Skip to main content

Weakness Types

37 CWEs
CWEWeaknessTypeCVEsKEVTop 25
CWE-77Command InjectionClass12113#23
CWE-78OS Command InjectionBase11148#9
CWE-74InjectionClass562-
CWE-20Improper Input ValidationClass4241#18
CWE-94Code InjectionBase3936#10
CWE-502Deserialization of Untrusted DataBase3736#15
CWE-22Path TraversalBase3331#6
CWE-306Missing Authentication for Critical FunctionBase2823#21
CWE-416Use After FreeVariant2625#7
CWE-284Improper Access ControlPillar2322#19
CWE-89SQL InjectionBase2017#2
CWE-287Improper AuthenticationClass1818-
CWE-122Heap-based Buffer OverflowVariant1817#16
CWE-121Stack-based Buffer OverflowVariant1714#14
CWE-288Authentication Bypass Using an Alternate PathBase1615-
CWE-434Unrestricted File UploadBase1512#12
CWE-79Cross-Site ScriptingBase1312#1
CWE-269Improper Privilege ManagementClass1110-
CWE-399Resource Management ErrorsCategory1010-
CWE-693Protection Mechanism FailurePillar1010-
CWE-119Improper Restriction of Memory Buffer BoundsClass98-
CWE-200Exposure of Sensitive InformationClass99#20
CWE-787Out-of-bounds WriteBase99#5
CWE-506Embedded Malicious CodeClass99-
CWE-73External Control of File Name or PathBase85-
CWE-918Server-Side Request ForgeryBase87#22
CWE-95Eval InjectionVariant84-
CWE-190Integer OverflowBase77-
CWE-863Incorrect AuthorizationClass77#17
CWE-347Improper Signature VerificationBase65-
CWE-400Uncontrolled Resource ConsumptionClass65-
CWE-59Link FollowingBase66-
CWE-36Absolute Path TraversalBase55-
CWE-125Out-of-bounds ReadBase55#8
CWE-290Authentication Bypass by SpoofingBase55-
CWE-1188Insecure Default InitializationBase54-
CWE-822Untrusted Pointer DereferenceBase55-

Frequently Asked Questions

What is CWE?→

CWE (Common Weakness Enumeration) is a community-developed list of common software and hardware weaknesses. CISA sponsors the program and The MITRE Corporation operates it. A CWE describes the kind of mistake behind a vulnerability, while a CVE identifies one specific vulnerability in one product.

What is the difference between CWE and CVE?→

A CVE ID names a single vulnerability in a specific product version. A CWE ID names the class of flaw that caused it. One CWE, such as CWE-78 (OS Command Injection), maps to thousands of CVEs across many vendors.

Where do the CWE mappings on this page come from?→

Each CVE record lists the CWE IDs its CVE Numbering Authority assigned. This page groups the records in this database by those IDs. A weakness gets its own page once at least 5 records map to it. Many older KEV records carry no CWE mapping, so the counts here undercount older vulnerabilities.

CWE is a trademark of The MITRE Corporation. Weakness names from the CWE List, used under the CWE Terms of Use. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.