#CWE

CVE ProgramCVE_Program
2025-12-19

1,736 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of December 8, 2025

cisa.gov/news-events/bulletins

PressMind Labspressmind
2025-12-18

GPT-5.2-Codex: nowy standard w programowaniu – bezpieczeństwo i jakość w kodzie

Czy model, który pisze kod szybciej niż junior po kawie, nauczył się wreszcie mówić „nie” wtedy, kiedy trzeba? OpenAI dorzuciło addendum do karty systemowej GPT-5.

Czytaj dalej:
pressmind.org/gpt-52-codex-now

Ilustracja przedstawiająca futurystyczne środowisko programistyczne z robotem przy biurku.
CVE ProgramCVE_Program
2025-12-16

816 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of December 1, 2025

cisa.gov/news-events/bulletins

CWE ProgramCWE_Program
2025-12-11

4.19 is now available! This latest release includes 1 new view to support the release of the “2021 CWE Top 25 Most Dangerous Software Weaknesses,” 1 new view for the “OWASP Top Ten 2025,” + continued CWE content usability improvements

cwe.mitre.org/news/archives/ne

Common Weakness Enumeration (CWE™) Version 4.19 now available!
CWE ProgramCWE_Program
2025-12-11

The 2025 Top 25 Most Dangerous Weaknesses list is now available!

See the the most severe and prevalent weaknesses behind the 39,080 Records in this year’s dataset. Take a look and share your thoughts!

cwe.mitre.org/top25/

The "2025 CWE Top 25 Most Dangerous Software Weaknesses" list demonstrates the currently most common and impactful software weaknesses. Often easy to find and exploit, these can lead to exploitable vulnerabilities that allow adversaries to completely take over a system, steal data, or prevent applications from working.
CVE ProgramCVE_Program
2025-12-08

468 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of November 24, 2025

cisa.gov/news-events/bulletins

CVE ProgramCVE_Program
2025-12-02

“CNA Enrichment Recognition” - 256 CNAs on the list for December 1, 2025

Published monthly, this list recognizes those CVE Numbering Authorities () actively providing and vulnerability data in their Records

medium.com/@cve_program/vulner

Increasing the Value of the CVE Record - CNA Enrichment Recognition List
CVE ProgramCVE_Program
2025-12-01

733 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of November 17, 2025

cisa.gov/news-events/bulletins

CWE ProgramCWE_Program
2025-11-17

User Experience Working Group (UEWG) members — Reminder that our next meeting is Wednesday, 11/19/2025, at 12:00-1:00PM EST

Topic:
- CWE Corpus Completeness

Join CWE UEWG: bit.ly/3CIylfz

CWE ProgramCWE_Program
2025-11-13

Hardware SIG members—Reminder that our next meeting is Friday, 11/14/2025, at 12:30-1:30 PM EST (16:30 – 17:30 UTC)

Topic:
- Review: “Formation of RTL Weakness Ad-Hoc Working Group”

Join SIG: bit.ly/3SCkqyk

CVE ProgramCVE_Program
2025-11-10

“CNA Enrichment Recognition” - 252 CNAs on the list for November 3, 2025

Published monthly, this list recognizes those CVE Numbering Authorities () actively providing and vulnerability data in their Records

medium.com/@cve_program/vulner

Increasing the Value of the CVE Record - CNA Enrichment Recognition List
CVE ProgramCVE_Program
2025-10-07

“CNA Enrichment Recognition” - 252 CNAs on the list for October 6, 2025

Published monthly, this list recognizes those CVE Numbering Authorities () actively providing and vulnerability data in their Records

medium.com/@cve_program/vulner

Increasing the Value of the CVE Record - CNA Enrichment Recognition List
CWE ProgramCWE_Program
2025-10-07

Hardware SIG members—Reminder that our next meeting is Friday, 10/10/2025, at 12:30-1:30 PM EDT (16:30 – 17:30 UTC)

Topic:
- Review HW submission: “Improper Request Propagation before Data Reception in Write Transactions in a Bus Architecture”

Join SIG: bit.ly/3SCkqyk

CVE ProgramCVE_Program
2025-10-02

1,064 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of September 22, 2025

cisa.gov/news-events/bulletins

CVE ProgramCVE_Program
2025-09-29

1,214 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of September 15, 2025

cisa.gov/news-events/bulletins

CVE ProgramCVE_Program
2025-09-23

840 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of September 8, 2025

cisa.gov/news-events/bulletins

2025-09-16

OWASP Top Ten 2021 через простые примеры на Java. И немного про SAST

В этой статье мы расскажем про категории OWASP Top Ten 2021 через призму срабатываний Java анализатора PVS-Studio. Так что, если у вас есть желание посмотреть на возможные паттерны уязвимостей в Java коде или узнать, что из себя представляют категории OWASP Top Ten, приятного чтения!

habr.com/ru/companies/pvs-stud

#owasp_top10 #pvsstudio #статистический_анализ #java #примеры_кода #информационная_безопасность #cwe #cve #owasp #sast

JAVAPROjavapro
2025-09-15

done.“ Wirklich? Doch was ist mit Path Traversal, unsicheren temp files & ? @svenruppert zeigt, wie Uploads mit Flow & NIO sicher werden - gegen CWE-22 -377 & CWE-778.

Lese: javapro.io/de/erstellen-einer-

@vaadin

CVE ProgramCVE_Program
2025-09-15

994 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of September 1, 2025

cisa.gov/news-events/bulletins

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst