LiveActive security incident?Get immediate response
CWE Reference

Common Weakness Enumeration intelligence for builders and executives

Search official CWE records, understand business impact, map weaknesses to CVEs and ATT&CK context, and turn recurring weakness patterns into concrete secure design decisions.

1450 normalized records4.20 releaseMITRE-sourcedGlexia analysis

Reference Search

Find a CWE by ID, name, language, phase, or impact

Use exact IDs such as CWE-79, search weakness names, or browse developer-focused filters.

High-Value Resources

Start with the CWE pages teams use most

Top List

CWE Top 25 quick links

  1. CWE-787: Out-of-bounds Write
  2. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  3. CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
  4. CWE-352: Cross-Site Request Forgery (CSRF)
  5. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  6. CWE-125: Out-of-bounds Read
  7. CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  8. CWE-416: Use After Free
  9. CWE-862: Missing Authorization
  10. CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Dictionary

CWE terms in operational language