[
{
"year": 1988,
"cwe_stats": []
},
{
"year": 1989,
"cwe_stats": []
},
{
"year": 1990,
"cwe_stats": [
{
"cwe_id": 269,
"cwe_name": "improper privilege management",
"count": 1
}
]
},
{
"year": 1991,
"cwe_stats": []
},
{
"year": 1992,
"cwe_stats": []
},
{
"year": 1993,
"cwe_stats": []
},
{
"year": 1994,
"cwe_stats": [
{
"cwe_id": 88,
"cwe_name": "improper neutralization of argument delimiters in a command ('argument injection')",
"count": 1
}
]
},
{
"year": 1995,
"cwe_stats": []
},
{
"year": 1996,
"cwe_stats": [
{
"cwe_id": 78,
"cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
"count": 2
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 1
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 1
}
]
},
{
"year": 1997,
"cwe_stats": [
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 4
},
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 2
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 1
},
{
"cwe_id": 77,
"cwe_name": "improper neutralization of special elements used in a command ('command injection')",
"count": 1
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 1
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 1
},
{
"cwe_id": 364,
"cwe_name": "signal handler race condition",
"count": 1
},
{
"cwe_id": 434,
"cwe_name": "unrestricted upload of file with dangerous type",
"count": 1
}
]
},
{
"year": 1998,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 3
},
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 2
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 1
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 1
},
{
"cwe_id": 178,
"cwe_name": "improper handling of case sensitivity",
"count": 1
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 1
},
{
"cwe_id": 290,
"cwe_name": "authentication bypass by spoofing",
"count": 1
},
{
"cwe_id": 307,
"cwe_name": "improper restriction of excessive authentication attempts",
"count": 1
},
{
"cwe_id": 327,
"cwe_name": "use of a broken or risky cryptographic algorithm",
"count": 1
},
{
"cwe_id": 400,
"cwe_name": "uncontrolled resource consumption",
"count": 1
}
]
},
{
"year": 1999,
"cwe_stats": [
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 9
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 8
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 6
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 3
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 3
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 3
},
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 1
},
{
"cwe_id": 193,
"cwe_name": "off-by-one error",
"count": 1
},
{
"cwe_id": 276,
"cwe_name": "incorrect default permissions",
"count": 1
},
{
"cwe_id": 307,
"cwe_name": "improper restriction of excessive authentication attempts",
"count": 1
}
]
},
{
"year": 2000,
"cwe_stats": [
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 4
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 4
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 3
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 3
},
{
"cwe_id": 178,
"cwe_name": "improper handling of case sensitivity",
"count": 3
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 1
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 1
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 1
},
{
"cwe_id": 346,
"cwe_name": "origin validation error",
"count": 1
},
{
"cwe_id": 362,
"cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
"count": 1
}
]
},
{
"year": 2001,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 9
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 7
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 5
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 5
},
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 5
},
{
"cwe_id": 203,
"cwe_name": "observable discrepancy",
"count": 4
},
{
"cwe_id": 88,
"cwe_name": "improper neutralization of argument delimiters in a command ('argument injection')",
"count": 3
},
{
"cwe_id": 131,
"cwe_name": "incorrect calculation of buffer size",
"count": 3
},
{
"cwe_id": 178,
"cwe_name": "improper handling of case sensitivity",
"count": 3
},
{
"cwe_id": 193,
"cwe_name": "off-by-one error",
"count": 3
}
]
},
{
"year": 2002,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 41
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 34
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 27
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 17
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 14
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 12
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 7
},
{
"cwe_id": 326,
"cwe_name": "inadequate encryption strength",
"count": 7
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 6
},
{
"cwe_id": 193,
"cwe_name": "off-by-one error",
"count": 6
}
]
},
{
"year": 2003,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 52
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 34
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 26
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 25
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 17
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 15
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 13
},
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 7
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 7
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 6
}
]
},
{
"year": 2004,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 24
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 23
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 17
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 15
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 10
},
{
"cwe_id": 203,
"cwe_name": "observable discrepancy",
"count": 7
},
{
"cwe_id": 476,
"cwe_name": "null pointer dereference",
"count": 7
},
{
"cwe_id": 88,
"cwe_name": "improper neutralization of argument delimiters in a command ('argument injection')",
"count": 6
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 6
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 6
}
]
},
{
"year": 2005,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 71
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 51
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 42
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 30
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 28
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 19
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 14
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 13
},
{
"cwe_id": 425,
"cwe_name": "direct request ('forced browsing')",
"count": 8
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 6
}
]
},
{
"year": 2006,
"cwe_stats": [
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 182
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 144
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 122
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 100
