METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

AI GlossaryCSafety and controversy

CWE Category

A standardized list of numbered, named categories that classify recurring types of security vulnerabilities in software.

In plain words

A CWE Category is a standard classification scheme that assigns a number and a name to each recurring type of security vulnerability found in software. Problems like failing to properly filter input, or forgetting to check permissions, keep showing up across completely different programs — and each of these recurring mistake types is cataloged much like a hospital's diagnostic codes for diseases.

When a scanning tool or a person finds a vulnerability, saying "this belongs to category number X" lets different companies and developers talk about the same problem using the same language, regardless of who found it or where. That's why security scan results commonly list a CWE Category alongside a confidence rating (how likely the finding is real) and a severity rating (how dangerous it would be if it is real).

How it shows up in the news

Articles often explain that "each finding comes with a CWE Category, a confidence rating, a severity rating, and a suggested fix." A common point of confusion here is that the CWE Category itself does not tell you how risky or how certain a finding is. It only names what kind of vulnerability it is — the actual risk level and certainty are provided separately, through the confidence and severity ratings.

Try it yourself

Paste in a piece of code and ask something like:

"If there's a security issue in this code, which CWE Category would it fall under, and why?"

Looking at the CWE number and name in the response shows how the same type of problem gets classified identically across different projects.

See also

Stories using this term

Browse every entry