diff --git a/discover-snyk/supported-languages/supported-languages-list/cobol.md b/discover-snyk/supported-languages/supported-languages-list/cobol.md
index 8a996142d3c8..4fa902ec1ce8 100644
--- a/discover-snyk/supported-languages/supported-languages-list/cobol.md
+++ b/discover-snyk/supported-languages/supported-languages-list/cobol.md
@@ -1,29 +1,25 @@
---
-description: Snyk support for COBOL with Snyk Code, available in Early Access on Enterprise plans, including CICS frameworks and supported dialects
+description: Snyk Code support for COBOL, including CICS frameworks and supported dialects
nav_context: agnostic
---
# COBOL
{% hint style="info" %}
-COBOL is supported only for Snyk Code.
+Snyk supports COBOL only in Snyk Code.
{% endhint %}
## COBOL for Snyk Code
-{% hint style="info" %}
-Code analysis support for COBOL is in Early Access and is available only with Enterprise plans. To enable the feature, see [Snyk Preview](https://app.gitbook.com/s/IgtgtomLQ2TUgSKOMSAm/snyk-hierarchy/snyk-preview).
-{% endhint %}
-
For an overview of the supported security rules, visit [COBOL rules](https://app.gitbook.com/s/BJO0IZx7zB6bOkotxQP2/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules).
### Supported frameworks and libraries
-For COBOL with Snyk Code, Snyk supports the CICS frameworks and libraries.
+For COBOL, Snyk Code supports CICS frameworks and libraries.
### Supported dialects and formats
-* IBM Enterprise COBOL for z/OS (v4.2+)
+* IBM Enterprise COBOL for z/OS version 4.2 and later
* Micro Focus COBOL
* GNU COBOL
* OpenCOBOL
@@ -33,7 +29,7 @@ For COBOL with Snyk Code, Snyk supports the CICS frameworks and libraries.
### Supported file formats
-The following file formats are supported: `.cbl`, `.ccp`, `.cob`, `.cpy`.
+Snyk Code supports the following file formats: `.cbl`, `.ccp`, `.cob`, `.cpy`.
### Available features
diff --git a/discover-snyk/supported-languages/supported-languages-package-managers-and-frameworks.md b/discover-snyk/supported-languages/supported-languages-package-managers-and-frameworks.md
index 4a8ffb9b05ed..f3bda32a4316 100644
--- a/discover-snyk/supported-languages/supported-languages-package-managers-and-frameworks.md
+++ b/discover-snyk/supported-languages/supported-languages-package-managers-and-frameworks.md
@@ -21,10 +21,10 @@ Check the language availability before you import, test, or monitor it as an app
The following table lists supported languages and the availability of support for using each language with SCM integrations and Snyk CLI, IDE, and CI/CD. Navigate to each language page for more details.
-
+
{% hint style="info" %}
-Interfile analysis in Snyk Code is available for all supported languages.
+Interfile analysis in Snyk Code is available for all supported languages except COBOL.
For Snyk Open Source, only official releases are tracked. Commits, including into the default branch, are not identified unless included in an official release or tag.
diff --git a/discover-snyk/whats-new.md b/discover-snyk/whats-new.md
index 37644668b9cf..5a56542ad25e 100644
--- a/discover-snyk/whats-new.md
+++ b/discover-snyk/whats-new.md
@@ -9,6 +9,12 @@ nav_context: new
The most recent updates include significant changes to the user docs, such as features added or removed, structural changes that affect how you find relevant information, and other improvements to enhance your interaction with the Snyk knowledge base.
+## August 2026
+
+### Snyk supported languages
+
+* Snyk Code support for COBOL is now generally available, on all plans, across SCM integrations and the Snyk CLI, IDE, and CI/CD. Visit [COBOL](https://docs.snyk.io/supported-languages/supported-languages-list/cobol) and [COBOL rules](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules) for more details.
+
## July 2026
### Evo by Snyk
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically.md
index bee684d3e7fe..35fb36e99343 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically.md
@@ -18,7 +18,7 @@ Snyk Agent Fix uses an agentic architecture that combines Snyk proprietary secur
* Dynamic few-shot prompting: Instead of relying on fine-tuning, the architecture uses the Snyk database of more than 35,000 expert-written fixes to provide real-world context to the LLM during inference. Every sample includes vulnerable code from real open-source projects and fixes written by Snyk security experts.
* Agentic retries: If a generated fix fails a Snyk Code scan, the system analyzes the error, feeds it back into the model, and generates a corrected version.
-Snyk Agent Fix remediates vulnerabilities across your entire stack without language-specific fine-tuning. By using a prompt-based agentic reasoning model, Snyk Agent Fix supports all languages supported by Snyk Code: Apex, C, C++, C#, Go, Java, JavaScript, PHP, Python, Ruby, Swift, and TypeScript.
+Snyk Agent Fix remediates vulnerabilities across your stack without language-specific fine-tuning. By using a prompt-based agentic reasoning model, Snyk Agent Fix supports every language that Snyk Code supports. For the current list, see [Supported languages, package managers, and frameworks](https://app.gitbook.com/s/L7HyJj9FsK1W4pNt8Gzl/supported-languages/supported-languages-package-managers-and-frameworks).
## How Snyk Agent Fix works
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/README.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/README.md
index 9c06a8a666cb..42be7c1c935a 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/README.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/README.md
@@ -13,10 +13,10 @@ This page lists all security rules used by Snyk Code when scanning your source c
Each rule includes the following information.
-* Rule Name: The Snyk name of the rule.
+* **Rule Name**: The Snyk name of the rule.
* **Languages**: The programming languages to which this specific rule applies. Note that there might be two rules with the same name that apply to different languages.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
{% hint style="info" %}
\* XML listed in the language column applies only to NuGet XML files.
