# CVEs per CWE, Year by Year

For every year since 1988, the CWE weakness types of that year's CVEs with their counts.

Source: https://docs.deepinfo.com/reference/vulnerability/cwe-timeline/examples/default/

Last updated: 2026-09-24

---
`GET https://api.deepinfo.com/v1/explore/vulnerability-insight/cwe-timeline`

For every year since 1988, the CWE weakness types of that year's CVEs with their counts.

Example 1 of 1 · [CWE Timeline Examples](/reference/vulnerability/cwe-timeline/examples/) · endpoint: [CWE Timeline](/reference/vulnerability/cwe-timeline/)

No parameters. `year` runs from 1988 to the current year; `cwe_stats` lists the CWEs of that year's CVEs, the most common first, with `cwe_id`, `cwe_name` and `count`.

## What to Notice

The early years have few or no CWE assignments (`cwe_stats` is empty for 1988). In 2026 the most common weakness is CWE-79, cross-site scripting (6,138 CVEs), ahead of CWE-284 and CWE-862. This page shows the first 10 CWEs of each year.

## Request

```bash
curl 'https://api.deepinfo.com/v1/explore/vulnerability-insight/cwe-timeline' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

## Response

### 200 · OK

> Shortened for this page: [].cwe_stats: first 10 items

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
[
  {
    "year": 1988,
    "cwe_stats": []
  },
  {
    "year": 1989,
    "cwe_stats": []
  },
  {
    "year": 1990,
    "cwe_stats": [
      {
        "cwe_id": 269,
        "cwe_name": "improper privilege management",
        "count": 1
      }
    ]
  },
  {
    "year": 1991,
    "cwe_stats": []
  },
  {
    "year": 1992,
    "cwe_stats": []
  },
  {
    "year": 1993,
    "cwe_stats": []
  },
  {
    "year": 1994,
    "cwe_stats": [
      {
        "cwe_id": 88,
        "cwe_name": "improper neutralization of argument delimiters in a command ('argument injection')",
        "count": 1
      }
    ]
  },
  {
    "year": 1995,
    "cwe_stats": []
  },
  {
    "year": 1996,
    "cwe_stats": [
      {
        "cwe_id": 78,
        "cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
        "count": 2
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 1
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 1
      }
    ]
  },
  {
    "year": 1997,
    "cwe_stats": [
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 4
      },
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 2
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 1
      },
      {
        "cwe_id": 77,
        "cwe_name": "improper neutralization of special elements used in a command ('command injection')",
        "count": 1
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 1
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 1
      },
      {
        "cwe_id": 364,
        "cwe_name": "signal handler race condition",
        "count": 1
      },
      {
        "cwe_id": 434,
        "cwe_name": "unrestricted upload of file with dangerous type",
        "count": 1
      }
    ]
  },
  {
    "year": 1998,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 3
      },
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 2
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 1
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 1
      },
      {
        "cwe_id": 178,
        "cwe_name": "improper handling of case sensitivity",
        "count": 1
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 1
      },
      {
        "cwe_id": 290,
        "cwe_name": "authentication bypass by spoofing",
        "count": 1
      },
      {
        "cwe_id": 307,
        "cwe_name": "improper restriction of excessive authentication attempts",
        "count": 1
      },
      {
        "cwe_id": 327,
        "cwe_name": "use of a broken or risky cryptographic algorithm",
        "count": 1
      },
      {
        "cwe_id": 400,
        "cwe_name": "uncontrolled resource consumption",
        "count": 1
      }
    ]
  },
  {
    "year": 1999,
    "cwe_stats": [
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 9
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 8
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 6
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 3
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 3
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 3
      },
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 1
      },
      {
        "cwe_id": 193,
        "cwe_name": "off-by-one error",
        "count": 1
      },
      {
        "cwe_id": 276,
        "cwe_name": "incorrect default permissions",
        "count": 1
      },
      {
        "cwe_id": 307,
        "cwe_name": "improper restriction of excessive authentication attempts",
        "count": 1
      }
    ]
  },
  {
    "year": 2000,
    "cwe_stats": [
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 4
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 4
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 3
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 3
      },
      {
        "cwe_id": 178,
        "cwe_name": "improper handling of case sensitivity",
        "count": 3
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 1
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 1
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 1
      },
      {
        "cwe_id": 346,
        "cwe_name": "origin validation error",
        "count": 1
      },
      {
        "cwe_id": 362,
        "cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
        "count": 1
      }
    ]
  },
  {
    "year": 2001,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 9
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 7
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 5
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 5
      },
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 5
      },
      {
        "cwe_id": 203,
        "cwe_name": "observable discrepancy",
        "count": 4
      },
      {
        "cwe_id": 88,
        "cwe_name": "improper neutralization of argument delimiters in a command ('argument injection')",
        "count": 3
      },
      {
        "cwe_id": 131,
        "cwe_name": "incorrect calculation of buffer size",
        "count": 3
      },
      {
        "cwe_id": 178,
        "cwe_name": "improper handling of case sensitivity",
        "count": 3
      },
      {
        "cwe_id": 193,
        "cwe_name": "off-by-one error",
        "count": 3
      }
    ]
  },
  {
    "year": 2002,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 41
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 34
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 27
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 17
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 14
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 12
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 7
      },
      {
        "cwe_id": 326,
        "cwe_name": "inadequate encryption strength",
        "count": 7
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 6
      },
      {
        "cwe_id": 193,
        "cwe_name": "off-by-one error",
        "count": 6
      }
    ]
  },
  {
    "year": 2003,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 52
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 34
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 26
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 25
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 17
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 15
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 13
      },
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 7
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 7
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 6
      }
    ]
  },
  {
    "year": 2004,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 24
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 23
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 17
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 15
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 10
      },
      {
        "cwe_id": 203,
        "cwe_name": "observable discrepancy",
        "count": 7
      },
      {
        "cwe_id": 476,
        "cwe_name": "null pointer dereference",
        "count": 7
      },
      {
        "cwe_id": 88,
