The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1085Invokable Control Element with Excessive Volume of Commented-out CodeBase0
CWE-1086Class with Excessive Number of Child ClassesBase0
CWE-1087Class with Virtual Method without a Virtual DestructorBase0
CWE-1088Synchronous Access of Remote Resource without TimeoutBase6
CWE-1089Large Data Table with Excessive Number of IndicesBase0
CWE-109Struts: Validator Turned OffVariant0
CWE-1090Method Containing Access of a Member Element from Another ClassBase0
CWE-1091Use of Object without Invoking Destructor MethodBase0
CWE-1092Use of Same Invokable Control Element in Multiple Architectural LayersBase0
CWE-1093Excessively Complex Data RepresentationClass0
CWE-1094Excessive Index Range Scan for a Data ResourceBase0
CWE-1095Loop Condition Value Update within the LoopBase0
CWE-1096Singleton Class Instance Creation without Proper Locking or SynchronizationVariant0
CWE-1097Persistent Storable Data Element without Associated Comparison Control ElementBase0
CWE-1098Data Element containing Pointer Item without Proper Copy Control ElementBase0
CWE-1099Inconsistent Naming Conventions for IdentifiersBase0
CWE-11ASP.NET Misconfiguration: Creating Debug BinaryVariant2
CWE-110Struts: Validator Without Form FieldVariant0
CWE-1100Insufficient Isolation of System-Dependent FunctionsBase4
CWE-1101Reliance on Runtime Component in Generated CodeBase0
Page 4 of 49 · 969 total