{
  "node_id": "mitre-cwe-top-25-2024-most-dangerous-weaknesses",
  "title": "MITRE CWE Top 25 Most Dangerous Software Weaknesses 2024 (CWE-79 XSS, CWE-787 Out-of-bounds Write, CWE-89 SQL Injection, CWE-352 CSRF, CWE-22 Path Traversal, CWE-125, CWE-78, CWE-416, CWE-862)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-03",
  "bluf": "The 2024 CWE Top 25 Most Dangerous Software Weaknesses, published by The MITRE Corporation's CWE program at cwe.mitre.org/top25/archive/2024/, is the ranked annual list of the most severe and prevalent software weaknesses derived from analysis of 31,770 CVE records in the 2024 dataset. The list is generated using a published methodology that scores CWEs by frequency and severity (KEV-weighted impact). The 2024 ranking is: 1 CWE-79 (XSS), 2 CWE-787 (Out-of-bounds Write), 3 CWE-89 (SQL Injection), 4 CWE-352 (CSRF), 5 CWE-22 (Path Traversal), 6 CWE-125 (Out-of-bounds Read), 7 CWE-78 (OS Command Injection), 8 CWE-416 (Use After Free), 9 CWE-862 (Missing Authorization), 10 CWE-434 (Unrestricted Upload of File with Dangerous Type), 11 CWE-94 (Code Injection), 12 CWE-20 (Improper Input Validation), 13 CWE-77 (Command Injection), 14 CWE-287 (Improper Authentication), 15 CWE-269 (Improper Privilege Management), 16 CWE-502 (Deserialization of Untrusted Data), 17 CWE-200 (Exposure of Sensitive Information), 18 CWE-863 (Incorrect Authorization), 19 CWE-918 (SSRF), 20 CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), 21 CWE-476 (NULL Pointer Dereference), 22 CWE-798 (Use of Hard-coded Credentials), 23 CWE-190 (Integer Overflow), 24 CWE-400 (Uncontrolled Resource Consumption), 25 CWE-306 (Missing Authentication for Critical Function). The CWE Top 25 is the canonical reference used by application security programs, secure SDLC requirements, the OWASP Top 10 cross-walk, the PCI Software Security Framework, and federal software-supply-chain policy (NIST SSDF, EO 14028, Memo M-22-18) to prioritise remediation and secure-coding training.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "ranking_basis",
      "key_institutions",
      "top_5_weaknesses",
      "ranks_6_through_10",
      "ranks_11_through_15",
      "ranks_16_through_20",
      "ranks_21_through_25",
      "methodology_kev_weighted",
      "cross_walks_to_owasp_pci_nist_eo14028",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "cyber-nist-csf-2",
    "us-cisa-kev-catalog",
    "oasis-stix-2-1-structured-threat-information",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}