The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-603Use of Client-Side AuthenticationBase23
CWE-605Multiple Binds to the Same PortVariant3
CWE-606Unchecked Input for Loop ConditionBase41
CWE-607Public Static Final Field References Mutable ObjectVariant0
CWE-608Struts: Non-private Field in ActionForm ClassVariant0
CWE-609Double-Checked LockingBase0
CWE-61UNIX Symbolic Link (Symlink) FollowingCompound160
CWE-610Externally Controlled Reference to a Resource in Another SphereClass81
CWE-611Improper Restriction of XML External Entity ReferenceBase491
CWE-612Improper Authorization of Index Containing Sensitive InformationBase11
CWE-613Insufficient Session ExpirationBase406
CWE-614Sensitive Cookie in HTTPS Session Without 'Secure' AttributeVariant62
CWE-615Inclusion of Sensitive Information in Source Code CommentsVariant3
CWE-616Incomplete Identification of Uploaded File Variables (PHP)Variant3
CWE-617Reachable AssertionBase337
CWE-618Exposed Unsafe ActiveX MethodVariant1
CWE-619Dangling Database Cursor ('Cursor Injection')Base0
CWE-62UNIX Hard LinkVariant3
CWE-620Unverified Password ChangeBase88
CWE-621Variable Extraction ErrorVariant1
Page 38 of 49 · 969 total