CWE
Common Weakness Enumeration
A catalogue of the kinds of mistake that cause vulnerabilities, each with a number.
Where a CVE names one vulnerability, a CWE names the class it belongs to: CWE-78 for injecting into an operating-system command, CWE-918 for server-side request forgery, CWE-1427 for input used to prompt a language model without being neutralised.
The rows of this site's rubric that correspond to a known class of weakness carry its CWE number, and so does every rule in the tool description pattern set, so a result can be read against a standard nobody here wrote.
It turns a finding into something comparable: two scanners that disagree about wording can agree about the class.
Reading a CWE number as severity. It says what kind of mistake it is, not how bad this instance is.
Related terms
See CWE on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue