CWE

Common Weakness Enumeration

A community-developed list of SW & HW weaknesses that can become vulnerabilities

New to CWE? click here!
CWE Most Important Hardware Weaknesses
CWE Top 25 Most Dangerous Weaknesses
Home > CWE Top 25 > 2023 On the Cusp Weaknesses Insight  
ID

2023 “On the Cusp” Weaknesses Insights


NOTICE: This is a previous version of the Top 25. For the most recent version go here.


The 2023 CWE Top 25 Most Dangerous Software Weaknesses list is a practical and convenient resource to help mitigate software security risk. But the complete dataset analyzed had 144 total weaknesses that were recorded, analyzed, and ranked. Beyond the Top 25, those performing mitigation and risk decision-making should consider these additional “On the Cusp” weaknesses in their efforts as they too can become severe, exploitable vulnerabilities under the right conditions.

Following are some observations on the weaknesses that did not make the 2023 CWE Top 25 list.

Analysis

The On the Cusp list comprises CWEs ranked in positions 26-40, per the 2023 CWE Top 25 Methodology. These CWEs continue to be prevalent and serious enough to cause concern.

Three CWEs have increased in rank to move them into this year’s On the Cusp list:

Two CWEs that were on the 2022 CWE Top 25 list dropped to the 2023 On the Cusp list:

Three CWEs that were on the 2022 On the Cusp list dropped out of this year’s On the Cusp list altogether (dropping to a position below the rank 40):

Page Last Updated: November 11, 2024