The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-691Insufficient Control Flow ManagementPillar33
CWE-692Incomplete Denylist to Cross-Site ScriptingCompound9
CWE-693Protection Mechanism FailurePillar455
CWE-694Use of Multiple Resources with Duplicate IdentifierBase11
CWE-695Use of Low-Level FunctionalityBase1
CWE-696Incorrect Behavior OrderClass40
CWE-697Incorrect ComparisonPillar76
CWE-698Execution After Redirect (EAR)Base19
CWE-7J2EE Misconfiguration: Missing Custom Error PageVariant0
CWE-703Improper Check or Handling of Exceptional ConditionsPillar125
CWE-704Incorrect Type Conversion or CastClass77
CWE-705Incorrect Control Flow ScopingClass8
CWE-706Use of Incorrectly-Resolved Name or ReferenceClass69
CWE-707Improper NeutralizationPillar250
CWE-708Incorrect Ownership AssignmentBase21
CWE-71DEPRECATED: Apple '.DS_Store'Variant0
CWE-710Improper Adherence to Coding StandardsPillar6
CWE-72Improper Handling of Apple HFS+ Alternate Data Stream PathVariant0
CWE-73External Control of File Name or PathBase587
CWE-732Incorrect Permission Assignment for Critical ResourceClass593
Page 42 of 49 · 969 total