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/apex-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/apex-rules.md
index 9f0b29b20fb6..488cc1029e4c 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/apex-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/apex-rules.md
@@ -8,29 +8,28 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s)**: The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/) (2025 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Access Violation | CWE-284, CWE-285 | OWASP:A01 | Yes |
-| Clear Text Sensitive Storage | CWE-200, CWE-312 | OWASP:A01, OWASP:A04 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Improper Access Control: Email Content Injection | CWE-284 | OWASP:A01 | Yes |
-| Use of Hardcoded Credentials | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Insecure Data Transmission | CWE-319 | OWASP:A02 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Regular expression injection | CWE-400, CWE-730 | None | Yes |
-| SOQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| SOSL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Unverified Password Change | CWE-620 | OWASP:A07 | Yes |
-| Unsafe SOQL Concatenation | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Unsafe SOSL Concatenation | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| XML Injection | CWE-91 | OWASP:A03 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | -------------------------------------------------------------------- |
+| Access Violation | CWE-284, CWE-285 | CWE Top 25, OWASP:A01:2025, OWASP-API:API1:2023, OWASP-API:API5:2023 |
+| Clear Text Sensitive Storage | CWE-200, CWE-312 | CWE Top 25, OWASP:A01:2025, OWASP:A06:2025, OWASP-API:API10:2023 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Improper Access Control: Email Content Injection | CWE-284 | CWE Top 25, OWASP:A01:2025 |
+| Use of Hardcoded Credentials | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Insecure Data Transmission | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Regular expression injection | CWE-400, CWE-730 | OWASP-API:API4:2023 |
+| SOQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| SOSL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Unverified Password Change | CWE-620 | OWASP:A07:2025 |
+| Unsafe SOQL Concatenation | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Unsafe SOSL Concatenation | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| XML Injection | CWE-91 | OWASP:A05:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-and-asp.net-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-and-asp.net-rules.md
index 45ebea0e6ea8..9f4bd12a1c27 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-and-asp.net-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-and-asp.net-rules.md
@@ -8,42 +8,41 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ----------------------------------------------------------------- | ---------------- | ---------------------- | ----------- |
-| Anti-forgery token validation disabled | CWE-352 | Sans Top 25, OWASP:A01 | Yes |
-| Debug Features Enabled | CWE-215 | None | Yes |
-| Usage of BinaryFormatter | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Cleartext Storage of Sensitive Information in a Cookie | CWE-315 | OWASP:A05 | Yes |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A03 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Insecure Data Transmission | CWE-319 | OWASP:A02 | Yes |
-| LDAP Injection | CWE-90 | OWASP:A03 | Yes |
-| Log Forging | CWE-117 | OWASP:A09 | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Exposure of Private Personal Information to an Unauthorized Actor | CWE-359 | OWASP:A01 | Yes |
-| Regular expression injection | CWE-400, CWE-730 | None | Yes |
-| Request Validation Disabled | CWE-554 | None | Yes |
-| Information Exposure | CWE-200 | OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| XAML Injection | CWE-611 | OWASP:A05 | Yes |
-| XML Injection | CWE-91 | OWASP:A03 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
-| Arbitrary File Write via Archive Extraction (Zip Slip) | CWE-22 | Sans Top 25, OWASP:A01 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ----------------------------------------------------------------- | ---------------- | --------------------------------------------------------- |
+| Anti-forgery token validation disabled | CWE-352 | CWE Top 25, OWASP:A01:2025 |
+| Debug Features Enabled | CWE-215 | OWASP:A10:2025 |
+| Usage of BinaryFormatter | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Cleartext Storage of Sensitive Information in a Cookie | CWE-315 | OWASP:A02:2025 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Insecure Data Transmission | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| LDAP Injection | CWE-90 | OWASP:A05:2025 |
+| Log Forging | CWE-117 | OWASP:A09:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Exposure of Private Personal Information to an Unauthorized Actor | CWE-359 | OWASP:A01:2025 |
+| Regular expression injection | CWE-400, CWE-730 | OWASP-API:API4:2023 |
+| Request Validation Disabled | CWE-554 | None |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| XAML Injection | CWE-611 | OWASP:A02:2025 |
+| XML Injection | CWE-91 | OWASP:A05:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
+| Arbitrary File Write via Archive Extraction (Zip Slip) | CWE-22 | CWE Top 25, OWASP:A01:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-c++-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-c++-rules.md
index 97889fdfffde..e92179529ce4 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-c++-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-c++-rules.md
@@ -8,40 +8,39 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Memory Allocation Of String Length | CWE-170 | None | Yes |
-| Insecure Anonymous LDAP Binding | CWE-287 | Sans Top 25, OWASP:A07 | Yes |
-| Buffer Overflow | CWE-122 | None | Yes |
-| Division By Zero | CWE-369 | None | Yes |
-| Missing Release of File Descriptor or Handle after Effective Lifetime | CWE-775 | None | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Dereference of a NULL Pointer | CWE-476 | Sans Top 25 | Yes |
-| Double Free | CWE-415 | None | Yes |
-| Use of Externally-Controlled Format String | CWE-134 | None | Yes |
-| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A02 | Yes |
-| Improper Null Termination | CWE-170 | None | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Integer Overflow | CWE-190 | Sans Top 25 | Yes |
-| LDAP Injection | CWE-90 | OWASP:A03 | Yes |
-| Missing Release of Memory after Effective Lifetime | CWE-401 | None | Yes |
-| An optimizing compiler may remove memset non-zero leaving data in memory | CWE-1330 | None | Yes |
-| Potential Negative Number Used as Index | CWE-125, CWE-787 | Sans Top 25 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Exposure of Private Personal Information to an Unauthorized Actor | CWE-359 | OWASP:A01 | Yes |
-| Size Used as Index | CWE-125, CWE-787 | Sans Top 25 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Potential buffer overflow from usage of unsafe function | CWE-122 | None | Yes |
-| Use of Expired File Descriptor | CWE-910 | None | Yes |
-| Use After Free | CWE-416 | Sans Top 25 | Yes |
-| User Controlled Pointer | CWE-1285 | None | Yes |
-| Authentication Bypass by Spoofing | CWE-290 | OWASP:A07 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------------------ | ---------------- | ----------------------------------------------- |
+| Memory Allocation Of String Length | CWE-170 | None |
+| Insecure Anonymous LDAP Binding | CWE-287 | OWASP:A07:2025 |
+| Buffer Overflow | CWE-122 | CWE Top 25 |
+| Division By Zero | CWE-369 | OWASP:A10:2025 |
+| Missing Release of File Descriptor or Handle after Effective Lifetime | CWE-775 | None |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Dereference of a NULL Pointer | CWE-476 | CWE Top 25, OWASP:A10:2025 |
+| Double Free | CWE-415 | None |
+| Use of Externally-Controlled Format String | CWE-134 | None |
+| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
+| Improper Null Termination | CWE-170 | None |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Integer Overflow | CWE-190 | None |
+| LDAP Injection | CWE-90 | OWASP:A05:2025 |
+| Missing Release of Memory after Effective Lifetime | CWE-401 | None |
+| An optimizing compiler may remove memset non-zero leaving data in memory | CWE-1330 | None |
+| Potential Negative Number Used as Index | CWE-125, CWE-787 | CWE Top 25 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Exposure of Private Personal Information to an Unauthorized Actor | CWE-359 | OWASP:A01:2025 |
+| Size Used as Index | CWE-125, CWE-787 | CWE Top 25 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Potential buffer overflow from usage of unsafe function | CWE-122 | CWE Top 25 |
+| Use of Expired File Descriptor | CWE-910 | None |
+| Use After Free | CWE-416 | CWE Top 25 |
+| User Controlled Pointer | CWE-1285 | None |
+| Authentication Bypass by Spoofing | CWE-290 | OWASP:A07:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md
index 8d87caaaaff9..ea55ba9ea6ec 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md
@@ -5,31 +5,26 @@ nav_context: agnostic
# COBOL rules
-{% hint style="info" %}
-Code analysis support for COBOL is in Early Access and is available only with Enterprise plans. To enable the feature, see [Snyk Preview](https://app.gitbook.com/s/IgtgtomLQ2TUgSKOMSAm/snyk-hierarchy/snyk-preview).
