The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1250Improper Preservation of Consistency Between Independent Representations of Shared StateBase6
CWE-1251Mirrored Regions with Different ValuesBase2
CWE-1252CPU Hardware Not Configured to Support Exclusivity of Write and Execute OperationsBase0
CWE-1253Incorrect Selection of Fuse ValuesBase1
CWE-1254Incorrect Comparison Logic GranularityBase5
CWE-1255Comparison Logic is Vulnerable to Power Side-Channel AttacksVariant1
CWE-1256Improper Restriction of Software Interfaces to Hardware FeaturesBase4
CWE-1257Improper Access Control Applied to Mirrored or Aliased Memory RegionsBase2
CWE-1258Exposure of Sensitive System Information Due to Uncleared Debug InformationBase13
CWE-1259Improper Restriction of Security Token AssignmentBase9
CWE-126Buffer Over-readVariant485
CWE-1260Improper Handling of Overlap Between Protected Memory RangesBase14
CWE-1261Improper Handling of Single Event UpsetsBase0
CWE-1262Improper Access Control for Register InterfaceBase8
CWE-1263Improper Physical Access ControlClass10
CWE-1264Hardware Logic with Insecure De-Synchronization between Control and Data ChannelsBase1
CWE-1265Unintended Reentrant Invocation of Non-reentrant Code Via Nested CallsBase0
CWE-1266Improper Scrubbing of Sensitive Data from Decommissioned DeviceBase0
CWE-1267Policy Uses Obsolete EncodingBase0
CWE-1268Policy Privileges are not Assigned Consistently Between Control and Data AgentsBase0
Page 9 of 49 · 969 total