A function or operation returns an incorrect return value or status code that does not indicate the true result of execution, causing the product to modify its behavior based on the incorrect result.
Volume of CVEs assigned to CWE-393 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9058CRITICAL For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the spec | May 25, 2026 | 9.3 | 40 | NO | NO |
CVE-2026-55958HIGH Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fai | Jun 25, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-42246HIGH Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cau | May 9, 2026 | 7.4 | 33 | NO | NO |
CVE-2026-53092HIGH In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix linked reg delta tracking when src_reg == dst_reg
Consider the case of rX += rX where src_reg and dst | Jun 24, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-5987HIGH A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to lib | Jul 7, 2025 | 8.1 | 25 | NO | NO |
CVE-2025-32414HIGH In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xm | Apr 8, 2025 | 7.5 | 23 | NO | NO |
CVE-2023-37897HIGH Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|fil | Jul 18, 2023 | 8.8 | 23 | NO | NO |
CVE-2025-24531MEDIUM In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing aut | Jan 16, 2026 | 6.7 | 22 | NO | NO |
CVE-2024-49117HIGH Windows Hyper-V Remote Code Execution Vulnerability | Dec 12, 2024 | 8.8 | 22 | NO | NO |
CVE-2020-5401MEDIUM Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent leg | Feb 27, 2020 | 5.3 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.