The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1230Exposure of Sensitive Information Through MetadataBase26
CWE-1231Improper Prevention of Lock Bit ModificationBase3
CWE-1232Improper Lock Behavior After Power State TransitionBase0
CWE-1233Security-Sensitive Hardware Controls with Missing Lock Bit ProtectionBase3
CWE-1234Hardware Internal or Debug Modes Allow Override of LocksBase4
CWE-1235Incorrect Use of Autoboxing and Unboxing for Performance Critical OperationsBase0
CWE-1236Improper Neutralization of Formula Elements in a CSV FileBase151
CWE-1239Improper Zeroization of Hardware RegisterVariant0
CWE-124Buffer Underwrite ('Buffer Underflow')Base39
CWE-1240Use of a Cryptographic Primitive with a Risky ImplementationBase22
CWE-1241Use of Predictable Algorithm in Random Number GeneratorBase8
CWE-1242Inclusion of Undocumented Features or Chicken BitsBase14
CWE-1243Sensitive Non-Volatile Information Not Protected During DebugBase0
CWE-1244Internal Asset Exposed to Unsafe Debug Access Level or StateBase12
CWE-1245Improper Finite State Machines (FSMs) in Hardware LogicBase5
CWE-1246Improper Write Handling in Limited-write Non-Volatile MemoriesBase1
CWE-1247Improper Protection Against Voltage and Clock GlitchesBase4
CWE-1248Semiconductor Defects in Hardware Logic with Security-Sensitive ImplicationsBase0
CWE-1249Application-Level Admin Tool with Inconsistent View of Underlying Operating SystemBase1
CWE-125Out-of-bounds ReadBase3,924
Page 8 of 49 · 969 total