant0
CWE-384Session FixationCompound179
CWE-385Covert Timing ChannelBase35
CWE-386Symbolic Name not Mapping to Correct ObjectBase0
CWE-39Path Traversal: 'C:dirname'Variant1
CWE-390Detection of Error Condition Without ActionBase20
CWE-391Unchecked Error ConditionBase25
CWE-392Missing Report of Error ConditionBase12
CWE-393Return of Wrong Status CodeBase10
CWE-394Unexpected Status Code or Return ValueBase15
CWE-395Use of NullPointerException Catch to Detect NULL Pointer DereferenceBase11
CWE-396Declaration of Catch for Generic ExceptionBase2
CWE-397Declaration of Throws for Generic ExceptionBase0
CWE-40Path Traversal: '\\UNC\share\name\' (Windows UNC Share)Variant5
CWE-400Uncontrolled Resource ConsumptionClass2,024
CWE-401Missing Release of Memory after Effective LifetimeVariant408
Page 27 of 49 · 969 total