-{% endhint %}
-
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| --------------------------------------------------- | ---------------- | --------------------------- | ----------- |
-| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A02:2021 | Yes |
-| Use of Hardcoded Cryptographic Initialization Value | CWE-321 | OWASP:A02:2021 | Yes |
-| No Dynamic SQL Clauses | CWE-89 | Sans Top 25, OWASP:A03:2021 | Yes |
-| Inadequate Encryption Strength - Small Key Size | CWE-326 | OWASP:A02:2021 | Yes |
-| Weak Cryptographic Primitive | CWE-327 | OWASP:A02:2021 | Yes |
-| Clear Text Logging | CWE-321 | OWASP:A02:2021 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A02:2021 | Yes |
-| Injection on Accept | CWE-20 | SANS Top 25 | Yes |
-| Insecure Debug Features Enabled | CWE-489, CWE-215 | OWASP:A05:2021 | Yes |
-| Insecure Data Transmission | CWE-319 | OWASP:A02:2021 | Yes |
-| SQL SELECT statement without WHERE clause | CWE-668 | OWASP:A01:2021 | Yes |
-| Multiple CICS HANDLE ABEND Declarations | CWE-755 | OWASP:A05:2021 | Yes |
-| Missing SQL Communication Area (SQLCA) | CWE-391 | OWASP:A05:2021 | Yes |
-| Ignored Error Condition | CWE-391 | OWASP:A05:2021 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02:2021 | Yes |
+| Rule Name | CWEs | Security Categories |
+| --------------------------------------------------- | ---------------- | ---------------------------------------------------------------------- |
+| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
+| Use of Hardcoded Cryptographic Initialization Value | CWE-321 | OWASP:A04:2025 |
+| No Dynamic SQL Clauses | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Inadequate Encryption Strength - Small Key Size | CWE-326 | OWASP:A04:2025 |
+| Weak Cryptographic Primitive | CWE-327 | OWASP:A04:2025 |
+| Clear Text Logging | CWE-321 | OWASP:A04:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Injection on Accept | CWE-20 | CWE Top 25, OWASP:A05:2025, OWASP-API:API10:2023, OWASP-Mobile:M4:2024 |
+| Insecure Debug Features Enabled | CWE-489, CWE-215 | OWASP:A02:2025, OWASP:A10:2025 |
+| Insecure Data Transmission | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| SQL SELECT statement without WHERE clause | CWE-668 | OWASP:A01:2025 |
+| Multiple CICS HANDLE ABEND Declarations | CWE-755 | OWASP:A10:2025 |
+| Missing SQL Communication Area (SQLCA) | CWE-391 | OWASP:A10:2025 |
+| Ignored Error Condition | CWE-391 | OWASP:A10:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/dart-and-flutter-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/dart-and-flutter-rules.md
index 19684c3e5a99..9a830101c78a 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/dart-and-flutter-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/dart-and-flutter-rules.md
@@ -12,24 +12,23 @@ Code analysis support for Dart is in Early Access and is available only with Ent
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s)**: The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/) (2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Clear Text Logging | CWE-200, CWE-312 | OWASP:A01, OWASP:A04 | Yes |
-| Cleartext Transmission - HTTP Instead of HTTPS | CWE-319 | OWASP:A02 | Yes |
-| Code Injection | CWE-94 | OWASP:A03 | Yes |
-| File Access Enabled | CWE-200 | OWASP:A01, OWASP:A04 | Yes |
-| Improper Certificate Validation - SSL Verification Bypass | CWE-295 | OWASP:A07 | Yes |
-| Insecure JWT Verification Method | CWE-347 | OWASP:A02 | Yes |
-| Insecure Storage Shared Keystore | CWE-922 | | Yes |
-| Insecure Token Storage | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values - Secrets | CWE-330 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | ---------------------------------------------------------------- |
+| Clear Text Logging | CWE-200, CWE-312 | CWE Top 25, OWASP:A01:2025, OWASP:A06:2025, OWASP-API:API10:2023 |
+| Cleartext Transmission - HTTP Instead of HTTPS | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| File Access Enabled | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Improper Certificate Validation - SSL Verification Bypass | CWE-295 | OWASP:A07:2025 |
+| Insecure JWT Verification Method | CWE-347 | OWASP:A04:2025 |
+| Insecure Storage Shared Keystore | CWE-922 | OWASP:A01:2025 |
+| Insecure Token Storage | CWE-798 | OWASP:A07:2025 |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values - Secrets | CWE-330 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/go-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/go-rules.md
index 9050d2f672bc..fbd8856bff55 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/go-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/go-rules.md
@@ -8,31 +8,30 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| -------------------------------------------------------------- | ---------------- | ---------------------- | ----------- |
-| Clear Text Logging | CWE-200, CWE-312 | OWASP:A01, OWASP:A04 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Improper Access Control: Email Content Injection | CWE-284 | OWASP:A01 | Yes |
-| Generation of Error Message Containing Sensitive Information | CWE-209 | OWASP:A04 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Insecure TLS Configuration | CWE-327 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Improper Neutralization of Directives in Statically Saved Code | CWE-96 | OWASP:A03 | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
+| Rule Name | CWEs | Security Categories |
+| -------------------------------------------------------------- | ---------------- | ---------------------------------------------------------------- |
+| Clear Text Logging | CWE-200, CWE-312 | CWE Top 25, OWASP:A01:2025, OWASP:A06:2025, OWASP-API:API10:2023 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Improper Access Control: Email Content Injection | CWE-284 | CWE Top 25, OWASP:A01:2025 |
+| Generation of Error Message Containing Sensitive Information | CWE-209 | OWASP:A10:2025, OWASP-API:API8:2023 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Insecure TLS Configuration | CWE-327 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Improper Neutralization of Directives in Statically Saved Code | CWE-96 | OWASP:A05:2025 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/groovy-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/groovy-rules.md
index 90b14a0c4bb9..a8fe207495e1 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/groovy-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/groovy-rules.md
@@ -11,25 +11,24 @@ Code analysis support for Groovy is in Early Access and is available only with E
Each rule includes the following information.
-* **Rule name**: The Snyk name of the rule.
-* **CWE(s)**: The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security categories**: The [OWASP Top 10](https://owasp.org/Top10/) (2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **Rule Name**: The Snyk name of the rule.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule name | CWE(s) | Security categories | Autofixable |
-| ----------------------------------------------------------- | ---------------- | ---------------------- | ----------- |
-| Code Injection | CWE-94 | OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | OWASP:A08 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Use of Hardcoded, Security-relevant Constants | CWE-547 | OWASP:A05 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| Inadequate Padding for AES encryption | CWE-326 | OWASP:A02 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ----------------------------------------------------------- | ---------------- | ----------------------------------------------- |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Use of Hardcoded, Security-relevant Constants | CWE-547 | OWASP:A02:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| Inadequate Padding for AES encryption | CWE-326 | OWASP:A04:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md
index c37a821dda60..c74a82b3be5a 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md
@@ -8,73 +8,72 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Android World Writeable/Readable File Permission Found | CWE-732 | None | Yes |
-| Use of Potentially Dangerous Function | CWE-676 | None | Yes |
-| Cleartext Storage of Sensitive Information in a Cookie | CWE-315 | OWASP:A05 | Yes |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Cross-Site Request Forgery (CSRF) | CWE-352 | Sans Top 25, OWASP:A01 | Yes |
-| Information Exposure | CWE-200 | OWASP:A01 | Yes |
-| Cleartext Transmission of Sensitive Information | CWE-319 | OWASP:A02 | Yes |
-| Indirect Command Injection via User Controlled Environment | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| External Control of System or Configuration Setting | CWE-15 | OWASP:A05 | Yes |
-| Process Control | CWE-114 | None | Yes |
-| File Access Enabled | CWE-200 | OWASP:A01 | Yes |
-| Android Fragment Injection | CWE-470 | OWASP:A03 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A03 | Yes |
-| Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A03 | Yes |
-| Inadequate Padding for AES encryption | CWE-326 | OWASP:A02 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Android Intent Forwarding | CWE-940 | OWASP:A07 | Yes |
