The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-466Return of Pointer Value Outside of Expected RangeBase8
CWE-467Use of sizeof() on a Pointer TypeVariant3
CWE-468Incorrect Pointer ScalingBase3
CWE-469Use of Pointer Subtraction to Determine SizeBase1
CWE-47Path Equivalence: ' filename' (Leading Space)Variant0
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')Base73
CWE-471Modification of Assumed-Immutable Data (MAID)Base36
CWE-472External Control of Assumed-Immutable Web ParameterBase148
CWE-473PHP External Variable ModificationVariant4
CWE-474Use of Function with Inconsistent ImplementationsBase4
CWE-475Undefined Behavior for Input to APIBase13
CWE-476NULL Pointer DereferenceBase1,679
CWE-477Use of Obsolete FunctionBase16
CWE-478Missing Default Case in Multiple Condition ExpressionBase1
CWE-479Signal Handler Use of a Non-reentrant FunctionVariant2
CWE-48Path Equivalence: 'file name' (Internal Whitespace)Variant0
CWE-480Use of Incorrect OperatorBase9
CWE-481Assigning instead of ComparingVariant0
CWE-482Comparing instead of AssigningVariant1
CWE-483Incorrect Block DelimitationBase0
Page 31 of 49 · 969 total