        "cwe_name": "improper neutralization of argument delimiters in a command ('argument injection')",
        "count": 6
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 6
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 6
      }
    ]
  },
  {
    "year": 2005,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 71
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 51
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 42
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 30
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 28
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 19
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 14
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 13
      },
      {
        "cwe_id": 425,
        "cwe_name": "direct request ('forced browsing')",
        "count": 8
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 6
      }
    ]
  },
  {
    "year": 2006,
    "cwe_stats": [
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 182
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 144
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 122
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 100
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 53
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 31
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 24
      },
      {
        "cwe_id": 134,
        "cwe_name": "use of externally-controlled format string",
        "count": 17
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 13
      },
      {
        "cwe_id": 88,
        "cwe_name": "improper neutralization of argument delimiters in a command ('argument injection')",
        "count": 9
      }
    ]
  },
  {
    "year": 2007,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 436
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 357
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 303
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 256
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 241
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 162
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 101
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 66
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 37
      },
      {
        "cwe_id": 134,
        "cwe_name": "use of externally-controlled format string",
        "count": 30
      }
    ]
  },
  {
    "year": 2008,
    "cwe_stats": [
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 1092
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 791
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 554
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 379
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 351
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 312
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 189
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 173
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 140
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 78
      }
    ]
  },
  {
    "year": 2009,
    "cwe_stats": [
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 948
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 822
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 549
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 321
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 317
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 301
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 209
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 160
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 113
      },
      {
        "cwe_id": 362,
        "cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
        "count": 33
      }
    ]
  },
  {
    "year": 2010,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 594
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 515
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 505
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 284
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 275
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 251
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 158
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 75
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 75
      },
      {
        "cwe_id": 362,
        "cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
        "count": 32
      }
    ]
  },
  {
    "year": 2011,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 579
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 459
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 355
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 292
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 289
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 106
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 102
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 56
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 55
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 55
      }
    ]
  },
  {
    "year": 2012,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 729
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 682
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 351
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 236
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 222
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 154
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 137
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 120
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 100
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 81
      }
    ]
  },
  {
    "year": 2013,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 730
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 616
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 493
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 246
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 146
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 138
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 120
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 108
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 103
      },
      {
        "cwe_id": 362,
        "cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
        "count": 64
      }
    ]
  },
  {
    "year": 2014,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 1027
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 742
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 539
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 355
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 295
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 246
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 198
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 188
      },
      {
        "cwe_id": 287,
        "cwe_name": "improper authentication",
        "count": 146
      },
      {
        "cwe_id": 59,
        "cwe_name": "improper link resolution before file access ('link following')",
        "count": 59
      }
    ]
  },
  {
    "year": 2015,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 963
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 726
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 595
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 380
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 241
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 213
      },
      {
        "cwe_id": 284,
        "cwe_name": "improper access control",
        "count": 144
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 141
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 50
      },
      {
        "cwe_id": 362,
        "cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
        "count": 48
      }
    ]
  },
  {
    "year": 2016,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 1036
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 684
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 526
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 472
      },
      {
        "cwe_id": 284,
        "cwe_name": "improper access control",
        "count": 399
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 175
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 157
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 94