-| Improper Validation of Certificate with Host Mismatch | CWE-297 | OWASP:A07 | Yes |
-| JavaScript Enabled | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Java Naming and Directory Interface (JNDI) Injection | CWE-074 | None | Yes |
-| JWT Signature Verification Bypass | CWE-347 | OWASP:A02 | Yes |
-| Improper Authentication | CWE-287 | Sans Top 25, OWASP:A07 | Yes |
-| LDAP Injection | CWE-90 | OWASP:A03 | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| The cipher text is equal to the provided input plain text | CWE-311 | OWASP:A04 | Yes |
-| NoSQL Injection | CWE-943 | None | Yes |
-| Use of Sticky broadcasts | CWE-265 | None | Yes |
-| Use of Hardcoded, Security-relevant Constants | CWE-547 | OWASP:A05 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Privacy Leak | CWE-532 | OWASP:A09 | Yes |
-| Unsafe Reflection | CWE-470 | OWASP:A03 | Yes |
-| Regular expression injection | CWE-400, CWE-730 | None | Yes |
-| Unprotected Storage of Credentials | CWE-256 | OWASP:A04 | Yes |
-| Incorrect Permission Assignment | CWE-732 | None | Yes |
-| Server Information Exposure | CWE-209 | OWASP:A04 | Yes |
-| Improper Handling of Insufficient Permissions or Privileges | CWE-280 | OWASP:A04 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Unrestricted Android Broadcast | CWE-862 | Sans Top 25, OWASP:A01 | Yes |
-| Spring Cross-Site Request Forgery (CSRF) | CWE-352 | Sans Top 25, OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Code Execution via Third Party Package Context | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Code Execution via Third Party Package Installation | CWE-940 | OWASP:A07 | Yes |
-| Observable Timing Discrepancy (Timing Attack) | CWE-208 | None | Yes |
-| Origin Validation Error | CWE-942, CWE-346 | OWASP:A05, OWASP:A07 | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
-| Cryptographic Issues | CWE-310 | OWASP:A02 | Yes |
-| Trust Boundary Violation | CWE-501 | OWASP:A04 | Yes |
-| Unauthorized File Access | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Android Uri Permission Manipulation | CWE-266 | OWASP:A04 | Yes |
-| Use of Externally-Controlled Format String | CWE-134 | None | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Insufficient Session Expiration | CWE-613 | OWASP:A07 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | --------------------------------------------------------- |
+| Android World Writeable/Readable File Permission Found | CWE-732 | OWASP:A01:2025 |
+| Use of Potentially Dangerous Function | CWE-676 | OWASP:A06:2025 |
+| Cleartext Storage of Sensitive Information in a Cookie | CWE-315 | OWASP:A02:2025 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Cross-Site Request Forgery (CSRF) | CWE-352 | CWE Top 25, OWASP:A01:2025 |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Cleartext Transmission of Sensitive Information | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Indirect Command Injection via User Controlled Environment | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| External Control of System or Configuration Setting | CWE-15 | OWASP:A02:2025 |
+| Process Control | CWE-114 | OWASP:A05:2025 |
+| File Access Enabled | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Android Fragment Injection | CWE-470 | OWASP:A05:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
+| Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
+| Inadequate Padding for AES encryption | CWE-326 | OWASP:A04:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Android Intent Forwarding | CWE-940 | OWASP:A07:2025 |
+| Improper Validation of Certificate with Host Mismatch | CWE-297 | OWASP:A07:2025 |
+| JavaScript Enabled | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Java Naming and Directory Interface (JNDI) Injection | CWE-074 | OWASP:A05:2025 |
+| JWT Signature Verification Bypass | CWE-347 | OWASP:A04:2025 |
+| Improper Authentication | CWE-287 | OWASP:A07:2025 |
+| LDAP Injection | CWE-90 | OWASP:A05:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| The cipher text is equal to the provided input plain text | CWE-311 | OWASP:A06:2025 |
+| NoSQL Injection | CWE-943 | None |
+| Use of Sticky broadcasts | CWE-265 | None |
+| Use of Hardcoded, Security-relevant Constants | CWE-547 | OWASP:A02:2025 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Privacy Leak | CWE-532 | OWASP:A09:2025 |
+| Unsafe Reflection | CWE-470 | OWASP:A05:2025 |
+| Regular expression injection | CWE-400, CWE-730 | OWASP-API:API4:2023 |
+| Unprotected Storage of Credentials | CWE-256 | OWASP:A06:2025 |
+| Incorrect Permission Assignment | CWE-732 | OWASP:A01:2025 |
+| Server Information Exposure | CWE-209 | OWASP:A10:2025, OWASP-API:API8:2023 |
+| Improper Handling of Insufficient Permissions or Privileges | CWE-280 | OWASP:A10:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Unrestricted Android Broadcast | CWE-862 | CWE Top 25, OWASP:A01:2025 |
+| Spring Cross-Site Request Forgery (CSRF) | CWE-352 | CWE Top 25, OWASP:A01:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Code Execution via Third Party Package Context | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Code Execution via Third Party Package Installation | CWE-940 | OWASP:A07:2025 |
+| Observable Timing Discrepancy (Timing Attack) | CWE-208 | None |
+| Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
+| Cryptographic Issues | CWE-310 | None |
+| Trust Boundary Violation | CWE-501 | OWASP:A06:2025 |
+| Unauthorized File Access | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Android Uri Permission Manipulation | CWE-266 | OWASP:A06:2025 |
+| Use of Externally-Controlled Format String | CWE-134 | None |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Insufficient Session Expiration | CWE-613 | OWASP:A07:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/javascript-and-typescript-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/javascript-and-typescript-rules.md
index c0e335121530..357cb9c8f7c0 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/javascript-and-typescript-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/javascript-and-typescript-rules.md
@@ -8,62 +8,61 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ----------------------------------------------------------------------------------------------------------------- | ----------------------- | ---------------------- | ----------- |
-| Disabling Strict Contextual escaping (SCE) could provide additional attack surface for Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Clear Text Sensitive Storage | CWE-200, CWE-312 | OWASP:A01, OWASP:A04 | Yes |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Information Exposure | CWE-200 | OWASP:A01 | Yes |
-| Electron Disable Security Warnings | CWE-16 | OWASP:A05 | Yes |
-| Electron Insecure Web Preferences | CWE-16 | OWASP:A05 | Yes |
-| Electron Load Insecure Content | CWE-16 | OWASP:A05 | Yes |
-| Use of Externally-Controlled Format String | CWE-134 | None | Yes |
-| GraphQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Improper Type Validation | CWE-1287 | None | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Cleartext Transmission of Sensitive Information | CWE-319 | OWASP:A02 | Yes |
-| Improper Code Sanitization | CWE-94, CWE-79, CWE-116 | Sans Top 25, OWASP:A03 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Insecure TLS Configuration | CWE-327 | OWASP:A02 | Yes |
-| Insufficient postMessage Validation | CWE-20 | Sans Top 25, OWASP:A03 | Yes |
-| Introspection Enabled | CWE-200 | OWASP:A01 | Yes |
-| Insecure JWT Verification Method | CWE-347 | OWASP:A02 | Yes |
-| JWT Signature Verification Method Disabled | CWE-347 | OWASP:A02 | Yes |
-| JWT 'none' Algorithm Supported | CWE-347 | OWASP:A02 | Yes |
-| Denial of Service (DoS) through Nested GraphQL Queries | CWE-400 | None | Yes |
-| Unchecked Input for Loop Condition | CWE-400, CWE-606 | None | Yes |
-| Observable Timing Discrepancy (Timing Attack) | CWE-208 | None | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Allocation of Resources Without Limits or Throttling | CWE-770 | None | Yes |
-| NoSQL Injection | CWE-943 | None | Yes |
-| Buffer Over-read | CWE-126 | None | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Prototype Pollution | CWE-1321 | None | Yes |
-| Use dangerouslySetInnerHTML to Explicitly Handle XSS Risks | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Weak Password Recovery Mechanism for Forgotten Password | CWE-640 | OWASP:A07 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Improper Neutralization of Directives in Statically Saved Code | CWE-96 | OWASP:A03 | Yes |
-| Origin Validation Error | CWE-942, CWE-346 | OWASP:A05, OWASP:A07 | Yes |
-| Permissive Cross-domain Policy | CWE-942 | OWASP:A05 | Yes |
-| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A04 | Yes |
-| Cryptographic Issues | CWE-310 | OWASP:A02 | Yes |
-| Unsafe JQuery Plugin | CWE-79, CWE-116 | Sans Top 25, OWASP:A03 | Yes |
-| Cross-Site Request Forgery (CSRF) | CWE-352 | Sans Top 25, OWASP:A01 | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
-| Arbitrary File Write via Archive Extraction (Zip Slip) | CWE-22 | Sans Top 25, OWASP:A01 | Yes |
