The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-528Exposure of Core Dump File to an Unauthorized Control SphereVariant2
CWE-529Exposure of Access Control List Files to an Unauthorized Control SphereVariant1
CWE-53Path Equivalence: '\multiple\\internal\backslash'Variant0
CWE-530Exposure of Backup File to an Unauthorized Control SphereVariant12
CWE-531Inclusion of Sensitive Information in Test CodeVariant2
CWE-532Insertion of Sensitive Information into Log FileBase730
CWE-533DEPRECATED: Information Exposure Through Server Log FilesVariant1
CWE-534DEPRECATED: Information Exposure Through Debug Log FilesVariant3
CWE-535Exposure of Information Through Shell Error MessageVariant0
CWE-536Servlet Runtime Error Message Containing Sensitive InformationVariant0
CWE-537Java Runtime Error Message Containing Sensitive InformationVariant0
CWE-538Insertion of Sensitive Information into Externally-Accessible File or DirectoryBase83
CWE-539Use of Persistent Cookies Containing Sensitive InformationVariant6
CWE-54Path Equivalence: 'filedir\' (Trailing Backslash)Variant0
CWE-540Inclusion of Sensitive Information in Source CodeBase30
CWE-541Inclusion of Sensitive Information in an Include FileVariant1
CWE-542DEPRECATED: Information Exposure Through Cleanup Log FilesVariant0
CWE-543Use of Singleton Pattern Without Synchronization in a Multithreaded ContextVariant0
CWE-544Missing Standardized Error Handling MechanismBase5
CWE-545DEPRECATED: Use of Dynamic Class LoadingVariant0
Page 34 of 49 · 969 total