CWE

Common Weakness Enumeration

A Community-Developed List of Software Weakness Types

CWE/SANS Top 25 Most Dangerous Software Errors
Home > Compatibility > Sort By Category  
ID

CWE Community

Sort By Category

All organizations participating in the Compatibility Program are listed below.

Assessment and Remediation Tool

Product (66) Organization (39) Type Country (15) Capability Status
BigLook Evenstar Code verification tool for ensuring source code compliance with domestic and international code seucrity guidelines. Korea
Coverage
Output
Searchable
CWE Compatible
CAST Application Intelligence Platform CAST Automated Application Assessment Platform France
Output
Searchable
Coverage
CWE Compatible
COBOT Beijing Beida Software Engineering Development Co., Ltd. Program Static Analysis Tool P.R. China
Coverage
Output
Searchable
CWE Compatible
CodePeer AdaCore Automated Code Review and Validation Tool United States
Coverage
Output
Searchable
CWE Compatible
CodeScroll Code Inspector Suresoft Technologies Inc. Code-Based Auto Inspection Tool Korea
Coverage
Output
Searchable
CWE Compatible
CodeScroll SNIPER Suresoft Technologies Inc. Static Code Analysis Tool Korea
Coverage
Output
Searchable
CWE Compatible
CodeSonar GrammaTech, Inc. Static Analysis Tool United States
Output
Searchable
Coverage
CWE Compatible
Conviso Security Compliance (CSC) Conviso Application Security Vulnerability Identification and Management Brazil
Output
Searchable
Coverage
CWE Compatible
Coverity Quality Advisor Coverity, Inc. Static Application Security Testing (SAST) United States
Output
Searchable
Coverage
CWE Compatible
Coverity Security Advisor Coverity, Inc. Static Application Security Testing (SAST) United States
Output
Searchable
Coverage
CWE Compatible
Cr0security Penetration Testing and Consultant Services Cr0security Network Penetration Testing and Vulnerability Assessment Services Indonesia
Coverage
Output
Searchable
CWE Compatible
Flawfinder David A. Wheeler Assessment Tool United States
Coverage
Output
Searchable
CWE Compatible
HP Assessment Management Platform (ASP) Hewlett-Packard Development Company, L.P. Enterprise Platform for Managing a Web Application Security Assessment Program United States
Output
Searchable
Coverage
CWE Compatible
HP Fortify On Demand Hewlett-Packard Development Company, L.P. Static and Dynamic Analysis and Results Reporting Service United States
Output
Searchable
Coverage
CWE Compatible
HP Fortify Real-Time Analyzer Hewlett-Packard Development Company, L.P. Real-Time Detection and Prevention of Attacks United States
Output
Searchable
Coverage
CWE Compatible
HP Fortify Software Security Center Hewlett-Packard Development Company, L.P. Results Reporting United States
Output
Searchable
Coverage
CWE Compatible
HP Fortify Static Code Analyzer Hewlett-Packard Development Company, L.P. Static Analysis and Results Reporting United States
Output
Searchable
Coverage
CWE Compatible
HP WebInspect Hewlett-Packard Development Company, L.P. Dynamic Analysis Web Application Security Assessment Tool United States
Output
Searchable
Coverage
CWE Compatible
IBM Security AppScan Standard IBM Security Systems Web Application Security Assessment Scanner United States
Output
Searchable
Coverage
CWE Compatible
Julia Julia S.R.L. Static Program Analysis Tool Italy
Coverage
Output
Searchable
CWE Compatible
Kiuwan Code Analysis Optimyth Software SaaS Enterprise Software Analytics Platform - Local Static Code Analysis with Emphasis on Security Spain
Coverage
Output
Searchable
CWE Compatible
Klocwork Insight Klocwork, Inc. Assessment and Remediation Tool Canada
Output
Searchable
Coverage
CWE Compatible
LDRA Testbed LDRA Static and Dynamic Software Analysis Tool Suite United Kingdom
Output
Searchable
Coverage
CWE Compatible
LDRArules LDRA Static Analysis Tool and Coding Rules Checker United Kingdom
Coverage
Output
Searchable
CWE Compatible
Lucent Sky Application Vulnerability Mitigation (AVM) Lucent Sky Corporation Application Vulnerability Mitigation United States
Coverage
Output
Searchable
CWE Compatible
Polyspace Bug Finder MathWorks, Inc. Static Analysis Tool and Coding Rules Checker France
Coverage
Output
Searchable
CWE Compatible
QA*C - CWE Compliance Module for C Programming Language Programming Research, Inc. Static Analysis of C code with advanced Data-flow/Control-flow/Cross-project and Multilanguage capabilities United States
Coverage
Output
Searchable
CWE Compatible
RESORT Code Analysis Soft4Soft Co., Ltd. Static Analysis Tool and Coding Rules Checker Korea
Coverage
Output
Searchable
CWE Compatible
SecurityPrism GTONE Co., Ltd. Semantic Based Static Application Security Testing Tool Korea
Coverage
Output
Searchable
CWE Compatible
Software Assurance Reference Dataset (SARD) National Institute of Standards and Technology (NIST) Web-based Software Security Assurance Application United States
Output
Searchable
Coverage
CWE Compatible
SonarQube platform with C/C++ plugin SonarSource SA Continuous Inspection, Trending, and Code Quality Management Platform Switzerland
Coverage
Output
Searchable
CWE Compatible
SonarQube platform with Java plugin SonarSource SA Continuous Inspection, Trending, and Code Quality Management Platform Switzerland
Coverage
Output
Searchable
CWE Compatible
SonarQube platform with Objective-C plugin SonarSource SA Continuous Inspection, Trending, and Code Quality Management Platform Switzerland
Coverage
Output
Searchable
CWE Compatible
SPARROW Fasoo.com, Inc. Semantic-Based Static Program Analysis Tool Korea
Output
Searchable
Coverage
CWE Compatible
TBvision LDRA Static Analysis Tool and Coding Rules Checker United Kingdom
Output
Searchable
Coverage
CWE Compatible
ThreadFix Denim Group, Ltd Open Source Vulnerability Management Tool United States
Output
Searchable
Coverage
CWE Compatible
vFeed API and Vulnerability Database Community ToolsWatch Open Source Correlated and Cross-Linked Vulnerability XML Vulnerability Database France
Coverage
Output
Searchable
CWE Compatible
WebLayers Center Security Policy Library WebLayers, Inc. Software Development Lifecycle (SDLC) Governance United States
Output
Searchable
Coverage
CWE Compatible
C/C++test Versions 10.x Parasoft Corporation Static Code Analysis United States
Coverage
Output
Searchable
Available
Available
Available
C/C++test Versions 9.x Parasoft Corporation Static Code Analysis United States
Output
Searchable
Coverage
Available
Available
Available
Cenzic Hailstorm Enterprise ARC Cenzic, Inc. Web Application Security Risk Management Platform United States
Output
Searchable
Coverage
Available
Available
Available
Cenzic Hailstorm Professional Cenzic, Inc. Web Application Penetration Testing and Vulnerability Management System United States
Output
Searchable
Coverage
Available
Available
Available
Code Dx Enterprise Edition Code Dx, Inc. Software Vulnerability Assessment Tool United States
Output
Searchable
Coverage
Available
Available
Planned
Code Dx Standard Edition Code Dx, Inc. Software Vulnerability Assessment Tool United States
