The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-423DEPRECATED: Proxied Trusted ChannelBase0
CWE-424Improper Protection of Alternate PathClass36
CWE-425Direct Request ('Forced Browsing')Base102
CWE-426Untrusted Search PathBase279
CWE-427Uncontrolled Search Path ElementBase789
CWE-428Unquoted Search Path or ElementBase335
CWE-43Path Equivalence: 'filename....' (Multiple Trailing Dot)Variant1
CWE-430Deployment of Wrong HandlerBase1
CWE-431Missing HandlerBase1
CWE-432Dangerous Signal Handler not Disabled During Sensitive OperationsBase0
CWE-433Unparsed Raw Web Content DeliveryVariant1
CWE-434Unrestricted Upload of File with Dangerous TypeBase2,463
CWE-435Improper Interaction Between Multiple Correctly-Behaving EntitiesPillar3
CWE-436Interpretation ConflictClass91
CWE-437Incomplete Model of Endpoint FeaturesBase3
CWE-439Behavioral Change in New Version or EnvironmentBase0
CWE-44Path Equivalence: 'file.name' (Internal Dot)Variant1
CWE-440Expected Behavior ViolationBase43
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')Class85
CWE-443DEPRECATED: HTTP response splittingBase1
Page 29 of 49 · 969 total