The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-911Improper Update of Reference CountBase16
CWE-912Hidden FunctionalityClass79
CWE-913Improper Control of Dynamically-Managed Code ResourcesClass76
CWE-914Improper Control of Dynamically-Identified VariablesBase7
CWE-915Improperly Controlled Modification of Dynamically-Determined Object AttributesBase151
CWE-916Use of Password Hash With Insufficient Computational EffortBase69
CWE-917Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')Base46
CWE-918Server-Side Request Forgery (SSRF)Base2,544
CWE-92DEPRECATED: Improper Sanitization of Custom Special CharactersBase34
CWE-920Improper Restriction of Power ConsumptionBase1
CWE-921Storage of Sensitive Data in a Mechanism without Access ControlBase9
CWE-922Insecure Storage of Sensitive InformationClass119
CWE-923Improper Restriction of Communication Channel to Intended EndpointsClass63
CWE-924Improper Enforcement of Message Integrity During Transmission in a Communication ChannelBase24
CWE-925Improper Verification of Intent by Broadcast ReceiverVariant3
CWE-926Improper Export of Android Application ComponentsVariant86
CWE-927Use of Implicit Intent for Sensitive CommunicationVariant16
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')Base190
CWE-939Improper Authorization in Handler for Custom URL SchemeBase24
CWE-94Improper Control of Generation of Code ('Code Injection')Base3,294
Page 48 of 49 · 969 total