Output
Searchable
Coverage
Available
Available
Planned
CodeSecure Enterprise Armorize Technologies, Inc. Web Application Source Code Analysis Tool United States
Output
Searchable
Coverage
Available
Available
Available
CodeSecure Verifier Armorize Technologies, Inc. Web Application Source Code Analysis Suite United States
Output
Searchable
Coverage
Available
Available
Available
CodeSecure Workbench Armorize Technologies, Inc. Web Application Source Code Analysis Tool United States
Output
Searchable
Coverage
Available
Available
Available
COREvidence NETpeas, SA Cloud-Based, Multi-Engines Vulnerability Management Service France
Output
Coverage
Searchable
Available
Available
Planned
Cppcheck CppCheck Development Team A tool for static C/C++ code analysis Ireland
Output
Searchable
Coverage
Available
Available
Planned
CxCloud Checkmarx Static Code Analysis On Demand Israel
Output
Searchable
Coverage
Available
Available
Available
CxEnteprise Checkmarx Static Code Analysis On Premise Israel
Output
Searchable
Coverage
Available
Available
Available
CxSuite Checkmarx Static Application Security Testing/Application Security Code Review Israel
Output
Searchable
Coverage
Available
Available
Available
DEFENSICS X Codenomicon Ltd. Fuzz Testing Tool with Integrated Capability to Report CWE Identifiers and Descriptions for Found Vulnerabilities Finland
Output
Searchable
Coverage
Available
Available
Planned
dotTEST Versions 10.x Parasoft Corporation Static Code Analysis United States
Coverage
Output
Searchable
Available
Available
Available
dotTEST Versions 9.x Parasoft Corporation Static Code Analysis United States
Coverage
Output
Searchable
Available
Available
Available
IBM Security AppScan Enterprise IBM Security Systems Enterprise Web Application Security Assessment Tool United States
Output
Searchable
Coverage
Planned
Planned
Planned
IBM Security AppScan Source IBM Security Systems Source Code Testing Tool United States
Output
Searchable
Coverage
Available
Available
Available
Jtest Version 9.x Parasoft Corporation Static Code Analysis United States
Coverage
Output
Searchable
Available
Available
Available
Jtest Versions 10.x Parasoft Corporation Static Code Analysis United States
Coverage
Output
Searchable
Available
Available
Available
MyJVN Information-technology Promotion Agency, Japan (IPA) Filtered Vulnerability Countermeasure Information Tool Japan
Output
Searchable
Coverage
Available
Available
Available
SofCheck Inspector for Ada SofCheck Inc. Static Analysis and Fault Detection Tool United States
Searchable
Output
Coverage
Available
Planned
Planned
Zed Attack Proxy (ZAP) Open Web Application Security Project (OWASP) Integrated Penetration Testing Tool for Finding Vulnerabilities in Web Applications United Kingdom
Coverage
Output
Searchable
Available
Available
Planned
HP DevInspect Hewlett-Packard Development Company, L.P. Web Application Security Assessment Tool for Developers United States
Output
Searchable
Coverage
Planned
Planned
Planned
HP QAInspect Hewlett-Packard Development Company, L.P. Web Application Security Assessment Tool for QA United States
Output
Searchable
Coverage
Planned
Planned
Planned
QA*CPP - CWE Compliance Module for C++ Programming Language Programming Research, Inc. Source Code Static Analysis Product Suite United States
Output
Searchable
Coverage
Planned
Planned
Planned
Rational AppScan Tester Edition IBM Rational Development-Time Web Application Security Testing Tool United States
Output
Searchable
Coverage
Planned
Planned
Planned