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 90
      },
      {
        "cwe_id": 476,
        "cwe_name": "null pointer dereference",
        "count": 84
      }
    ]
  },
  {
    "year": 2017,
    "cwe_stats": [
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 2115
      },
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 1477
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 1312
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 959
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 711
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 504
      },
      {
        "cwe_id": 476,
        "cwe_name": "null pointer dereference",
        "count": 344
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 315
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 295
      },
      {
        "cwe_id": 284,
        "cwe_name": "improper access control",
        "count": 278
      }
    ]
  },
  {
    "year": 2018,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 2021
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 1281
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 1076
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 1010
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 863
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 768
      },
      {
        "cwe_id": 190,
        "cwe_name": "integer overflow or wraparound",
        "count": 725
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 564
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 502
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 453
      }
    ]
  },
  {
    "year": 2019,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 2342
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 1294
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 929
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 908
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 574
      },
      {
        "cwe_id": 200,
        "cwe_name": "exposure of sensitive information to an unauthorized actor",
        "count": 559
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 547
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 543
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 481
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 481
      }
    ]
  },
  {
    "year": 2020,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 2167
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 1389
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 831
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 673
      },
      {
        "cwe_id": 78,
        "cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
        "count": 538
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 463
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 431
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 399
      },
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 391
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 380
      }
    ]
  },
  {
    "year": 2021,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 2683
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 1576
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 737
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 729
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 683
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 556
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 539
      },
      {
        "cwe_id": 78,
        "cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
        "count": 494
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 467
      },
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 418
      }
    ]
  },
  {
    "year": 2022,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 3235
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 2276
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 1739
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 864
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 752
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 744
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 732
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 703
      },
      {
        "cwe_id": 78,
        "cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
        "count": 585
      },
      {
        "cwe_id": 862,
        "cwe_name": "missing authorization",
        "count": 515
      }
    ]
  },
  {
    "year": 2023,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 4728
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 2023
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 1984
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 1304
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 987
      },
      {
        "cwe_id": 862,
        "cwe_name": "missing authorization",
        "count": 845
      },
      {
        "cwe_id": 20,
        "cwe_name": "improper input validation",
        "count": 821
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 769
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 645
      },
      {
        "cwe_id": 120,
        "cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
        "count": 607
      }
    ]
  },
  {
    "year": 2024,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 7371
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 2687
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 2017
      },
      {
        "cwe_id": 862,
        "cwe_name": "missing authorization",
        "count": 1908
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 1423
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 1264
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 1231
      },
      {
        "cwe_id": 476,
        "cwe_name": "null pointer dereference",
        "count": 1165
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 1074
      },
      {
        "cwe_id": 121,
        "cwe_name": "stack-based buffer overflow",
        "count": 898
      }
    ]
  },
  {
    "year": 2025,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 8295
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 4001
      },
      {
        "cwe_id": 74,
        "cwe_name": "improper neutralization of special elements in output used by a downstream component ('injection')",
        "count": 2569
      },
      {
        "cwe_id": 862,
        "cwe_name": "missing authorization",
        "count": 2354
      },
      {
        "cwe_id": 352,
        "cwe_name": "cross-site request forgery (csrf)",
        "count": 1922
      },
      {
        "cwe_id": 94,
        "cwe_name": "improper control of generation of code ('code injection')",
        "count": 1411
      },
      {
        "cwe_id": 284,
        "cwe_name": "improper access control",
        "count": 1253
      },
      {
        "cwe_id": 476,
        "cwe_name": "null pointer dereference",
        "count": 1219
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 1173
      },
      {
        "cwe_id": 119,
        "cwe_name": "improper restriction of operations within the bounds of a memory buffer",
        "count": 1157
      }
    ]
  },
  {
    "year": 2026,
    "cwe_stats": [
      {
        "cwe_id": 79,
        "cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
        "count": 6138
      },
      {
        "cwe_id": 284,
        "cwe_name": "improper access control",
        "count": 3701
      },
      {
        "cwe_id": 862,
        "cwe_name": "missing authorization",
        "count": 3534
      },
      {
        "cwe_id": 89,
        "cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
        "count": 3303
      },
      {
        "cwe_id": 22,
        "cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
        "count": 2346
      },
      {
        "cwe_id": 416,
        "cwe_name": "use after free",
        "count": 2205
      },
      {
        "cwe_id": 78,
        "cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
        "count": 1740
      },
      {
        "cwe_id": 125,
        "cwe_name": "out-of-bounds read",
        "count": 1698
      },
      {
        "cwe_id": 918,
        "cwe_name": "server-side request forgery (ssrf)",
        "count": 1684
      },
      {
        "cwe_id": 787,
        "cwe_name": "out-of-bounds write",
        "count": 1671
      }
    ]
  }
]
```