-| Regular Expression Denial of Service (ReDoS) | CWE-400 | None | Yes |
+| Rule Name | CWEs | Security Categories |
+| ----------------------------------------------------------------------------------------------------------------- | ----------------------- | ---------------------------------------------------------------------- |
+| Disabling Strict Contextual escaping (SCE) could provide additional attack surface for Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Clear Text Sensitive Storage | CWE-200, CWE-312 | CWE Top 25, OWASP:A01:2025, OWASP:A06:2025, OWASP-API:API10:2023 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Electron Disable Security Warnings | CWE-16 | OWASP:A02:2025, OWASP-API:API8:2023 |
+| Electron Insecure Web Preferences | CWE-16 | OWASP:A02:2025, OWASP-API:API8:2023 |
+| Electron Load Insecure Content | CWE-16 | OWASP:A02:2025, OWASP-API:API8:2023 |
+| Use of Externally-Controlled Format String | CWE-134 | None |
+| GraphQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Improper Type Validation | CWE-1287 | None |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Cleartext Transmission of Sensitive Information | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Improper Code Sanitization | CWE-94, CWE-79, CWE-116 | CWE Top 25, OWASP:A05:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Insecure TLS Configuration | CWE-327 | OWASP:A04:2025 |
+| Insufficient postMessage Validation | CWE-20 | CWE Top 25, OWASP:A05:2025, OWASP-API:API10:2023, OWASP-Mobile:M4:2024 |
+| Introspection Enabled | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Insecure JWT Verification Method | CWE-347 | OWASP:A04:2025 |
+| JWT Signature Verification Method Disabled | CWE-347 | OWASP:A04:2025 |
+| JWT 'none' Algorithm Supported | CWE-347 | OWASP:A04:2025 |
+| Denial of Service (DoS) through Nested GraphQL Queries | CWE-400 | OWASP-API:API4:2023 |
+| Unchecked Input for Loop Condition | CWE-400, CWE-606 | OWASP-API:API4:2023 |
+| Observable Timing Discrepancy (Timing Attack) | CWE-208 | None |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Allocation of Resources Without Limits or Throttling | CWE-770 | CWE Top 25, OWASP-API:API4:2023 |
+| NoSQL Injection | CWE-943 | None |
+| Buffer Over-read | CWE-126 | None |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Prototype Pollution | CWE-1321 | None |
+| Use dangerouslySetInnerHTML to Explicitly Handle XSS Risks | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Weak Password Recovery Mechanism for Forgotten Password | CWE-640 | OWASP:A07:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Improper Neutralization of Directives in Statically Saved Code | CWE-96 | OWASP:A05:2025 |
+| Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
+| Permissive Cross-domain Policy | CWE-942 | OWASP:A02:2025, OWASP-API:API8:2023 |
+| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A06:2025 |
+| Cryptographic Issues | CWE-310 | None |
+| Unsafe JQuery Plugin | CWE-79, CWE-116 | CWE Top 25, OWASP:A05:2025 |
+| Cross-Site Request Forgery (CSRF) | CWE-352 | CWE Top 25, OWASP:A01:2025 |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
+| Arbitrary File Write via Archive Extraction (Zip Slip) | CWE-22 | CWE Top 25, OWASP:A01:2025 |
+| Regular Expression Denial of Service (ReDoS) | CWE-400 | OWASP-API:API4:2023 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/kotlin-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/kotlin-rules.md
index ff9dc70a3408..7e04819a0490 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/kotlin-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/kotlin-rules.md
@@ -8,68 +8,67 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Android World Writeable/Readable File Permission Found | CWE-732 | None | Yes |
-| Use of Potentially Dangerous Function | CWE-676 | None | Yes |
-| Cleartext Storage of Sensitive Information in a Cookie | CWE-315 | OWASP:A05 | Yes |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Cross-Site Request Forgery (CSRF) | CWE-352 | Sans Top 25, OWASP:A01 | Yes |
-| Information Exposure | CWE-200 | OWASP:A01 | Yes |
-| Cleartext Transmission of Sensitive Information | CWE-319 | OWASP:A02 | Yes |
-| Indirect Command Injection via User Controlled Environment | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| External Control of System or Configuration Setting | CWE-15 | OWASP:A05 | Yes |
-| Process Control | CWE-114 | None | Yes |
-| File Access Enabled | CWE-200 | OWASP:A01 | Yes |
-| Android Fragment Injection | CWE-470 | OWASP:A03 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A03 | Yes |
-| Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A03 | Yes |
-| Inadequate Padding for AES encryption | CWE-326 | OWASP:A02 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Android Intent Forwarding | CWE-940 | OWASP:A07 | Yes |
-| Improper Validation of Certificate with Host Mismatch | CWE-297 | OWASP:A07 | Yes |
-| JavaScript Enabled | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Java Naming and Directory Interface (JNDI) Injection | CWE-074 | None | Yes |
-| Improper Authentication | CWE-287 | Sans Top 25, OWASP:A07 | Yes |
-| LDAP Injection | CWE-90 | OWASP:A03 | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| The cipher text is equal to the provided input plain text | CWE-311 | OWASP:A04 | Yes |
-| Use of Sticky broadcasts | CWE-265 | None | Yes |
-| Use of Hardcoded, Security-relevant Constants | CWE-547 | OWASP:A05 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Regular expression injection | CWE-400, CWE-730 | None | Yes |
-| Unprotected Storage of Credentials | CWE-256 | OWASP:A04 | Yes |
-| Incorrect Permission Assignment | CWE-732 | None | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
-| Server Information Exposure | CWE-209 | OWASP:A04 | Yes |
-| Improper Handling of Insufficient Permissions or Privileges | CWE-280 | OWASP:A04 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Unrestricted Android Broadcast | CWE-862 | Sans Top 25, OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Code Execution via Third Party Package Context | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Code Execution via Third Party Package Installation | CWE-940 | OWASP:A07 | Yes |
-| Observable Timing Discrepancy (Timing Attack) | CWE-208 | None | Yes |
-| Origin Validation Error | CWE-942, CWE-346 | OWASP:A05, OWASP:A07 | Yes |
-| Cryptographic Issues | CWE-310 | OWASP:A02 | Yes |
-| Trust Boundary Violation | CWE-501 | OWASP:A04 | Yes |
-| Unauthorized File Access | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Android Uri Permission Manipulation | CWE-266 | OWASP:A04 | Yes |
-| Use of Externally-Controlled Format String | CWE-134 | None | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Insufficient Session Expiration | CWE-613 | OWASP:A07 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | --------------------------------------------------------- |
+| Android World Writeable/Readable File Permission Found | CWE-732 | OWASP:A01:2025 |
+| Use of Potentially Dangerous Function | CWE-676 | OWASP:A06:2025 |
+| Cleartext Storage of Sensitive Information in a Cookie | CWE-315 | OWASP:A02:2025 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Cross-Site Request Forgery (CSRF) | CWE-352 | CWE Top 25, OWASP:A01:2025 |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Cleartext Transmission of Sensitive Information | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Indirect Command Injection via User Controlled Environment | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| External Control of System or Configuration Setting | CWE-15 | OWASP:A02:2025 |
+| Process Control | CWE-114 | OWASP:A05:2025 |
+| File Access Enabled | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Android Fragment Injection | CWE-470 | OWASP:A05:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
+| Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
+| Inadequate Padding for AES encryption | CWE-326 | OWASP:A04:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Android Intent Forwarding | CWE-940 | OWASP:A07:2025 |
+| Improper Validation of Certificate with Host Mismatch | CWE-297 | OWASP:A07:2025 |
+| JavaScript Enabled | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Java Naming and Directory Interface (JNDI) Injection | CWE-074 | OWASP:A05:2025 |
+| Improper Authentication | CWE-287 | OWASP:A07:2025 |
+| LDAP Injection | CWE-90 | OWASP:A05:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| The cipher text is equal to the provided input plain text | CWE-311 | OWASP:A06:2025 |
+| Use of Sticky broadcasts | CWE-265 | None |
+| Use of Hardcoded, Security-relevant Constants | CWE-547 | OWASP:A02:2025 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Regular expression injection | CWE-400, CWE-730 | OWASP-API:API4:2023 |
+| Unprotected Storage of Credentials | CWE-256 | OWASP:A06:2025 |
+| Incorrect Permission Assignment | CWE-732 | OWASP:A01:2025 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
+| Server Information Exposure | CWE-209 | OWASP:A10:2025, OWASP-API:API8:2023 |
