Rezultati pretraživanja
  1. 17. ruj 2019.

    PSA related to CVE and the : NIST is retiring NVD's XML feeds in October. (Guess how I found out ;-)) Might want to make sure you don't have any dependencies the XML feed. (json continues)

  2. 10. sij

    is no longer considered the top threat in but it's still common, easy, and dangerous

  3. 12. stu 2019.
  4. 22. lis 2019.
  5. 22. lis 2019.
    Odgovor korisnicima

    SQLi increase also seems inconsistent with what OWASP seems to be reporting. Can't really compare from 2011 with the 2019 version due to major methodology changes :( and even NVD data prolly isn't directly comparable :(

  6. 4. lis 2019.

    NVD has integrated the CWE mapping changes from the 2019 CWE Top 25 project. If you’re interested in replicating the methodology, get the new NVD data and see

  7. 20. ruj 2019.

    Memory Errors Top MITRE’s ‘Most Dangerous’ List, presenting biggest threat to orgs. New report reveals Top 25 most dangerous software errors–see how Virsec provides complete coverage for Top 10 errors, Memory and Web errors & more.

  8. 19. ruj 2019.

    So, CWE have released their Top 25 software errors that can lead to the most serious vulnerabilities in the software. What do you think about the Top 10? Agree/disagree.

  9. 18. ruj 2019.

    . just issued the Top 25 List of Software Weaknesses via . Many of the top weakness have been on the list for years. Read more via Security

  10. List of Top 25 Most Dangerous Software Flaws – 2019 CWE Top 25 Read More: The list was generated based on the data-driven approach based on the CVE published NVD, as well as the CVSS scores associated with it.

  11. 17. ruj 2019.

    This is more useful to teach developers, IMHO, than the OWASP Top 10. Why? Because the OWASP Top 10 describes vulnerabilities or attacks (and isn't specific on what), using InfoSec language. MITRE's , by contrast, talks to devs about dev behaviours using dev language.

  12. 17. ruj 2019.

    We are investigating why CWE-20 (improper input validation) is #3 in the CWE Top 25. It's a broad class, often used in low-info disclosures. Many CVEs say "input validation" w/o more details. Could also indicate a gap in the CWEs that NIST uses for mapping.

  13. 17. ruj 2019.

    CVE Entries, combined with NVD’s CVSS scores, are the basis for the 2019 CWE Top 25

  14. 17. ruj 2019.

    The 2019 CWE Top 25 Most Dangerous Software Errors list is now available. See .

  15. 15. sij 2015.

    CWE Top 25

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.