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 53
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 31
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 24
},
{
"cwe_id": 134,
"cwe_name": "use of externally-controlled format string",
"count": 17
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 13
},
{
"cwe_id": 88,
"cwe_name": "improper neutralization of argument delimiters in a command ('argument injection')",
"count": 9
}
]
},
{
"year": 2007,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 436
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 357
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 303
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 256
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 241
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 162
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 101
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 66
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 37
},
{
"cwe_id": 134,
"cwe_name": "use of externally-controlled format string",
"count": 30
}
]
},
{
"year": 2008,
"cwe_stats": [
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 1092
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 791
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 554
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 379
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 351
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 312
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 189
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 173
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 140
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 78
}
]
},
{
"year": 2009,
"cwe_stats": [
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 948
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 822
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 549
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 321
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 317
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 301
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 209
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 160
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 113
},
{
"cwe_id": 362,
"cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
"count": 33
}
]
},
{
"year": 2010,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 594
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 515
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 505
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 284
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 275
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 251
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 158
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 75
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 75
},
{
"cwe_id": 362,
"cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
"count": 32
}
]
},
{
"year": 2011,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 579
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 459
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 355
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 292
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 289
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 106
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 102
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 56
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 55
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 55
}
]
},
{
"year": 2012,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 729
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 682
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 351
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 236
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 222
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 154
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 137
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 120
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 100
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 81
}
]
},
{
"year": 2013,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 730
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 616
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 493
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 246
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 146
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 138
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 120
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 108
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 103
},
{
"cwe_id": 362,
"cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
"count": 64
}
]
},
{
"year": 2014,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 1027
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 742
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 539
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 355
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 295
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 246
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 198
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 188
},
{
"cwe_id": 287,
"cwe_name": "improper authentication",
"count": 146
},
{
"cwe_id": 59,
"cwe_name": "improper link resolution before file access ('link following')",
"count": 59
}
]
},
{
"year": 2015,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 963
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 726
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 595
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 380
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 241
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 213
},
{
"cwe_id": 284,
"cwe_name": "improper access control",
"count": 144
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 141
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 50
},
{
"cwe_id": 362,
"cwe_name": "concurrent execution using shared resource with improper synchronization ('race condition')",
"count": 48
}
]
},
{
"year": 2016,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 1036
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 684
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 526
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 472
},
{
"cwe_id": 284,
"cwe_name": "improper access control",
"count": 399
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 175
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 157
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 94
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 90
},
{
"cwe_id": 476,
"cwe_name": "null pointer dereference",
"count": 84
}
]
},
{
"year": 2017,
"cwe_stats": [
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 2115
},
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 1477