+| Improper Handling of Insufficient Permissions or Privileges | CWE-280 | OWASP:A10:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Unrestricted Android Broadcast | CWE-862 | CWE Top 25, OWASP:A01:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Code Execution via Third Party Package Context | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Code Execution via Third Party Package Installation | CWE-940 | OWASP:A07:2025 |
+| Observable Timing Discrepancy (Timing Attack) | CWE-208 | None |
+| Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
+| Cryptographic Issues | CWE-310 | None |
+| Trust Boundary Violation | CWE-501 | OWASP:A06:2025 |
+| Unauthorized File Access | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Android Uri Permission Manipulation | CWE-266 | OWASP:A06:2025 |
+| Use of Externally-Controlled Format String | CWE-134 | None |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Insufficient Session Expiration | CWE-613 | OWASP:A07:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/objective-c-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/objective-c-rules.md
index 7c6b175706c4..aec942b78730 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/objective-c-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/objective-c-rules.md
@@ -12,27 +12,26 @@ Code analysis support for Objective-C is in Early Access and is available only w
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s)**: The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/) (2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Clear Text Logging | CWE-200, CWE-312 | OWASP:A01, OWASP:A04 | Yes |
-| Client-Side Request Forgery (CSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Code Injection | CWE-94 | OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Device Authentication Bypass | CWE-287 | OWASP:A07 | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Information Exposure | CWE-200 | OWASP:A01, OWASP:A04 | Yes |
-| Insecure Data Storage | CWE-922 | | Yes |
-| Memory Corruption | CWE-822 | OWASP:A03 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | ---------------------------------------------------------------- |
+| Clear Text Logging | CWE-200, CWE-312 | CWE Top 25, OWASP:A01:2025, OWASP:A06:2025, OWASP-API:API10:2023 |
+| Client-Side Request Forgery (CSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Device Authentication Bypass | CWE-287 | OWASP:A07:2025 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Insecure Data Storage | CWE-922 | OWASP:A01:2025 |
+| Memory Corruption | CWE-822 | None |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/php-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/php-rules.md
index 66776e0924db..58f152f35912 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/php-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/php-rules.md
@@ -8,37 +8,36 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Improper Access Control: Email Content Injection | CWE-284 | OWASP:A01 | Yes |
-| File Inclusion | CWE-98 | OWASP:A03 | Yes |
-| Use of Hardcoded Credentials | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Inadequate Padding for Public Key Encryption | CWE-326 | OWASP:A02 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Allocation of Resources Without Limits or Throttling | CWE-770 | None | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Information Exposure | CWE-200 | OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Origin Validation Error | CWE-942, CWE-346 | OWASP:A05, OWASP:A07 | Yes |
-| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A04 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| Arbitrary File Write via Archive Extraction (Zip Slip) | CWE-22 | Sans Top 25, OWASP:A01 | Yes |
-| Regular Expression Denial of Service (ReDoS) | CWE-400 | None | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | --------------------------------------------------- |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Improper Access Control: Email Content Injection | CWE-284 | CWE Top 25, OWASP:A01:2025 |
+| File Inclusion | CWE-98 | OWASP:A05:2025 |
+| Use of Hardcoded Credentials | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Inadequate Padding for Public Key Encryption | CWE-326 | OWASP:A04:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Allocation of Resources Without Limits or Throttling | CWE-770 | CWE Top 25, OWASP-API:API4:2023 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
+| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A06:2025 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| Arbitrary File Write via Archive Extraction (Zip Slip) | CWE-22 | CWE Top 25, OWASP:A01:2025 |
+| Regular Expression Denial of Service (ReDoS) | CWE-400 | OWASP-API:API4:2023 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md
index 8023c7eeadad..7ac6571207b9 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md
@@ -8,52 +8,51 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| -------------------------------------------------------------------------- | ---------------- | ---------------------- | ----------- |
-| Authentication over HTTP | CWE-319 | OWASP:A02 | Yes |
-| Binding to all network interfaces may open service to unintended traffic | CWE-284 | OWASP:A01 | Yes |
-| Broken User Authentication | CWE-287 | Sans Top 25, OWASP:A07 | Yes |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Cross-Site Request Forgery (CSRF) | CWE-352 | Sans Top 25, OWASP:A01 | Yes |
-| Password Requirements Not Enforced in Django Application | CWE-521 | OWASP:A07 | Yes |
-| Use of Hardcoded Cryptographic Initialization Value | CWE-329 | OWASP:A02 | Yes |
-| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A02 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Insecure default value | CWE-453 | None | Yes |
-| Insecure File Permissions | CWE-732 | None | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Insecure Temporary File | CWE-377 | OWASP:A01 | Yes |
-| Insecure Xml Parser | CWE-611 | OWASP:A05 | Yes |
-| Jinja auto-escape is set to false. | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| LDAP Injection | CWE-90 | OWASP:A03 | Yes |
-| Improper Handling of Insufficient Permissions or Privileges | CWE-280 | OWASP:A04 | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| NoSQL Injection | CWE-943 | None | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Debug Mode Enabled | CWE-489 | None | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
-| Server Information Exposure | CWE-209 | OWASP:A04 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Improper Neutralization of Directives in Statically Saved Code | CWE-96 | OWASP:A03 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Arbitrary File Write via Archive Extraction (Tar Slip) | CWE-22 | Sans Top 25, OWASP:A01 | Yes |
-| Origin Validation Error | CWE-942, CWE-346 | OWASP:A05, OWASP:A07 | Yes |
-| Cryptographic Issues | CWE-310 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Python 2 source code | CWE-1104 | OWASP:A06 | Yes |
-| Selection of Less-Secure Algorithm During Negotiation (SSL instead of TLS) | CWE-757 | OWASP:A02 | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
-| Regular Expression Denial of Service (ReDoS) | CWE-400 | None | Yes |
+| Rule Name | CWEs | Security Categories |
+| -------------------------------------------------------------------------- | ---------------- | --------------------------------------------------------- |
+| Authentication over HTTP | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Binding to all network interfaces may open service to unintended traffic | CWE-284 | CWE Top 25, OWASP:A01:2025 |
+| Broken User Authentication | CWE-287 | OWASP:A07:2025 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Cross-Site Request Forgery (CSRF) | CWE-352 | CWE Top 25, OWASP:A01:2025 |
+| Password Requirements Not Enforced in Django Application | CWE-521 | OWASP:A07:2025 |
+| Use of Hardcoded Cryptographic Initialization Value | CWE-329 | OWASP:A04:2025 |
+| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Insecure default value | CWE-453 | None |
+| Insecure File Permissions | CWE-732 | OWASP:A01:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Insecure Temporary File | CWE-377 | OWASP:A01:2025 |
+| Insecure Xml Parser | CWE-611 | OWASP:A02:2025 |
+| Jinja auto-escape is set to false. | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| LDAP Injection | CWE-90 | OWASP:A05:2025 |
+| Improper Handling of Insufficient Permissions or Privileges | CWE-280 | OWASP:A10:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| NoSQL Injection | CWE-943 | None |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Debug Mode Enabled | CWE-489 | OWASP:A02:2025 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
+| Server Information Exposure | CWE-209 | OWASP:A10:2025, OWASP-API:API8:2023 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Improper Neutralization of Directives in Statically Saved Code | CWE-96 | OWASP:A05:2025 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Arbitrary File Write via Archive Extraction (Tar Slip) | CWE-22 | CWE Top 25, OWASP:A01:2025 |
+| Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
+| Cryptographic Issues | CWE-310 | None |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Python 2 source code | CWE-1104 | OWASP:A03:2025 |
