The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-585Empty Synchronized BlockVariant0
CWE-586Explicit Call to Finalize()Base0
CWE-587Assignment of a Fixed Address to a PointerVariant1
CWE-588Attempt to Access Child of a Non-structure PointerVariant3
CWE-589Call to Non-ubiquitous APIVariant0
CWE-59Improper Link Resolution Before File Access ('Link Following')Base691
CWE-590Free of Memory not on the HeapVariant19
CWE-591Sensitive Data Storage in Improperly Locked MemoryVariant75
CWE-592DEPRECATED: Authentication Bypass IssuesClass22
CWE-593Authentication Bypass: OpenSSL CTX Object Modified after SSL Objects are CreatedVariant0
CWE-594J2EE Framework: Saving Unserializable Objects to DiskVariant0
CWE-595Comparison of Object References Instead of Object ContentsVariant0
CWE-596DEPRECATED: Incorrect Semantic Object ComparisonBase0
CWE-597Use of Wrong Operator in String ComparisonVariant3
CWE-598Use of HTTP Request With Sensitive Query StringVariant81
CWE-599Missing Validation of OpenSSL CertificateVariant5
CWE-6J2EE Misconfiguration: Insufficient Session-ID LengthVariant1
CWE-600Uncaught Exception in ServletVariant1
CWE-601URL Redirection to Untrusted Site ('Open Redirect')Base948
CWE-602Client-Side Enforcement of Server-Side SecurityClass129
Page 37 of 49 · 969 total