CWE trends
Compare monthly CVE volume across vulnerability categories, then explore changes in the CWE classes behind them.
Over time
Most Used CWEs
| # | CWE | 12-mo | |
|---|---|---|---|
| 1 | CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | -83% | |
| 2 | CWE-862 Missing Authorization | -53% | |
| 3 | CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | -83% | |
| 4 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | -34% | |
| 5 | CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | -88% | |
| 6 | CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | -44% | |
| 7 | CWE-416 Use After Free | -82% | |
| 8 | CWE-918 Server-Side Request Forgery (SSRF) | +39% | |
| 9 | CWE-94 Improper Control of Generation of Code ('Code Injection') | -71% | |
| 10 | CWE-863 Incorrect Authorization | +44% | |
| 11 | CWE-20 Improper Input Validation | -57% | |
| 12 | CWE-639 Authorization Bypass Through User-Controlled Key | +16% | |
| 13 | CWE-125 Out-of-bounds Read | -65% | |
| 14 | CWE-284 Improper Access Control | -80% | |
| 15 | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor | -81% | |
| 16 | CWE-787 Out-of-bounds Write | -45% | |
| 17 | CWE-352 Cross-Site Request Forgery (CSRF) | -81% | |
| 18 | CWE-121 Stack-based Buffer Overflow | -72% | |
| 19 | CWE-122 Heap-based Buffer Overflow | -71% | |
| 20 | CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer | -94% | |
| 21 | CWE-306 Missing Authentication for Critical Function | -20% | |
| 22 | CWE-502 Deserialization of Untrusted Data | -21% | |
| 23 | CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') | -64% | |
| 24 | CWE-770 Allocation of Resources Without Limits or Throttling | -3% | |
| 25 | CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | -96% | |
| 26 | CWE-434 Unrestricted Upload of File with Dangerous Type | -80% | |
| 27 | CWE-400 Uncontrolled Resource Consumption | -12% | |
| 28 | CWE-287 Improper Authentication | -41% | |
| 29 | CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | -90% | |
| 30 | CWE-285 Improper Authorization | -37% |