+| Selection of Less-Secure Algorithm During Negotiation (SSL instead of TLS) | CWE-757 | OWASP:A04:2025 |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
+| Regular Expression Denial of Service (ReDoS) | CWE-400 | OWASP-API:API4:2023 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md
index 26334f1bb569..7dc58d49d887 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md
@@ -8,41 +8,40 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------------------------ | ----------------------------------------------------------- | ------------------------------------------------------- | ----------- |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Remote Code Execution via Endpoint | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Use of Hardcoded Credentials | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A02 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Sinatra Protection Layers Disabled | CWE-16, CWE-352, CWE-79, CWE-693, CWE-1021, CWE-35, CWE-348 | Sans Top 25, OWASP:A05, OWASP:A03, OWASP:A01, OWASP:A04 | Yes |
-| Insecure Data Transmission | CWE-319 | OWASP:A02 | Yes |
-| Improper Input Validation | CWE-20 | Sans Top 25, OWASP:A03 | Yes |
-| Improperly Controlled Modification of Dynamically-Determined Object Attributes | CWE-915 | OWASP:A08 | Yes |
-| Selection of Less-Secure Algorithm During Negotiation (Force SSL) | CWE-311, CWE-757 | OWASP:A02, OWASP:A04 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Unsafe Reflection | CWE-470 | OWASP:A03 | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
-| Information Exposure | CWE-200 | OWASP:A01 | Yes |
-| Session Manipulation | CWE-285 | OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Improper Neutralization of Directives in Statically Saved Code | CWE-96 | OWASP:A03 | Yes |
-| No Weak Password Requirements | CWE-521 | OWASP:A07 | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Incorrect regular expression for validating values | CWE-1286 | None | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
-| Regular Expression Denial of Service (ReDoS) | CWE-400 | None | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------------------------ | ----------------------------------------------------------- | ----------------------------------------------------------------------------------------------- |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Remote Code Execution via Endpoint | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Use of Hardcoded Credentials | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Sinatra Protection Layers Disabled | CWE-16, CWE-352, CWE-79, CWE-693, CWE-1021, CWE-35, CWE-348 | CWE Top 25, OWASP:A01:2025, OWASP:A02:2025, OWASP:A05:2025, OWASP:A06:2025, OWASP-API:API8:2023 |
+| Insecure Data Transmission | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Improper Input Validation | CWE-20 | CWE Top 25, OWASP:A05:2025, OWASP-API:API10:2023, OWASP-Mobile:M4:2024 |
+| Improperly Controlled Modification of Dynamically-Determined Object Attributes | CWE-915 | OWASP:A08:2025, OWASP-API:API3:2023 |
+| Selection of Less-Secure Algorithm During Negotiation (Force SSL) | CWE-311, CWE-757 | OWASP:A04:2025, OWASP:A06:2025 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Unsafe Reflection | CWE-470 | OWASP:A05:2025 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Session Manipulation | CWE-285 | OWASP:A01:2025, OWASP-API:API1:2023, OWASP-API:API5:2023 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Improper Neutralization of Directives in Statically Saved Code | CWE-96 | OWASP:A05:2025 |
+| No Weak Password Requirements | CWE-521 | OWASP:A07:2025 |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Incorrect regular expression for validating values | CWE-1286 | None |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
+| Regular Expression Denial of Service (ReDoS) | CWE-400 | OWASP-API:API4:2023 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md
index dce4a218ddd5..f1e19bc7bdb3 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md
@@ -12,24 +12,23 @@ Code analysis support for Rust is in Early Access and is available only with Ent
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s)**: The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/) (2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ----------------------------------------------------------- | ---------------- | ---------------------- | ----------- |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Inadequate Padding for Public Key Encryption | CWE-326 | OWASP:A02 | Yes |
-| Insecure File Permissions | CWE-732 | OWASP:A05 | Yes |
-| Observable Timing Discrepancy | CWE-208 | OWASP:A02 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Origin Validation Error | CWE-346, CWE-942 | OWASP:A05 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Use of Hardcoded Passwords | CWE-259, CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ----------------------------------------------------------- | ---------------- | --------------------------------------------------- |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Inadequate Padding for Public Key Encryption | CWE-326 | OWASP:A04:2025 |
+| Insecure File Permissions | CWE-732 | OWASP:A01:2025 |
+| Observable Timing Discrepancy | CWE-208 | None |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Origin Validation Error | CWE-346, CWE-942 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Use of Hardcoded Passwords | CWE-259, CWE-798 | OWASP:A07:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/scala-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/scala-rules.md
index e496769b6877..f9390656e324 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/scala-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/scala-rules.md
@@ -8,56 +8,55 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Use of Potentially Dangerous Function | CWE-676 | None | Yes |
-| Cleartext Storage of Sensitive Information in a Cookie | CWE-315 | OWASP:A05 | Yes |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Cross-Site Request Forgery (CSRF) | CWE-352 | Sans Top 25, OWASP:A01 | Yes |
-| Information Exposure | CWE-200 | OWASP:A01 | Yes |
-| Cleartext Transmission of Sensitive Information | CWE-319 | OWASP:A02 | Yes |
-| Indirect Command Injection via User Controlled Environment | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| External Control of System or Configuration Setting | CWE-15 | OWASP:A05 | Yes |
-| Process Control | CWE-114 | None | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A03 | Yes |
-| Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A03 | Yes |
-| Inadequate Padding for AES encryption | CWE-326 | OWASP:A02 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Improper Validation of Certificate with Host Mismatch | CWE-297 | OWASP:A07 | Yes |
-| Java Naming and Directory Interface (JNDI) Injection | CWE-074 | None | Yes |
-| Improper Authentication | CWE-287 | Sans Top 25, OWASP:A07 | Yes |
-| LDAP Injection | CWE-90 | OWASP:A03 | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| The cipher text is equal to the provided input plain text | CWE-311 | OWASP:A04 | Yes |
-| Use of Hardcoded, Security-relevant Constants | CWE-547 | OWASP:A05 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Regular expression injection | CWE-400, CWE-730 | None | Yes |
-| Unprotected Storage of Credentials | CWE-256 | OWASP:A04 | Yes |
-| Server Information Exposure | CWE-209 | OWASP:A04 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| Android World Writeable/Readable File Permission Found | CWE-732 | None | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Observable Timing Discrepancy (Timing Attack) | CWE-208 | None | Yes |
-| Origin Validation Error | CWE-942, CWE-346 | OWASP:A05, OWASP:A07 | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
-| Cryptographic Issues | CWE-310 | OWASP:A02 | Yes |
-| Trust Boundary Violation | CWE-501 | OWASP:A04 | Yes |
-| Use of Externally-Controlled Format String | CWE-134 | None | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Insufficient Session Expiration | CWE-613 | OWASP:A07 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | --------------------------------------------------------- |
+| Use of Potentially Dangerous Function | CWE-676 | OWASP:A06:2025 |
+| Cleartext Storage of Sensitive Information in a Cookie | CWE-315 | OWASP:A02:2025 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Cross-Site Request Forgery (CSRF) | CWE-352 | CWE Top 25, OWASP:A01:2025 |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Cleartext Transmission of Sensitive Information | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Indirect Command Injection via User Controlled Environment | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| External Control of System or Configuration Setting | CWE-15 | OWASP:A02:2025 |
+| Process Control | CWE-114 | OWASP:A05:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
+| Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
