The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-402Transmission of Private Resources into a New Sphere ('Resource Leak')Class22
CWE-403Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')Base6
CWE-404Improper Resource Shutdown or ReleaseClass584
CWE-405Asymmetric Resource Consumption (Amplification)Class49
CWE-406Insufficient Control of Network Message Volume (Network Amplification)Class16
CWE-407Inefficient Algorithmic ComplexityClass137
CWE-408Incorrect Behavior Order: Early AmplificationBase7
CWE-409Improper Handling of Highly Compressed Data (Data Amplification)Base108
CWE-41Improper Resolution of Path EquivalenceBase28
CWE-410Insufficient Resource PoolClass21
CWE-412Unrestricted Externally Accessible LockBase5
CWE-413Improper Resource LockingBase14
CWE-414Missing Lock CheckBase4
CWE-415Double FreeVariant330
CWE-416Use After FreeVariant4,192
CWE-419Unprotected Primary ChannelBase11
CWE-42Path Equivalence: 'filename.' (Trailing Dot)Variant1
CWE-420Unprotected Alternate ChannelBase37
CWE-421Race Condition During Access to Alternate ChannelBase7
CWE-422Unprotected Windows Messaging Channel ('Shatter')Variant2
Page 28 of 49 · 969 total