The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-733Compiler Optimization Removal or Modification of Security-critical CodeBase4
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')Class4,544
CWE-749Exposed Dangerous Method or FunctionBase172
CWE-75Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)Class19
CWE-754Improper Check for Unusual or Exceptional ConditionsClass386
CWE-755Improper Handling of Exceptional ConditionsClass212
CWE-756Missing Custom Error PageBase3
CWE-757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')Base33
CWE-758Reliance on Undefined, Unspecified, or Implementation-Defined BehaviorClass23
CWE-759Use of a One-Way Hash without a SaltVariant20
CWE-76Improper Neutralization of Equivalent Special ElementsBase14
CWE-760Use of a One-Way Hash with a Predictable SaltVariant9
CWE-761Free of Pointer not at Start of BufferVariant1
CWE-762Mismatched Memory Management RoutinesVariant10
CWE-763Release of Invalid Pointer or ReferenceBase38
CWE-764Multiple Locks of a Critical ResourceBase1
CWE-765Multiple Unlocks of a Critical ResourceBase1
CWE-766Critical Data Element Declared PublicBase0
CWE-767Access to Critical Private Variable via Public MethodBase4
CWE-768Incorrect Short Circuit EvaluationVariant1
Page 43 of 49 · 969 total