Advertisement · 728 × 90

Posts by Common Weakness Enumeration (CWE) Program

I'm getting pumped for this afternoon's CVE-to-CWE Mapping Workshop with my colleague Connor Mullaly at #VulnCon26 #VulnCon2026 ! 1:30 PM to 5:30 PM at Workshop Room 3. There's no shortage of topics we'll be discussing. Whether we get 2 people or 50 people, we'll be ready :)

2 days ago 3 1 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

Hardware #CWE SIG members—Reminder that our next meeting is Friday, 3/20/2026, at 12:30-1:30 PM EST (16:30 – 17:30 UTC)

Topic:
- RTL WG Update
- Commonly Confused HW CWEs

Join #HW SIG: bit.ly/3SCkqyk

4 weeks ago 0 1 0 0
The CVE Program and FIRST will co-host “VulnCon 2026” at the DoubleTree Resort by Hilton Hotel Paradise Valley - Scottsdale, in Scottsdale, Arizona, USA, on April 13–16, 2026. Registration, both virtual and in-person, is open on the FIRST website.

The CVE Program and FIRST will co-host “VulnCon 2026” at the DoubleTree Resort by Hilton Hotel Paradise Valley - Scottsdale, in Scottsdale, Arizona, USA, on April 13–16, 2026. Registration, both virtual and in-person, is open on the FIRST website.

Check out the #CWE talks in the agenda for “CVE/FIRST VulnCon 2026” on April 13-16, 2026!
www.first.org/conference/v...

Virtual & In-person registration available. Register today!

#cve #first #vulnerability #infosec #cybersecurity

1 month ago 1 0 1 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

Root Cause Mapping Working Group (RCM WG) members — Reminder that our next meeting is tomorrow, Wednesday, 2/18/2026, at 012:00 - 01:00 PM EST

Topic:
- 2025 CWE Top 25 , On-the-Cusp, & KEV Top 10 lists

About RCM WG: cwe.mitre.org/community/wo...

#CWE #CVE

1 month ago 0 0 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

Hardware #CWE SIG members—Reminder that our next meeting is Friday, 2/20/2026, at 12:30-1:30 PM EST (16:30 – 17:30 UTC)

Topic:
- 2026 Goals & Completeness Priorities

Join #HW SIG: bit.ly/3SCkqyk

1 month ago 0 0 0 0
Tree Map of the https://cwe.mitre.org/top25/archive/2025/2025_kev_list.html

Tree Map of the https://cwe.mitre.org/top25/archive/2025/2025_kev_list.html

Want to know the top ten #CWEs in CISA’s “Known Exploited Vulnerabilities (#KEV) Catalog”?

The “2025 CWE Top 10 KEV Weaknesses” list is now available on the CWE website!

List - cwe.mitre.org/top25/archiv...
Key Insights - cwe.mitre.org/top25/archiv...
Methodology - cwe.mitre.org/top25/archiv...

2 months ago 0 1 0 0
CWE - 2025 On the Cusp - Other Dangerous Software Weaknesses Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

15 CWEs were “On the Cusp” of making the “2025 #CWE Top 25 Most Dangerous Software Weaknesses” list.

These CWEs continue to be prevalent & severe enough to cause concern.

See the “2025 On the Cusp” list here: cwe.mitre.org/top25/archiv...

2 months ago 0 1 0 0

Root Cause Mapping Working Group (RCM WG) members — Reminder that our next meeting is Wednesday, 1/21/2026, at 012:00 - 01:00 PM EST

Topic:
- CWE ChatBot

About RCM WG: cwe.mitre.org/community/wo...

#CWE #CVE

2 months ago 0 0 0 0

Hardware #CWE SIG members—Reminder that our next meeting is Friday, 1/16/2026, at 12:30-1:30 PM EST (16:30 – 17:30 UTC)

Topic:
- HW CWE Completeness

Join #HW SIG: bit.ly/3SCkqyk

3 months ago 0 0 0 0
Common Weakness Enumeration (CWE™) Version 4.19 now available!

Common Weakness Enumeration (CWE™) Version 4.19 now available!

#CWE 4.19 is now available! This latest release includes 1 new view to support the release of the “2021 CWE Top 25 Most Dangerous Software Weaknesses,” 1 new view for the “OWASP Top Ten 2025,” + continued CWE content usability improvements

cwe.mitre.org/news/archive...

4 months ago 4 2 1 0
Advertisement
The "2025 CWE Top 25 Most Dangerous Software Weaknesses" list demonstrates the currently most common and impactful software weaknesses. Often easy to find and exploit, these can lead to exploitable vulnerabilities that allow adversaries to completely take over a system, steal data, or prevent applications from working.

The "2025 CWE Top 25 Most Dangerous Software Weaknesses" list demonstrates the currently most common and impactful software weaknesses. Often easy to find and exploit, these can lead to exploitable vulnerabilities that allow adversaries to completely take over a system, steal data, or prevent applications from working.

The 2025 #CWE Top 25 Most Dangerous #Software Weaknesses list is now available!

See the the most severe and prevalent weaknesses behind the 39,080 #CVE Records in this year’s dataset. Take a look and share your thoughts!

cwe.mitre.org/top25/

4 months ago 1 1 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

#CWE User Experience Working Group (UEWG) members — Reminder that our next meeting is Wednesday, 11/19/2025, at 12:00-1:00PM EST

Topic:
- CWE Corpus Completeness

Join CWE UEWG: bit.ly/3CIylfz

4 months ago 0 0 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

Hardware #CWE SIG members—Reminder that our next meeting is Friday, 11/14/2025, at 12:30-1:30 PM EST (16:30 – 17:30 UTC)

Topic:
- Review: “Formation of RTL Weakness Ad-Hoc Working Group”

Join #HW SIG: bit.ly/3SCkqyk

5 months ago 0 0 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

Hardware #CWE SIG members—Reminder that our next meeting is Friday, 10/10/2025, at 12:30-1:30 PM EDT (16:30 – 17:30 UTC)

Topic:
- Review HW submission: “Improper Request Propagation before Data Reception in Write Transactions in a Bus Architecture”

Join #HW SIG: bit.ly/3SCkqyk

6 months ago 0 1 0 0
Preview
“2025 CWE™ Most Important Hardware Weaknesses” Now Available The “2025 CWE™ Most Important Hardware Weaknesses” (2025 MIHW) was released on August 20, 2025, on the CWE website.

New on the #CWE Blog:
“2025 CWE™ Most Important Hardware Weaknesses” Now Available

medium.com/@CWE_CAPEC/2...

#hardware #hw #informationtechnology #informationsecurity #cybersecurity

6 months ago 0 0 0 0
New Common Weakness Enumeration (CWE™) List Version Released!

New Common Weakness Enumeration (CWE™) List Version Released!

#CWE 4.18 is now available! This latest release includes 1 new view related to the recently released “2025 Most Important Hardware Weaknesses,” 1 new AI weakness, usability improvements for 14 CWE entries including diagrams & more

cwe.mitre.org/news/archive...

7 months ago 1 1 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

Hardware #CWE SIG members—Reminder that our next meeting is Friday, 9/12/2025, at 12:30-1:30 PM EDT (16:30 – 17:30 UTC)

Topic:
- CWE Gaps Identified in Most Important Hardware Weaknesses (MIHW) Analysis

Join #HW SIG: bit.ly/3SCkqyk

7 months ago 0 0 0 0
Preview
The "2025 CWE Most Important Hardware Weaknesses” Discover the 2025 most important hardware security weaknesses. Learn how to leverage this list to strengthen your security program.

The “2025 CWE Most Important Hardware Weaknesses”

cycuity.com/type/blog/th...

#cwe #cybersecurity #infosec #hardwaresecurity #hw #hardware

7 months ago 0 0 0 0
Preview
Cybersecurity Snapshot: Industrial Systems in Crosshairs of Russian Hackers, FBI Warns, as MITRE Updates List of Top Hardware Weaknesses Check out the FBI’s alert on Russia-backed hackers infiltrating critical infrastructure networks via an old Cisco bug. Plus, MITRE dropped a revamped list of the most important critical security flaws...

"MITRE updates list of top hardware security blunders"

securityboulevard.com/2025/08/cybe...

#cwe #cybersecurity #infosec #hw #hardware

7 months ago 1 0 0 0
Advertisement
Preview
MITRE Updates List of Most Common Hardware Weaknesses MITRE has updated the list of Most Important Hardware Weaknesses to align it with evolving hardware security challenges.

MITRE Updates List of Most Common Hardware Weaknesses
www.securityweek.com/mitre-update...