Assessment Service

Product (23) Organization (13) Type Country (6) Capability Status
Cr0security Penetration Testing and Consultant Services Cr0security Network Penetration Testing and Vulnerability Assessment Services Indonesia
Coverage
Output
Searchable
CWE Compatible
HP Assessment Management Platform (ASP) Hewlett-Packard Development Company, L.P. Enterprise Platform for Managing a Web Application Security Assessment Program United States
Output
Searchable
Coverage
CWE Compatible
HP Fortify On Demand Hewlett-Packard Development Company, L.P. Static and Dynamic Analysis and Results Reporting Service United States
Output
Searchable
Coverage
CWE Compatible
HP Fortify Software Security Center Hewlett-Packard Development Company, L.P. Results Reporting United States
Output
Searchable
Coverage
CWE Compatible
HP WebInspect Hewlett-Packard Development Company, L.P. Dynamic Analysis Web Application Security Assessment Tool United States
Output
Searchable
Coverage
CWE Compatible
ImmuniWeb High-Tech Bridge SA SaaS Web Application Vulnerability Assessment Service Switzerland
Coverage
Output
Searchable
CWE Compatible
Red Hat Customer Portal Red Hat, Inc. Customer Assessment Service United States
Output
Searchable
Coverage
CWE Compatible
Security-Database Web Services Security-Database Web Services France
Output
Searchable
Coverage
CWE Compatible
Veracode Analytics Veracode, Inc. SAST, DAST, Manual Penetration Testing United States
Output
Searchable
Coverage
CWE Compatible
Veracode Dynamic Analysis Veracode, Inc. SAST, DAST, Manual Penetration Testing United States
Output
Searchable
Coverage
CWE Compatible
Veracode Manual Testing Veracode, Inc. SAST, DAST, Manual Penetration Testing United States
Output
Searchable
Coverage
CWE Compatible
Veracode Static Analysis Veracode, Inc. SAST, DAST, Manual Penetration Testing United States
Output
Searchable
Coverage
CWE Compatible
Ambionics Security Ambionics Security Security Service France
Coverage
Output
Searchable
Available
Available
Available
Architectural and Design Risk Management Cigital, Inc. Software Security Architecture and Design Risk Assessment and Management United States
Output
Searchable
Coverage
Available
Available
Planned
cIFrex CXSecurity Free Security Research Tool Poland
Output
Searchable
Documentation
Coverage
Available
Available
Available
Available
COREvidence NETpeas, SA Cloud-Based, Multi-Engines Vulnerability Management Service France
Output
Coverage
Searchable
Available
Available
Planned
Secure Code Review Astyran Pte Ltd. Secure Code Review Singapore
Output
Searchable
Coverage
Available
Available
Planned
Secure Code Review with Automated Tools Cigital, Inc. Security Code Assessment United States
Output
Searchable
Coverage
Available
Available
Planned
Secure Design Review Astyran Pte Ltd. Secure Design Review Singapore
Output
Searchable
Coverage
Available
Available
Planned
Software Assurance Assessment KDM Analytics Software Assurance Assessment Service United States
Output
Searchable
Coverage
Available
Available
Planned
Web Application Vulnerability Assessment Astyran Pte Ltd. Application Vulnerability Assessment Singapore
Output
Searchable
Coverage
Available
Available
Available
HP SaaS for ASC Hewlett-Packard Development Company, L.P. Web Application Security Assessment and AMP delivered through Software-as-a-Service United States
Output
Searchable
Coverage
Planned
Planned
Planned
Secure Programming Exams/Assessments SANS Institute Professional Secure Programming Examination United States
Output
Searchable
Coverage
Planned
Planned
Planned

Database/Knowledge Repository

Product (13) Organization (13) Type Country (8) Capability Status
Conviso Security Compliance (CSC) Conviso Application Security Vulnerability Identification and Management Brazil
Output
Searchable
Coverage
CWE Compatible
High-Tech Bridge Security Advisories High-Tech Bridge SA Database/Knowledge Repository Based upon High-Tech Bridge's Proprietary Research Switzerland
Output
Searchable
Coverage
CWE Compatible
LDRA Testbed LDRA Static and Dynamic Software Analysis Tool Suite United Kingdom
Output
Searchable
Coverage
CWE Compatible
Security-Database Web Services Security-Database Web Services France
Output
Searchable
Coverage
CWE Compatible
Software Assurance Reference Dataset (SARD) National Institute of Standards and Technology (NIST) Web-based Software Security Assurance Application United States
Output
Searchable
Coverage
CWE Compatible
TBvision LDRA Static Analysis Tool and Coding Rules Checker United Kingdom
Output
Searchable
Coverage
CWE Compatible
vFeed API and Vulnerability Database Community ToolsWatch Open Source Correlated and Cross-Linked Vulnerability XML Vulnerability Database France
Coverage
Output
Searchable
CWE Compatible
World Laboratory of Bugtraq (WLB) 2 CXSecurity Vulnerability Database Poland
Output
Searchable
Coverage
CWE Compatible
JVN iPedia Information-technology Promotion Agency, Japan (IPA) Vulnerability Countermeasure Information Database Japan
Output
Searchable
Coverage
Available
Available
Available
SDElements SD Elements Secure Application Lifecycle Management (SALM) Tool United States
Output
Searchable
Coverage
Available
Available
Available
SecurityAlert SecurityReason Web Application Security Risk Management Platform Poland
Output
Searchable
Coverage
Available
Available
Available
SofCheck Inspector for Ada SofCheck Inc. Static Analysis and Fault Detection Tool United States
Searchable
Output
Coverage
Available
Planned
Planned
Tool Output Integration Framework (TOIF) KDM Analytics Open Source Vulnerability Detection Platform United States
Output
Searchable
Coverage
Available
Available
Available

