The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-787Out-of-bounds WriteBase3,204
CWE-788Access of Memory Location After End of BufferBase144
CWE-789Memory Allocation with Excessive Size ValueVariant222
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Base24,491
CWE-790Improper Filtering of Special ElementsClass13
CWE-791Incomplete Filtering of Special ElementsBase37
CWE-792Incomplete Filtering of One or More Instances of Special ElementsVariant5
CWE-793Only Filtering One Instance of a Special ElementVariant0
CWE-794Incomplete Filtering of Multiple Instances of Special ElementsVariant5
CWE-795Only Filtering Special Elements at a Specified LocationBase0
CWE-796Only Filtering Special Elements Relative to a MarkerVariant0
CWE-797Only Filtering Special Elements at an Absolute PositionVariant0
CWE-798Use of Hard-coded CredentialsBase712
CWE-799Improper Control of Interaction FrequencyClass74
CWE-8J2EE Misconfiguration: Entity Bean Declared RemoteVariant0
CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)Variant542
CWE-804Guessable CAPTCHABase16
CWE-805Buffer Access with Incorrect Length ValueBase49
CWE-806Buffer Access Using Size of Source BufferVariant0
CWE-807Reliance on Untrusted Inputs in a Security DecisionBase91
Page 45 of 49 · 969 total