The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1066Missing Serialization Control ElementBase1
CWE-1067Excessive Execution of Sequential Searches of Data ResourceBase0
CWE-1068Inconsistency Between Implementation and Documented DesignBase3
CWE-1069Empty Exception BlockVariant0
CWE-107Struts: Unused Validation FormVariant0
CWE-1070Serializable Data Element Containing non-Serializable Item ElementsBase0
CWE-1071Empty Code BlockBase0
CWE-1072Data Resource Access without Use of Connection PoolingBase1
CWE-1073Non-SQL Invokable Control Element with Excessive Number of Data Resource AccessesBase0
CWE-1074Class with Excessively Deep InheritanceBase0
CWE-1075Unconditional Control Flow Transfer outside of Switch BlockBase0
CWE-1076Insufficient Adherence to Expected ConventionsClass2
CWE-1077Floating Point Comparison with Incorrect OperatorVariant5
CWE-1078Inappropriate Source Code Style or FormattingClass1
CWE-1079Parent Class without Virtual Destructor MethodBase0
CWE-108Struts: Unvalidated Action FormVariant0
CWE-1080Source Code File with Excessive Number of Lines of CodeBase0
CWE-1082Class Instance Self Destruction Control ElementBase0
CWE-1083Data Access from Outside Expected Data Manager ComponentBase1
CWE-1084Invokable Control Element with Excessive File or Data Access OperationsBase0
Page 3 of 49 · 969 total