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 1312
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 959
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 711
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 504
},
{
"cwe_id": 476,
"cwe_name": "null pointer dereference",
"count": 344
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 315
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 295
},
{
"cwe_id": 284,
"cwe_name": "improper access control",
"count": 278
}
]
},
{
"year": 2018,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 2021
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 1281
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 1076
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 1010
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 863
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 768
},
{
"cwe_id": 190,
"cwe_name": "integer overflow or wraparound",
"count": 725
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 564
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 502
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 453
}
]
},
{
"year": 2019,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 2342
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 1294
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 929
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 908
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 574
},
{
"cwe_id": 200,
"cwe_name": "exposure of sensitive information to an unauthorized actor",
"count": 559
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 547
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 543
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 481
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 481
}
]
},
{
"year": 2020,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 2167
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 1389
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 831
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 673
},
{
"cwe_id": 78,
"cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
"count": 538
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 463
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 431
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 399
},
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 391
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 380
}
]
},
{
"year": 2021,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 2683
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 1576
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 737
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 729
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 683
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 556
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 539
},
{
"cwe_id": 78,
"cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
"count": 494
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 467
},
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 418
}
]
},
{
"year": 2022,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 3235
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 2276
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 1739
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 864
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 752
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 744
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 732
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 703
},
{
"cwe_id": 78,
"cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
"count": 585
},
{
"cwe_id": 862,
"cwe_name": "missing authorization",
"count": 515
}
]
},
{
"year": 2023,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 4728
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 2023
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 1984
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 1304
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 987
},
{
"cwe_id": 862,
"cwe_name": "missing authorization",
"count": 845
},
{
"cwe_id": 20,
"cwe_name": "improper input validation",
"count": 821
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 769
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 645
},
{
"cwe_id": 120,
"cwe_name": "buffer copy without checking size of input ('classic buffer overflow')",
"count": 607
}
]
},
{
"year": 2024,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 7371
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 2687
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 2017
},
{
"cwe_id": 862,
"cwe_name": "missing authorization",
"count": 1908
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 1423
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 1264
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 1231
},
{
"cwe_id": 476,
"cwe_name": "null pointer dereference",
"count": 1165
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 1074
},
{
"cwe_id": 121,
"cwe_name": "stack-based buffer overflow",
"count": 898
}
]
},
{
"year": 2025,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 8295
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 4001
},
{
"cwe_id": 74,
"cwe_name": "improper neutralization of special elements in output used by a downstream component ('injection')",
"count": 2569
},
{
"cwe_id": 862,
"cwe_name": "missing authorization",
"count": 2354
},
{
"cwe_id": 352,
"cwe_name": "cross-site request forgery (csrf)",
"count": 1922
},
{
"cwe_id": 94,
"cwe_name": "improper control of generation of code ('code injection')",
"count": 1411
},
{
"cwe_id": 284,
"cwe_name": "improper access control",
"count": 1253
},
{
"cwe_id": 476,
"cwe_name": "null pointer dereference",
"count": 1219
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 1173
},
{
"cwe_id": 119,
"cwe_name": "improper restriction of operations within the bounds of a memory buffer",
"count": 1157
}
]
},
{
"year": 2026,
"cwe_stats": [
{
"cwe_id": 79,
"cwe_name": "improper neutralization of input during web page generation ('cross-site scripting')",
"count": 6138
},
{
"cwe_id": 284,
"cwe_name": "improper access control",
"count": 3701
},
{
"cwe_id": 862,
"cwe_name": "missing authorization",
"count": 3534
},
{
"cwe_id": 89,
"cwe_name": "improper neutralization of special elements used in an sql command ('sql injection')",
"count": 3303
},
{
"cwe_id": 22,
"cwe_name": "improper limitation of a pathname to a restricted directory ('path traversal')",
"count": 2346
},
{
"cwe_id": 416,
"cwe_name": "use after free",
"count": 2205
},
{
"cwe_id": 78,
"cwe_name": "improper neutralization of special elements used in an os command ('os command injection')",
"count": 1740
},
{
"cwe_id": 125,
"cwe_name": "out-of-bounds read",
"count": 1698
},
{
"cwe_id": 918,
"cwe_name": "server-side request forgery (ssrf)",
"count": 1684
},
{
"cwe_id": 787,
"cwe_name": "out-of-bounds write",
"count": 1671
}
]
}
]