The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-566Authorization Bypass Through User-Controlled SQL Primary KeyVariant7
CWE-567Unsynchronized Access to Shared Data in a Multithreaded ContextBase7
CWE-568finalize() Method Without super.finalize()Variant0
CWE-57Path Equivalence: 'fakedir/../realdir/filename'Variant0
CWE-570Expression is Always FalseBase1
CWE-571Expression is Always TrueBase1
CWE-572Call to Thread run() instead of start()Variant0
CWE-573Improper Following of Specification by CallerClass7
CWE-574EJB Bad Practices: Use of Synchronization PrimitivesVariant0
CWE-575EJB Bad Practices: Use of AWT SwingVariant0
CWE-576EJB Bad Practices: Use of Java I/OVariant0
CWE-577EJB Bad Practices: Use of SocketsVariant0
CWE-578EJB Bad Practices: Use of Class LoaderVariant0
CWE-579J2EE Bad Practices: Non-serializable Object Stored in SessionVariant0
CWE-58Path Equivalence: Windows 8.3 FilenameVariant0
CWE-580clone() Method Without super.clone()Variant0
CWE-581Object Model Violation: Just One of Equals and Hashcode DefinedVariant0
CWE-582Array Declared Public, Final, and StaticVariant0
CWE-583finalize() Method Declared PublicVariant0
CWE-584Return Inside Finally BlockBase0
Page 36 of 49 · 969 total