Threat Intelligence
CWE
Common Weakness Enumeration
Community
Global
MITRE / CISA
Since 2006
A hierarchical catalogue of software and hardware weakness types: the class of flaw (CWE) as distinct from the individual vulnerability instance (CVE).
Static analysis findings, penetration test reports and secure development requirements all reference CWE IDs, which makes it the join key between your scanner output and the control you claim satisfies it.
At a glance
- Category
- Threat Intelligence
- Jurisdiction
- Global
- Governance
- MITRE / CISA
- Status
- Actively maintained; CWE Top 25 published annually
- First released
- 2006
Links
Related frameworks
Other entries under Threat Intelligence.
- MITRE ATT&CK: Adversarial Tactics, Techniques and Common Knowledge
- MITRE D3FEND: Defensive Countermeasures Knowledge Graph
- CAPEC: Common Attack Pattern Enumeration and Classification
- STIX: Structured Threat Information Expression
- TAXII: Trusted Automated Exchange of Intelligence Information
See CWE in context
Open the interactive Data Landscape for Regulation to compare CWE against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.