The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-622Improper Validation of Function Hook ArgumentsVariant2
CWE-623Unsafe ActiveX Control Marked Safe For ScriptingVariant3
CWE-624Executable Regular Expression ErrorBase2
CWE-625Permissive Regular ExpressionBase16
CWE-626Null Byte Interaction Error (Poison Null Byte)Variant8
CWE-627Dynamic Variable EvaluationVariant5
CWE-628Function Call with Incorrectly Specified ArgumentsBase7
CWE-636Not Failing Securely ('Failing Open')Class51
CWE-637Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')Class1
CWE-638Not Using Complete MediationClass1
CWE-639Authorization Bypass Through User-Controlled KeyBase2,025
CWE-64Windows Shortcut Following (.LNK)Variant9
CWE-640Weak Password Recovery Mechanism for Forgotten PasswordBase171
CWE-641Improper Restriction of Names for Files and Other ResourcesBase17
CWE-642External Control of Critical State DataClass15
CWE-643Improper Neutralization of Data within XPath Expressions ('XPath Injection')Base14
CWE-644Improper Neutralization of HTTP Headers for Scripting SyntaxVariant60
CWE-645Overly Restrictive Account Lockout MechanismBase7
CWE-646Reliance on File Name or Extension of Externally-Supplied FileVariant10
CWE-647Use of Non-Canonical URL Paths for Authorization DecisionsVariant12
Page 39 of 49 · 969 total