Cyber Resilience

Weakness Under-RatingWeekly

The weaknesses NVD marks up most: CWE-707 averages +2.4 over the vendor

Updated 12 August 2026 · Timeframe: All re-scored pairs, by CWE (>=80 pairs)

CWE-707 · Improper Neutralization2.4CWE-74 · Injection2.2CWE-89 · SQL Injection1.7CWE-352 · Cross-Site Request Forgery1.5CWE-266 · Incorrect Privilege Assignment1.4CWE-404 · Improper Resource Shutdown or Rel…1.4
Average NVD markup over the vendor, by weakness (CVSS points) · security-resilience.ai

When NVD re-scores a vendor's CVE, the size of the upward correction depends on the weakness type. Injection and impact-heavy classes lead: CWE-707 (Improper Neutralization) averages +2.4 points over the vendor's score. Vendors systematically under-rate the impact of these classes; NVD does not.

Why it matters

If your stack is heavy in the weakness types NVD marks up most, the vendor CVSS understates your real exposure by a predictable amount. Knowing which classes lets you correct for it.

What to do

Our take

Showing which weakness types the vendor-vs-NVD gap concentrates in turns a broad disagreement into an actionable correction.