Education Offering

Product (8) Organization (8) Type Country (2) Capability Status
Cr0security Certified Security Testing Cr0security Professional Security Testing Certification Indonesia
Coverage
Output
Searchable
CWE Compatible
Certification of Software Lifecycle Personnel ISC2 The International Information Systems Security Certification Consortium Professional Certification United States
Output
Searchable
Coverage
Available
Planned
Planned
SDElements SD Elements Secure Application Lifecycle Management (SALM) Tool United States
Output
Searchable
Coverage
Available
Available
Available
Secure programming class, CS390S CERIAS/Purdue University Secure Programming Class and Publicly Available Teaching Materials United States
Output
Searchable
Coverage
Available
Available
Planned
Security Training and Awareness (various courses) Cigital, Inc. Software Security Training and Awareness Courses United States
Output
Searchable
Coverage
Available
Available
Planned
EC-Council Certified Secure Programmer EC-Council Secure Programmer Certification Program United States
Output
Searchable
Coverage
Planned
Planned
No
Secure Application Development Training Courses SkillBridge, LLC Instructor Led Training United States
Output
Searchable
Coverage
Planned
Planned
Planned
Secure Programming Exams/Assessments SANS Institute Professional Secure Programming Examination United States
Output
Searchable
Coverage
Planned
Planned
Planned

Software Development Practices

Product (14) Organization (11) Type Country (4) Capability Status
Cr0security Certified Security Testing Cr0security Professional Security Testing Certification Indonesia
Coverage
Output
Searchable
CWE Compatible
HP Assessment Management Platform (ASP) Hewlett-Packard Development Company, L.P. Enterprise Platform for Managing a Web Application Security Assessment Program United States
Output
Searchable
Coverage
CWE Compatible
HP WebInspect Hewlett-Packard Development Company, L.P. Dynamic Analysis Web Application Security Assessment Tool United States
Output
Searchable
Coverage
CWE Compatible
Kiuwan Code Analysis Optimyth Software SaaS Enterprise Software Analytics Platform - Local Static Code Analysis with Emphasis on Security Spain
Coverage
Output
Searchable
CWE Compatible
QA*C - CWE Compliance Module for C Programming Language Programming Research, Inc. Static Analysis of C code with advanced Data-flow/Control-flow/Cross-project and Multilanguage capabilities United States
Coverage
Output
Searchable
CWE Compatible
WebLayers Center Security Policy Library WebLayers, Inc. Software Development Lifecycle (SDLC) Governance United States
Output
Searchable
Coverage
CWE Compatible
Certification of Software Lifecycle Personnel ISC2 The International Information Systems Security Certification Consortium Professional Certification United States
Output
Searchable
Coverage
Available
Planned
Planned
Cppcheck CppCheck Development Team A tool for static C/C++ code analysis Ireland
Output
Searchable
Coverage
Available
Available
Planned
EMC Product Security Policy (PSP) EMC Corporation and RSA (The Security Division of EMC) Enterprise Policy for Secure Product Development United States
Output
Searchable
Coverage
Available
Available
No
EMC Security Development Lifecycle (SDL) EMC Corporation and RSA (The Security Division of EMC) Enterprise Secure Development Lifecycle United States
Output
Searchable
Coverage
Available
Available
No
EMC Vulnerability Response Policy (VRP) EMC Corporation and RSA (The Security Division of EMC) Enterprise Response Policy for Product Vulnerabilities United States
Output
Searchable
Coverage
Available
Available
No
Secure Development Lifecycle Apple, Inc. Secure Development Lifecycle United States
Output
Coverage
Searchable
Available
Available
No
Symantec Product Security Symantec Corporation Symmunize (Symantec's Secure Development Lifecycle Process) United States
Output
Searchable
Coverage
Available
Available
No
Tool Output Integration Framework (TOIF) KDM Analytics Open Source Vulnerability Detection Platform United States
Output
Searchable
Coverage
Available
Available
Available

More information is available — Please select a different filter.
Page Last Updated: October 11, 2017