The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-648Incorrect Use of Privileged APIsBase63
CWE-649Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity CheckingBase5
CWE-65Windows Hard LinkVariant6
CWE-650Trusting HTTP Permission Methods on the Server SideVariant11
CWE-651Exposure of WSDL File Containing Sensitive InformationVariant0
CWE-652Improper Neutralization of Data within XQuery Expressions ('XQuery Injection')Base0
CWE-653Improper Isolation or CompartmentalizationClass56
CWE-654Reliance on a Single Factor in a Security DecisionBase1
CWE-655Insufficient Psychological AcceptabilityClass1
CWE-656Reliance on Security Through ObscurityClass10
CWE-657Violation of Secure Design PrinciplesClass17
CWE-66Improper Handling of File Names that Identify Virtual ResourcesBase1
CWE-662Improper SynchronizationClass7
CWE-663Use of a Non-reentrant Function in a Concurrent ContextBase1
CWE-664Improper Control of a Resource Through its LifetimePillar39
CWE-665Improper InitializationClass125
CWE-666Operation on Resource in Wrong Phase of LifetimeClass1
CWE-667Improper LockingClass122
CWE-668Exposure of Resource to Wrong SphereClass200
CWE-669Incorrect Resource Transfer Between SpheresClass64
Page 40 of 49 · 969 total