Threat Intelligence

CWE

Common Weakness Enumeration

Community Global MITRE / CISA Since 2006

A hierarchical catalogue of software and hardware weakness types: the class of flaw (CWE) as distinct from the individual vulnerability instance (CVE).

Static analysis findings, penetration test reports and secure development requirements all reference CWE IDs, which makes it the join key between your scanner output and the control you claim satisfies it.

At a glance

Category
Threat Intelligence
Jurisdiction
Global
Governance
MITRE / CISA
Status
Actively maintained; CWE Top 25 published annually
First released
2006

Links

Related frameworks

Other entries under Threat Intelligence.

See CWE in context

Open the interactive Data Landscape for Regulation to compare CWE against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.