CWE top 25 most dangerous software weaknesses

Share:

The CWE list of the 25 most dangerous software weaknesses demonstrates the currently most common and impactful software flaws. Identifying the root causes of these vulnerabilities provides insights to shape investments, policies, and practices that proactively prevent their occurrence.

The CWE top 25 most dangerous software weaknesses list was calculated by analyzing public vulnerability information in Common Vulnerabilities and Exposures (CVE) Records for CWE root cause mappings.

This year’s dataset included 31,770 CVE Records for vulnerabilities published between June 1, 2023 and June 1, 2024. Data was initially pulled on July 30, 2024, to share with CNA community partners for review. Data was pulled again on November 4, 2024, to ensure the most up-to-date CVE Records information was used in the top 25 list calculations. For more in-depth details about the methodology, go here.

CWE Top 25 for 2024

  1. CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  2. CWE-787: Out-of-bounds Write
  3. CWE-89: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)
  4. CWE-352: Cross-Site Request Forgery (CSRF)
  5. CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
  6. CWE-125: Out-of-bounds Read
  7. CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
  8. CWE-416: Use After Free
  9. CWE-862: Missing Authorization
  10. CWE-434: Unrestricted Upload of File with Dangerous Type
  11. CWE-94: Improper Control of Generation of Code (‘Code Injection’)
  12. CWE-20: Improper Input Validation
  13. CWE-77: Improper Neutralization of Special Elements used in a Command (‘Command Injection’)
  14. CWE-287: Improper Authentication
  15. CWE-269: Improper Privilege Management
  16. CWE-502: Deserialization of Untrusted Data
  17. CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  18. CWE-863: Incorrect Authorization
  19. CWE-918: Server-Side Request Forgery (SSRF)
  20. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  21. CWE-476: NULL Pointer Dereference
  22. CWE-798: Use of Hard-coded Credentials
  23. CWE-190: Integer Overflow or Wraparound
  24. CWE-400: Uncontrolled Resource Consumption
  25. CWE-306: Missing Authentication for Critical Function

Help Net Security

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:20 am, Jul 2, 2025
weather icon 19°C
L: 18° | H: 20°
broken clouds
Humidity: 81 %
Pressure: 1014 mb
Wind: 6 mph NE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 57%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:48 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 20°°C 0.26 mm 26% 11 mph 81 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 12 mph 54 % 1028 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 12 mph 61 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
16° | 21°°C 1 mm 100% 13 mph 95 % 1022 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
14° | 17°°C 1 mm 100% 12 mph 91 % 1009 mb 0 mm/h
Today 7:00 am
weather icon
18° | 19°°C 0 mm 0% 8 mph 81 % 1014 mb 0 mm/h
Today 10:00 am
weather icon
21° | 21°°C 0 mm 0% 6 mph 75 % 1016 mb 0 mm/h
Today 1:00 pm
weather icon
19° | 19°°C 0.2 mm 20% 7 mph 71 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
21° | 21°°C 0.26 mm 26% 8 mph 45 % 1019 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 11 mph 32 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
18° | 18°°C 0 mm 0% 11 mph 35 % 1023 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 15°°C 0 mm 0% 7 mph 39 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
14° | 14°°C 0 mm 0% 4 mph 52 % 1026 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,805.73
-1.05%
Ethereum(ETH)
€2,053.11
-2.48%
Tether(USDT)
€0.85
-0.02%
XRP(XRP)
€1.85
-2.29%
Solana(SOL)
€125.89
-3.13%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.134551
-3.47%
Shiba Inu(SHIB)
€0.000009
-1.11%
Pepe(PEPE)
€0.000008
-3.66%
Scroll to Top