Which weakness classes appear most often in the records in scope, with records carrying no CWE mapping reported rather than dropped.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.cves.cwes via fetchCves · public.canonical_findings in environment mode
Rule: Danger score per CWE = mean CVSS of the records carrying that CWE × ln(count + 1). Records with no CWE mapping are counted separately and reported, never silently dropped.
Danger score per CWE = average severity × log(frequency). A dangerous cluster is both common and serious.
Engineering themes the top CWEs typically roll up into:
Records with no usable CWE mapping are excluded from the ranking and counted separately in the KPI row; they are never silently dropped.
A CWE appearing here does not mean any of your assets are affected: presence on an asset is not assessed on this lens.
New to CWEs? Read CWE vs CVE explained for how weakness categories relate to individual vulnerabilities.