Vulnerabilities by Weakness (CWE)
The software weakness types behind the CVEs in this database, ranked by record count. Each page covers the weakness, its mitigations, and every mapped CVE.
Weakness Types
37 CWEs| CWE | Weakness | Type | CVEs | KEV | Top 25 |
|---|---|---|---|---|---|
| CWE-77 | Command Injection | Class | 121 | 13 | #23 |
| CWE-78 | OS Command Injection | Base | 111 | 48 | #9 |
| CWE-74 | Injection | Class | 56 | 2 | - |
| CWE-20 | Improper Input Validation | Class | 42 | 41 | #18 |
| CWE-94 | Code Injection | Base | 39 | 36 | #10 |
| CWE-502 | Deserialization of Untrusted Data | Base | 37 | 36 | #15 |
| CWE-22 | Path Traversal | Base | 33 | 31 | #6 |
| CWE-306 | Missing Authentication for Critical Function | Base | 28 | 23 | #21 |
| CWE-416 | Use After Free | Variant | 26 | 25 | #7 |
| CWE-284 | Improper Access Control | Pillar | 23 | 22 | #19 |
| CWE-89 | SQL Injection | Base | 20 | 17 | #2 |
| CWE-287 | Improper Authentication | Class | 18 | 18 | - |
| CWE-122 | Heap-based Buffer Overflow | Variant | 18 | 17 | #16 |
| CWE-121 | Stack-based Buffer Overflow | Variant | 17 | 14 | #14 |
| CWE-288 | Authentication Bypass Using an Alternate Path | Base | 16 | 15 | - |
| CWE-434 | Unrestricted File Upload | Base | 15 | 12 | #12 |
| CWE-79 | Cross-Site Scripting | Base | 13 | 12 | #1 |
| CWE-269 | Improper Privilege Management | Class | 11 | 10 | - |
| CWE-399 | Resource Management Errors | Category | 10 | 10 | - |
| CWE-693 | Protection Mechanism Failure | Pillar | 10 | 10 | - |
| CWE-119 | Improper Restriction of Memory Buffer Bounds | Class | 9 | 8 | - |
| CWE-200 | Exposure of Sensitive Information | Class | 9 | 9 | #20 |
| CWE-787 | Out-of-bounds Write | Base | 9 | 9 | #5 |
| CWE-506 | Embedded Malicious Code | Class | 9 | 9 | - |
| CWE-73 | External Control of File Name or Path | Base | 8 | 5 | - |
| CWE-918 | Server-Side Request Forgery | Base | 8 | 7 | #22 |
| CWE-95 | Eval Injection | Variant | 8 | 4 | - |
| CWE-190 | Integer Overflow | Base | 7 | 7 | - |
| CWE-863 | Incorrect Authorization | Class | 7 | 7 | #17 |
| CWE-347 | Improper Signature Verification | Base | 6 | 5 | - |
| CWE-400 | Uncontrolled Resource Consumption | Class | 6 | 5 | - |
| CWE-59 | Link Following | Base | 6 | 6 | - |
| CWE-36 | Absolute Path Traversal | Base | 5 | 5 | - |
| CWE-125 | Out-of-bounds Read | Base | 5 | 5 | #8 |
| CWE-290 | Authentication Bypass by Spoofing | Base | 5 | 5 | - |
| CWE-1188 | Insecure Default Initialization | Base | 5 | 4 | - |
| CWE-822 | Untrusted Pointer Dereference | Base | 5 | 5 | - |
Frequently Asked Questions
What is CWE?→
CWE (Common Weakness Enumeration) is a community-developed list of common software and hardware weaknesses. CISA sponsors the program and The MITRE Corporation operates it. A CWE describes the kind of mistake behind a vulnerability, while a CVE identifies one specific vulnerability in one product.
What is the difference between CWE and CVE?→
A CVE ID names a single vulnerability in a specific product version. A CWE ID names the class of flaw that caused it. One CWE, such as CWE-78 (OS Command Injection), maps to thousands of CVEs across many vendors.
Where do the CWE mappings on this page come from?→
Each CVE record lists the CWE IDs its CVE Numbering Authority assigned. This page groups the records in this database by those IDs. A weakness gets its own page once at least 5 records map to it. Many older KEV records carry no CWE mapping, so the counts here undercount older vulnerabilities.
CWE is a trademark of The MITRE Corporation. Weakness names from the CWE List, used under the CWE Terms of Use. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.