CWE — Common Weakness Enumeration

CWE is a community-developed taxonomy of software and hardware weakness types. In SEPSES-KG each CWE explains the root cause behind vulnerabilities (e.g., CWE-125 Out-of-bounds Read) and connects CVEs to attack patterns (CAPEC).

TOTAL CWE ENTITIES
969
CVES MAPPED
187,412
CAPEC LINKS
1,247

Latest Weaknesses

1004UNKNOWN

Sensitive Cookie Without 'HttpOnly' Flag

? CVEs

General
1007UNKNOWN

Insufficient Visual Distinction of Homoglyphs Presented to User

? CVEs

General
102UNKNOWN

Struts: Duplicate Validation Forms

? CVEs

General
1021UNKNOWN

Improper Restriction of Rendered UI Layers or Frames

? CVEs

General

Filter CWE Data

Showing 50 of 933 CWEs

Top 10 CWEs by Linked CVE Count

CWE Categories Distribution

CWEs with/without CAPEC Mapping

TOTAL933
With CAPEC
634 CWEs68.0%
Without CAPEC
299 CWEs32.0%

Emerging Weaknesses per Year

Understanding CWE Fields

identifier

Unique CWE-ID string (e.g., CWE-79).

name & description

Human-readable weakness name and summary.

category

Classification group (e.g., Memory Safety, Injection).

related CVEs

Vulnerability records caused by this weakness.

related CAPEC

Attack patterns that exploit this weakness type.