The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-81Improper Neutralization of Script in an Error Message Web PageVariant9
CWE-82Improper Neutralization of Script in Attributes of IMG Tags in a Web PageVariant7
CWE-820Missing SynchronizationBase14
CWE-821Incorrect SynchronizationBase13
CWE-822Untrusted Pointer DereferenceBase224
CWE-823Use of Out-of-range Pointer OffsetBase101
CWE-824Access of Uninitialized PointerBase189
CWE-825Expired Pointer DereferenceBase55
CWE-826Premature Release of Resource During Expected LifetimeBase10
CWE-827Improper Control of Document Type DefinitionVariant3
CWE-828Signal Handler with Functionality that is not Asynchronous-SafeVariant1
CWE-829Inclusion of Functionality from Untrusted Control SphereBase220
CWE-83Improper Neutralization of Script in Attributes in a Web PageVariant27
CWE-830Inclusion of Web Functionality from an Untrusted SourceVariant11
CWE-831Signal Handler Function Associated with Multiple SignalsVariant0
CWE-832Unlock of a Resource that is not LockedBase0
CWE-833DeadlockBase22
CWE-834Excessive IterationClass36
CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')Base341
CWE-836Use of Password Hash Instead of Password for AuthenticationBase16
Page 46 of 49 · 969 total