Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
cwe-tool — 基于OWASP/CAPSEC通用弱点枚举数据库的命令行CWE发现工具。 | Kitploit
工具/GitHubGitHub/owasp/cwe-tool
静态分析漏洞分析代码分析实用工具与框架学习与教育精选资源
GitHubowasp/cwe-tool

cwe-tool

基于OWASP/CAPSEC通用弱点枚举数据库的命令行CWE发现工具。

查看仓库
642254个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

cwe-tool

一个基于 OWASP / CAPSEC 通用弱点枚举数据库的命令行 CWE 发现工具。
官方 OWASP CWE Toolkit 页面

npm version license downloads build codecov Known Vulnerabilities Responsible Disclosure Policy

安装

通过 Node.js 工具直接执行

如果您有 Node.js 环境,可以使用 npx 工具调用 cwe-tool,如下所示:

root@kitploit:~
npx cwe-tool [...命令行选项...]

Docker

从 Docker Hub 拉取镜像

root@kitploit:~
docker pull lirantal/cwe-tool
docker run --rm lirantal/cwe-tool --search test

本地构建说明

root@kitploit:~
git clone https://github.com/OWASP/cwe-tool
docker build -t docker.pkg.github.com/owasp/cwe-tool/cwe-tool . 

上述 -t 参数后的 image name 可以替换为您选择的镜像名称!

使用 Docker 运行示例

root@kitploit:~
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --id 22
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --search test

不想本地构建?直接拉取镜像

从 GitHub 包注册表拉取镜像并执行搜索

root@kitploit:~
docker pull docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest --search test

用法

CWE 工具输出为 JSON 格式,以便后续处理数据或进行深入分析。

命令行选项说明:

示例

通过 ID 获取 CWE

root@kitploit:~
npx cwe-tool --id 22

过滤满足父级关系的 CWE ID

以下命令基于 CWE ID 是否在树中满足与给定父 ID 的任何直接或间接关系进行过滤。

root@kitploit:~
npx cwe-tool --id 22 --parent-id 167 --indirect

输出为以下 JSON:

root@kitploit:~
{
  "attr": {
    "@_ID": "242",
    "@_Name": "Use of Inherently Dangerous Function",
    "@_Abstraction": "Base",
    "@_Structure": "Simple",
    "@_Status": "Draft"
  },
  "Description": "The program calls a function that can never be guaranteed to work safely.",
  "Extended_Description": "Certain functions behave in dangerous ways regardless of how they are used. Functions in this category were often implemented without taking security concerns into account. The gets() function is unsafe because it does not perform bounds checking on the size of its input. An attacker can easily send arbitrarily-sized input to gets() and overflow the destination buffer. Similarly, the >> operator is unsafe to use when reading into a statically-allocated character array because it does not perform bounds checking on the size of its input. An attacker can easily send arbitrarily-sized input to the >> operator and overflow the destination buffer.",
  "Related_Weaknesses": {
    "Related_Weakness": {
      "attr": {
        "@_Nature": "ChildOf",
        "@_CWE_ID": "1177",
        "@_View_ID": "1000",
        "@_Ordinal": "Primary"
      }
    }
  },
  "Weakness_Ordinalities": { "Weakness_Ordinality": { "Ordinality": "Primary" } },
  "Applicable_Platforms": {
    "Language": [
      { "attr": { "@_Name": "C", "@_Prevalence": "Undetermined" } },
      { "attr": { "@_Name": "C++", "@_Prevalence": "Undetermined" } }
    ]
  },
  "Modes_Of_Introduction": { "Introduction": { "Phase": "Implementation" } },
  "Likelihood_Of_Exploit": "High",
  "Common_Consequences": { "Consequence": { "Scope": "Other", "Impact": "Varies by Context" } },
  "Potential_Mitigations": {
    "Mitigation": [
      {
        "Phase": ["Implementation", "Requirements"],
        "Description": "Ban the use of dangerous functions. Use their safe equivalent."
      },
      {
        "Phase": "Testing",
        "Description": "Use grep or static analysis tools to spot usage of dangerous functions."
      }
    ]
  },
  "Demonstrative_Examples": {
    "Demonstrative_Example": [
      {
        "Intro_Text": "The code below calls gets() to read information into a buffer.",
        "Example_Code": {
          "attr": { "@_Nature": "bad", "@_Language": "C" },
          "xhtml:div": { "#text": "char buf[BUFSIZE];gets(buf);", "xhtml:br": "" }
        },
        "Body_Text": "The gets() function in C is inherently unsafe."
      },
      {
        "attr": { "@_Demonstrative_Example_ID": "DX-5" },
        "Intro_Text": "The code below calls the gets() function to read in data from the command line.",
        "Example_Code": {
          "attr": { "@_Nature": "bad", "@_Language": "C" },
          "xhtml:div": {
            "#text": "}",
            "xhtml:div": {
              "#text": "char buf[24];printf(\"Please enter your name and press <Enter>\\n\");gets(buf);...",
              "attr": { "@_style": "margin-left:10px;" },
              "xhtml:br": ["", "", ""]
            }
          }
        },
        "Body_Text": "However, the programmer uses the function gets() which is inherently unsafe because it blindly copies all input from STDIN to the buffer without checking size. This allows the user to provide a string that is larger than the buffer size, resulting in an overflow condition."
      }
    ]
  },
  "Taxonomy_Mappings": {
    "Taxonomy_Mapping": [
      {
        "attr": { "@_Taxonomy_Name": "7 Pernicious Kingdoms" },
        "Entry_Name": "Dangerous Functions"
      },
      {
        "attr": { "@_Taxonomy_Name": "CERT C Secure Coding" },
        "Entry_ID": "POS33-C",
        "Entry_Name": "Do not use vfork()",
        "Mapping_Fit": "CWE More Abstract"
      },
      {
        "attr": { "@_Taxonomy_Name": "Software Fault Patterns" },
        "Entry_ID": "SFP3",
        "Entry_Name": "Use of an improper API"
      }
    ]
  },
  "References": {
    "Reference": [
      { "attr": { "@_External_Reference_ID": "REF-6" } },
      {
        "attr": { "@_External_Reference_ID": "REF-194", "@_Section": "Chapter 5. Working with I/O" }
      },
      {
        "attr": {
          "@_External_Reference_ID": "REF-7",
          "@_Section": "Chapter 5, "gets and fgets" Page 163"
        }
      }
    ]
  },
  "Content_History": {
    "Submission": { "Submission_Name": "7 Pernicious Kingdoms", "Submission_Date": "2006-07-19" },
    "Modification": [
      {
        "Modification_Name": "Sean Eidemiller",
        "Modification_Organization": "Cigital",
        "Modification_Date": "2008-07-01",
        "Modification_Comment": "added/updated demonstrative examples"
      },
      {
        "Modification_Name": "Eric Dalci",
        "Modification_Organization": "Cigital",
        "Modification_Date": "2008-07-01",
        "Modification_Comment": "updated Potential_Mitigations"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2008-09-08",
        "Modification_Comment": "updated Applicable_Platforms, Relationships, Other_Notes, Taxonomy_Mappings, Type, Weakness_Ordinalities"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2008-11-24",
        "Modification_Comment": "updated Relationships, Taxonomy_Mappings"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2009-10-29",
        "Modification_Comment": "updated Description, Other_Notes, References"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2010-02-16",
        "Modification_Comment": "updated Demonstrative_Examples, References, Relationships"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2010-04-05",
        "Modification_Comment": "updated Relationships"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2011-06-01",
        "Modification_Comment": "updated Common_Consequences"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2011-06-27",
        "Modification_Comment": "updated Common_Consequences"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2012-05-11",
        "Modification_Comment": "updated Relationships"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2012-10-30",
        "Modification_Comment": "updated Potential_Mitigations"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2014-07-30",
        "Modification_Comment": "updated Demonstrative_Examples, Relationships, Taxonomy_Mappings"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2017-11-08",
        "Modification_Comment": "updated Causal_Nature, References, Relationships, Taxonomy_Mappings"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2018-03-27",
        "Modification_Comment": "updated References"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2019-01-03",
        "Modification_Comment": "updated Relationships"
      },
      {
        "Modification_Name": "CWE Content Team",
        "Modification_Organization": "MITRE",
        "Modification_Date": "2020-02-24",
        "Modification_Comment": "updated References, Relationships"
      }
    ],
    "Previous_Entry_Name": [
      { "#text": "Dangerous Functions", "attr": { "@_Date": "2008-01-30" } },
      { "#text": "Use of Inherently Dangerous Functions", "attr": { "@_Date": "2008-04-11" } }
    ]
  }
}

贡献

请参考 CONTRIBUTING 以获取关于为本项目贡献的指南。

作者

cwe-tool © Liran Tal,以 Apache-2.0 许可证发布。

下载工具
命令行参数描述实现状态
--id通过 ID 获取 CWE 数据。✅
--parent-id当同时提供 --id 和 --parent-id 时,仅返回满足父 ID 条件的 CWE ID。✅ 欢迎 PR
--indirect与 --parent-id 一起指定时,检索至根节点的所有间接父级。✅
--search字符串搜索,返回所有匹配的 CWE 标题。✅
--show-membership返回所有 CWE ID 及其对应的 CWE 类别成员关系。❌ 欢迎 PR