The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-837Improper Enforcement of a Single, Unique ActionBase17
CWE-838Inappropriate Encoding for Output ContextBase7
CWE-839Numeric Range Comparison Without Minimum CheckBase4
CWE-84Improper Neutralization of Encoded URI Schemes in a Web PageVariant12
CWE-841Improper Enforcement of Behavioral WorkflowClass65
CWE-842Placement of User into Incorrect GroupBase10
CWE-843Access of Resource Using Incompatible Type ('Type Confusion')Base505
CWE-85Doubled Character XSS ManipulationsVariant2
CWE-86Improper Neutralization of Invalid Characters in Identifiers in Web PagesVariant10
CWE-862Missing AuthorizationClass7,511
CWE-863Incorrect AuthorizationClass2,302
CWE-87Improper Neutralization of Alternate XSS SyntaxVariant55
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')Base252
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')Base10,520
CWE-9J2EE Misconfiguration: Weak Access Permissions for EJB MethodsVariant0
CWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')Base66
CWE-908Use of Uninitialized ResourceBase273
CWE-909Missing Initialization of ResourceClass13
CWE-91XML Injection (aka Blind XPath Injection)Base70
CWE-910Use of Expired File DescriptorBase2
Page 47 of 49 · 969 total