Vulnerability classes.The bug behind every CVE.
CVEs change; bug patterns repeat. Each class covers the root cause, vulnerable and fixed code, and prevention steps.
Classes covered in depth
Root cause, representative vulnerable/fixed code and prevention steps written by our team.
- CWE-79Cross-site scriptingUser content is inserted into the page as HTML. The browser interprets the content as code rather than data.47,649 CVEs · top score 99
- CWE-89SQL injectionThe query text is built by concatenating user input. The database cannot tell where the data ends and the command begins.17,346 CVEs · top score 99
- CWE-200Exposure of sensitive information to an unauthorized actorThe extension requests broader permissions than its function needs and sends the data it collects out for purposes beyond its stated function.10,849 CVEs · top score 94
- CWE-22Path traversalA user-supplied file name is joined with the allowed directory, but the result is never checked to confirm it is still inside that directory.9,994 CVEs · top score 100
- CWE-352Cross-site request forgeryState-changing requests rely on the session cookie the browser sends automatically; nothing verifies that the request came from the user’s own page.9,466 CVEs · top score 95
- CWE-416Use after freeAfter a memory region is freed, another reference pointing to it is still used. By then, the same region may have been allocated for different data.8,147 CVEs · top score 99
- CWE-78OS command injectionUser input is inserted as text into a shell command. The shell may interpret special characters in the input as part of the command.5,951 CVEs · top score 100
- CWE-287Improper authenticationAuthentication is added route by route instead of being enforced in one place. When a route added later bypasses the shared middleware, the session check never runs for it.4,533 CVEs · top score 99
- CWE-400Uncontrolled resource consumptionCode that parses nested structures sets no depth or size limit. A small input can turn into a disproportionate processing load.3,675 CVEs · top score 90
- CWE-120Buffer copy without bounds checkingWhen data is copied, the source length is not compared with the size of the destination buffer. Excess data overwrites adjacent memory.3,626 CVEs · top score 99
- CWE-269Improper privilege managementTo simplify setup, a service account is granted broad, cluster-wide permissions. The principle of least privilege is skipped during installation.3,258 CVEs · top score 97
- CWE-502Deserialization of untrusted dataData received over the network is deserialized into the language’s native object format without verifying its source. Code paths inside the object can be triggered during deserialization.3,045 CVEs · top score 100
- CWE-306Missing authentication for critical functionA function added for development or support ships to production without authentication. It often relies on the assumption that it is “only reachable from the internal network.”2,686 CVEs · top score 100
- CWE-639Authorization bypass through user-controlled keyThe endpoint fetches the record by the ID sent in the request, but never checks whether the record belongs to the requesting user.2,471 CVEs · top score 66
- CWE-798Hard-coded credentialsFor convenience in support or manufacturing, an account that is identical on every device is embedded in the software. Credentials learned from one device work on all of them.1,511 CVEs · top score 98
- CWE-295Improper certificate validationA certificate validation error is silently swallowed instead of terminating the connection. Often, code added for a test environment makes its way into production.1,502 CVEs · top score 90
- CWE-347Improper verification of cryptographic signatureThe verifier takes the algorithm to verify with from the token’s own header. Untrusted data ends up deciding its own verification rule.799 CVEs · top score 89
Most frequent classes in the database
CWE distribution of published records. Click a class to list every CVE in it.
- CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer13,888 CVEs
- CWE-20Improper Input Validation13,033 CVEs
- CWE-787Out-of-bounds Write10,893 CVEs
- CWE-862Missing Authorization9,343 CVEs
- CWE-125Out-of-bounds Read9,091 CVEs
- CWE-284Improper Access Control7,357 CVEs
- CWE-94Improper Control of Generation of Code ('Code Injection')5,483 CVEs
- CWE-264Permissions, Privileges, and Access Controls5,366 CVEs
- CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')5,324 CVEs
- CWE-476NULL Pointer Dereference5,304 CVEs
- CWE-434Unrestricted Upload of File with Dangerous Type3,722 CVEs
- CWE-918Server-Side Request Forgery (SSRF)3,408 CVEs
- CWE-863Incorrect Authorization3,387 CVEs
- CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')3,230 CVEs
- CWE-190Integer Overflow or Wraparound3,189 CVEs
- CWE-122Heap-based Buffer Overflow2,936 CVEs
- CWE-121Stack-based Buffer Overflow2,898 CVEs
- CWE-399Resource Management Errors2,632 CVEs
- CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2,464 CVEs
- CWE-310Cryptographic Issues2,325 CVEs
- CWE-770Allocation of Resources Without Limits or Throttling1,998 CVEs
- CWE-401Missing Release of Memory after Effective Lifetime1,845 CVEs
- CWE-601URL Redirection to Untrusted Site ('Open Redirect')1,649 CVEs
- CWE-59Improper Link Resolution Before File Access ('Link Following')1,604 CVEs
- CWE-732Incorrect Permission Assignment for Critical Resource1,473 CVEs
- CWE-276Incorrect Default Permissions1,435 CVEs
- CWE-285Improper Authorization1,337 CVEs
- CWE-611Improper Restriction of XML External Entity Reference1,303 CVEs
- CWE-98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1,293 CVEs
- CWE-189Numeric Errors1,236 CVEs
- CWE-266Incorrect Privilege Assignment1,169 CVEs
- CWE-522Insufficiently Protected Credentials1,156 CVEs
- CWE-427Uncontrolled Search Path Element1,149 CVEs
- CWE-532Insertion of Sensitive Information into Log File1,116 CVEs
- CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')843 CVEs
- CWE-415Double Free839 CVEs
- CWE-843Access of Resource Using Incompatible Type ('Type Confusion')823 CVEs
- CWE-319Cleartext Transmission of Sensitive Information823 CVEs
- CWE-617Reachable Assertion791 CVEs
- CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition773 CVEs