The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')Base258
CWE-446UI Discrepancy for Security FeatureClass3
CWE-447Unimplemented or Unsupported Feature in UIBase3
CWE-448Obsolete Feature in UIBase3
CWE-449The UI Performs the Wrong ActionBase12
CWE-45Path Equivalence: 'file...name' (Multiple Internal Dot)Variant0
CWE-450Multiple Interpretations of UI InputBase2
CWE-451User Interface (UI) Misrepresentation of Critical InformationClass151
CWE-453Insecure Default Variable InitializationVariant16
CWE-454External Initialization of Trusted Variables or Data StoresBase4
CWE-455Non-exit on Failed InitializationBase2
CWE-456Missing Initialization of a VariableVariant8
CWE-457Use of Uninitialized VariableVariant220
CWE-458DEPRECATED: Incorrect InitializationBase0
CWE-459Incomplete CleanupBase92
CWE-46Path Equivalence: 'filename ' (Trailing Space)Variant1
CWE-460Improper Cleanup on Thrown ExceptionBase21
CWE-462Duplicate Key in Associative List (Alist)Variant1
CWE-463Deletion of Data Structure SentinelBase1
CWE-464Addition of Data Structure SentinelBase0
Page 30 of 49 · 969 total