The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1188Initialization of a Resource with an Insecure DefaultBase168
CWE-1189Improper Isolation of Shared Resources on System-on-a-Chip (SoC)Base6
CWE-119Improper Restriction of Operations within the Bounds of a Memory BufferClass2,807
CWE-1190DMA Device Enabled Too Early in Boot PhaseBase1
CWE-1191On-Chip Debug and Test Interface With Improper Access ControlBase18
CWE-1192Improper Identifier for IP Block used in System-On-Chip (SOC)Base0
CWE-1193Power-On of Untrusted Execution Core Before Enabling Fabric Access ControlBase0
CWE-12ASP.NET Misconfiguration: Missing Custom Error PageVariant1
CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')Base2,022
CWE-1204Generation of Weak Initialization Vector (IV)Base5
CWE-1209Failure to Disable Reserved BitsBase0
CWE-121Stack-based Buffer OverflowVariant3,003
CWE-122Heap-based Buffer OverflowVariant2,578
CWE-1220Insufficient Granularity of Access ControlBase100
CWE-1221Incorrect Register Defaults or Module ParametersBase2
CWE-1222Insufficient Granularity of Address Regions Protected by Register LocksVariant1
CWE-1223Race Condition for Write-Once AttributesBase0
CWE-1224Improper Restriction of Write-Once Bit FieldsBase1
CWE-1229Creation of Emergent ResourceClass0
CWE-123Write-what-where ConditionBase41
Page 7 of 49 · 969 total