The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-769DEPRECATED: Uncontrolled File Descriptor ConsumptionBase2
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')Class1,898
CWE-770Allocation of Resources Without Limits or ThrottlingBase1,469
CWE-771Missing Reference to Active Allocated ResourceBase6
CWE-772Missing Release of Resource after Effective LifetimeBase86
CWE-773Missing Reference to Active File Descriptor or HandleVariant0
CWE-774Allocation of File Descriptors or Handles Without Limits or ThrottlingVariant4
CWE-775Missing Release of File Descriptor or Handle after Effective LifetimeVariant6
CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')Base40
CWE-777Regular Expression without AnchorsVariant4
CWE-778Insufficient LoggingBase28
CWE-779Logging of Excessive DataBase17
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Base3,701
CWE-780Use of RSA Algorithm without OAEPVariant3
CWE-781Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control CodeVariant0
CWE-782Exposed IOCTL with Insufficient Access ControlVariant30
CWE-783Operator Precedence Logic ErrorBase6
CWE-784Reliance on Cookies without Validation and Integrity Checking in a Security DecisionVariant6
CWE-785Use of Path Manipulation Function without Maximum-sized BufferVariant0
CWE-786Access of Memory Location Before Start of BufferBase4
Page 44 of 49 · 969 total