#cwe #cybersecurity #infosec #hw #hardware

7 months ago 0 0 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

#CWE User Experience Working Group (UEWG) members — Reminder that our next meeting is tomorrow, Wednesday, 8/27/2025, at 12:00-1:00PM EDT

Topics:
- Weakness Remediation
- CWE Survey Updates
- Open Discussion

Join CWE UEWG: bit.ly/3CIylfz

7 months ago 0 0 0 0
Logo image of the CWE™ "2025 Most Important Hardware Weaknesses (MIHW)," which empowers organizations with the knowledge to proactively strengthen hardware security and reduce risks at the source.

Logo image of the CWE™ "2025 Most Important Hardware Weaknesses (MIHW)," which empowers organizations with the knowledge to proactively strengthen hardware security and reduce risks at the source.

The #CWE “2025 Most Important Hardware Weaknesses (MIHW)” has arrived!

See what’s included, check out the new methodology, and more!

#hardware #hw cwe.mitre.org/topHW/

7 months ago 1 2 0 0
Mapping the Root Causes of CVEs
Mapping the Root Causes of CVEs YouTube video by CVE™ Program

Check out this “We Speak CVE Podcast” about mapping the roots causes of CVEs to CWEs

youtu.be/3nNmrv4j1YE

#CWE #CVE #Vulnerability #VulnerabilityManagement #InformationSecurity #Cybersecurity

8 months ago 0 0 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

#CWE User Experience Working Group (UEWG) members — Reminder that our next meeting is tomorrow, Wednesday, 7/30/2025, at 12:00-1:00PM EDT

Topics:
- CWE Survey Ideas?
- Open Discussion

Join CWE UEWG: bit.ly/3CIylfz

8 months ago 0 0 0 0
How Do We Leverage CVE Root Cause Mapping and CWE Data to Prevent New Vulnerabilities?
How Do We Leverage CVE Root Cause Mapping and CWE Data to Prevent New Vulnerabilities? YouTube video by FIRST

Listen to Alexander Bushkin & Jeremy West of #RedHat discuss “How Do We Leverage CVE Root Cause Mapping and CWE Data to Prevent New Vulnerabilities?” in this video from #VULNCON25

youtu.be/5bRA2Qxqzd0 #CVE #CWE

8 months ago 0 0 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

Hardware #CWE SIG members—Reminder that our next meeting is Friday, 7/11/2025, at 12:30-1:30 PM EDT (16:30 – 17:30 UTC)

Topic:
- HW Memory Weaknesses Working Session

Join #HW SIG: bit.ly/3SCkqyk

9 months ago 0 0 0 0
Advertisement
Vulnerability Root Cause Mapping with CWE: Challenges, Solutions, and Insights from Grounded LLM-based Analysis

Vulnerability Root Cause Mapping with CWE: Challenges, Solutions, and Insights from Grounded LLM-based Analysis

Hear how the CVE Numbering Authority (#CNA) community is enhancing #CVE Records with Root Cause Mapping (RCM) of their CVEs to #CWEs, challenges & practical solutions, & how an LLM can help in this video from #VULNCON25

youtu.be/TH1tGO15K24

9 months ago 0 0 0 0
“Hard Problems in CWE, and What it Tells us about Hard Problems in the Industry,” presentation from “CVE/FIRST VulnCon 2025.” Speaker: CWE Program Technical Lead Steve Christey Coley.

“Hard Problems in CWE, and What it Tells us about Hard Problems in the Industry,” presentation from “CVE/FIRST VulnCon 2025.” Speaker: CWE Program Technical Lead Steve Christey Coley.

Learn about CWE’s most important problems and where they fit within the challenges faced by the broader #vulnerabilitymanagement / #softwaresecurity ecosystem in this video from #VULNCON25

youtu.be/RcR-EFSptnQ #CVE #CWE

9 months ago 0 0 0 0
CWE - CWE Community WGs & SIGs Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

Hardware #CWE SIG members—Reminder that our next meeting is Friday, 6/13/2025, at 12:30-1:30 PM EDT (16:30 – 17:30 UTC)

Topic:
- Continue discussion regarding Memory Access Related Weaknesses as they relate to hardware

Join HW SIG: bit.ly/3SCkqyk

10 months ago 0 0 0 0
Preview
CVE/FIRST VulnCon 2025 - YouTube The CVE Program and FIRST co-hosted “CVE/FIRST VulnCon 2025” at the McKimmon Center in Raleigh, North Carolina, USA, on April 7-10, 2025. The purpose of Vuln...

All of the videos from “VulnCon 2025” are now available on YouTube!

youtube.com/playlist?lis...

#CWE #CVE #FIRST #VulnerabilityManagement #Vulnerability #Cybersecurity #InformationSecurity

10 months ago 0 0 0 0