The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1102Reliance on Machine-Dependent Data RepresentationBase1
CWE-1103Use of Platform-Dependent Third Party ComponentsBase2
CWE-1104Use of Unmaintained Third Party ComponentsBase27
CWE-1105Insufficient Encapsulation of Machine-Dependent FunctionalityBase0
CWE-1106Insufficient Use of Symbolic ConstantsBase0
CWE-1107Insufficient Isolation of Symbolic Constant DefinitionsBase2
CWE-1108Excessive Reliance on Global VariablesBase3
CWE-1109Use of Same Variable for Multiple PurposesBase0
CWE-111Direct Use of Unsafe JNIVariant2
CWE-1110Incomplete Design DocumentationBase0
CWE-1111Incomplete I/O DocumentationBase0
CWE-1112Incomplete Documentation of Program ExecutionBase2
CWE-1113Inappropriate Comment StyleBase1
CWE-1114Inappropriate Whitespace StyleBase0
CWE-1115Source Code Element without Standard PrologueBase0
CWE-1116Inaccurate Source Code CommentsBase1
CWE-1117Callable with Insufficient Behavioral SummaryBase0
CWE-1118Insufficient Documentation of Error Handling TechniquesBase1
CWE-1119Excessive Use of Unconditional BranchingBase2
CWE-112Missing XML ValidationBase7
Page 5 of 49 · 969 total