CWE
A taxonomy of recurring software and hardware weakness types that can lead to exploitable vulnerabilities.
CWE (Common Weakness Enumeration) is a taxonomy of recurring software and hardware weakness types; unlike CVE, it does not identify one specific vulnerability instance.
Security Context
CWE classifies recurring root-cause weaknesses such as buffer overflows, improper input validation, and authorization errors. The taxonomy is useful for secure-coding guidance, static-analysis rules, and grouping vulnerability findings by the underlying defect pattern.
Identification Boundary
CWE is not an incident identifier for one product flaw. A CVE records a specific publicly disclosed vulnerability, whereas CWE names a class of weakness that may occur in many implementations.
Related Security Concepts
- CVE
- CVSS
- Static Analysis
- Secure Coding
Source
- https://csrc.nist.gov/glossary/term/cwe
CWE versus CVE
CWE classifies recurring weakness types, whereas CVE identifies specific publicly disclosed vulnerability records. A CVE may map to one or more CWE classes, but the two systems do not serve the same purpose. CWE is useful for tracking design and coding weakness classes; CVE is better suited to tracking concrete product/version exposure.