+| Inadequate Padding for AES encryption | CWE-326 | OWASP:A04:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Improper Validation of Certificate with Host Mismatch | CWE-297 | OWASP:A07:2025 |
+| Java Naming and Directory Interface (JNDI) Injection | CWE-074 | OWASP:A05:2025 |
+| Improper Authentication | CWE-287 | OWASP:A07:2025 |
+| LDAP Injection | CWE-90 | OWASP:A05:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| The cipher text is equal to the provided input plain text | CWE-311 | OWASP:A06:2025 |
+| Use of Hardcoded, Security-relevant Constants | CWE-547 | OWASP:A02:2025 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Regular expression injection | CWE-400, CWE-730 | OWASP-API:API4:2023 |
+| Unprotected Storage of Credentials | CWE-256 | OWASP:A06:2025 |
+| Server Information Exposure | CWE-209 | OWASP:A10:2025, OWASP-API:API8:2023 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| Android World Writeable/Readable File Permission Found | CWE-732 | OWASP:A01:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Observable Timing Discrepancy (Timing Attack) | CWE-208 | None |
+| Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
+| Cryptographic Issues | CWE-310 | None |
+| Trust Boundary Violation | CWE-501 | OWASP:A06:2025 |
+| Use of Externally-Controlled Format String | CWE-134 | None |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Insufficient Session Expiration | CWE-613 | OWASP:A07:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/swift-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/swift-rules.md
index 42b58ea107c9..7672caf64126 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/swift-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/swift-rules.md
@@ -8,31 +8,30 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Clear Text Logging | CWE-200, CWE-312 | OWASP:A01, OWASP:A04 | Yes |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Device Authentication Bypass | CWE-287 | Sans Top 25, OWASP:A07 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Information Exposure | CWE-200 | OWASP:A01 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Insecure Data Storage | CWE-922 | OWASP:A01 | Yes |
-| Memory Corruption | CWE-822 | None | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Improper Certificate Validation | CWE-295 | OWASP:A07 | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Insecure Deserialization | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | ---------------------------------------------------------------- |
+| Clear Text Logging | CWE-200, CWE-312 | CWE Top 25, OWASP:A01:2025, OWASP:A06:2025, OWASP-API:API10:2023 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Device Authentication Bypass | CWE-287 | OWASP:A07:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Information Exposure | CWE-200 | CWE Top 25, OWASP:A01:2025, OWASP-API:API10:2023 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Insecure Data Storage | CWE-922 | OWASP:A01:2025 |
+| Memory Corruption | CWE-822 | None |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Improper Certificate Validation | CWE-295 | OWASP:A07:2025 |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Insecure Deserialization | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/visual-basic-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/visual-basic-rules.md
index 957e78210402..c81c1b52427d 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/visual-basic-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/visual-basic-rules.md
@@ -8,33 +8,32 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s):** The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10 ](https://owasp.org/Top10/)(2021 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Debug Features Enabled | CWE-215 | None | Yes |
-| Usage of BinaryFormatter | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Code Injection | CWE-94 | Sans Top 25, OWASP:A03 | Yes |
-| Command Injection | CWE-78 | Sans Top 25, OWASP:A03 | Yes |
-| Deserialization of Untrusted Data | CWE-502 | Sans Top 25, OWASP:A08 | Yes |
-| Hardcoded Secret | CWE-547 | OWASP:A05 | Yes |
-| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A03 | Yes |
-| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A02 | Yes |
-| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A02 | Yes |
-| Use of Insufficiently Random Values | CWE-330 | OWASP:A02 | Yes |
-| Use of Hardcoded Credentials | CWE-798 | Sans Top 25, OWASP:A07 | Yes |
-| Open Redirect | CWE-601 | OWASP:A01 | Yes |
-| Path Traversal | CWE-23 | OWASP:A01 | Yes |
-| Regular expression injection | CWE-400, CWE-730 | None | Yes |
-| Request Validation Disabled | CWE-554 | None | Yes |
-| SQL Injection | CWE-89 | Sans Top 25, OWASP:A03 | Yes |
-| Server-Side Request Forgery (SSRF) | CWE-918 | Sans Top 25, OWASP:A10 | Yes |
-| Inadequate Encryption Strength | CWE-326 | OWASP:A02 | Yes |
-| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A05 | Yes |
-| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A05 | Yes |
-| Cross-site Scripting (XSS) | CWE-79 | Sans Top 25, OWASP:A03 | Yes |
-| XML External Entity (XXE) Injection | CWE-611 | OWASP:A05 | Yes |
-| XML Injection | CWE-91 | OWASP:A03 | Yes |
-| XPath Injection | CWE-643 | OWASP:A03 | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | ----------------------------------------------- |
+| Debug Features Enabled | CWE-215 | OWASP:A10:2025 |
+| Usage of BinaryFormatter | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Code Injection | CWE-94 | CWE Top 25, OWASP:A05:2025 |
+| Command Injection | CWE-78 | CWE Top 25, OWASP:A05:2025 |
+| Deserialization of Untrusted Data | CWE-502 | CWE Top 25, OWASP:A08:2025 |
+| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
+| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
+| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
+| Open Redirect | CWE-601 | OWASP:A01:2025 |
+| Path Traversal | CWE-23 | OWASP:A01:2025 |
+| Regular expression injection | CWE-400, CWE-730 | OWASP-API:API4:2023 |
+| Request Validation Disabled | CWE-554 | None |
+| SQL Injection | CWE-89 | CWE Top 25, OWASP:A05:2025 |
+| Server-Side Request Forgery (SSRF) | CWE-918 | CWE Top 25, OWASP:A01:2025, OWASP-API:API7:2023 |
+| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
+| Sensitive Cookie Without 'HttpOnly' Flag | CWE-1004 | OWASP:A02:2025 |
+| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | CWE-614 | OWASP:A02:2025 |
+| Cross-site Scripting (XSS) | CWE-79 | CWE Top 25, OWASP:A05:2025 |
+| XML External Entity (XXE) Injection | CWE-611 | OWASP:A02:2025 |
+| XML Injection | CWE-91 | OWASP:A05:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/xml-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/xml-rules.md
index c5bd8a498a18..47824f630eaa 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/xml-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/xml-rules.md
@@ -8,17 +8,16 @@ nav_context: agnostic
Each rule includes the following information.
* **Rule Name**: The Snyk name of the rule.
-* **CWE(s)**: The [CWE numbers](https://cwe.mitre.org/) that are covered by this rule.
-* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/) (2025 edition) category to which the rule belongs to, if any, and if it is included in [SANS 25](https://www.sans.org/top25-software-errors/).
-* **Autofixable**: Security rules that are autofixable by Snyk Agent Fix. This information is included only for the supported programming languages.
+* **CWEs**: The [CWE numbers](https://cwe.mitre.org/) the rule covers.
+* **Security Categories**: The [OWASP Top 10](https://owasp.org/Top10/2025/) (2025 edition) category the rule maps to, when applicable. This column also notes whether the rule appears in the [CWE Top 25](https://cwe.mitre.org/top25/), and any applicable [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/) (2023) or [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) (2024) categories.
-| Rule Name | CWE(s) | Security Categories | Autofixable |
-| ------------------------------------------------------------ | ---------------- | ---------------------- | ----------- |
-| Android Debug Mode Enabled | CWE-489 | None | Yes |
-| Debug Features Enabled | CWE-215 | None | Yes |
-| Generation of Error Message Containing Sensitive Information | CWE-209 | OWASP:A04 | Yes |
-| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A04 | Yes |
-| ASP SSL Disabled | CWE-319 | OWASP:A02 | Yes |
-| Use of Hardcoded Passwords | CWE-798, CWE-259 | Sans Top 25, OWASP:A07 | Yes |
-| Request Validation Disabled | CWE-554 | None | Yes |
-| Struts Development Mode Enabled | CWE-489 | None | Yes |
+| Rule Name | CWEs | Security Categories |
+| ------------------------------------------------------------ | ---------------- | --------------------------------------------------------- |
+| Android Debug Mode Enabled | CWE-489 | OWASP:A02:2025 |
+| Debug Features Enabled | CWE-215 | OWASP:A10:2025 |
+| Generation of Error Message Containing Sensitive Information | CWE-209 | OWASP:A10:2025, OWASP-API:API8:2023 |
+| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A06:2025 |
+| ASP SSL Disabled | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Request Validation Disabled | CWE-554 | None |
+| Struts Development Mode Enabled | CWE-489 | OWASP:A02:2025 |