The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.
Volume of CVEs assigned to CWE-394 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25085CRITICAL A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in
which an unexpected return value from the authentication routine is
later on processed as a legitimate va | Feb 27, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-12516CRITICAL Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . | Oct 30, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-12515CRITICAL Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . | Oct 30, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-23013HIGH In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support auth | Jan 15, 2025 | 7.3 | 24 | NO | NO |
CVE-2019-0066HIGH An unexpected status return value weakness in the Next-Generation Multicast VPN (NG-mVPN) service of Juniper Networks Junos OS allows attacker to cause a Denial of Service (DoS) co | Oct 9, 2019 | 7.5 | 24 | NO | NO |
CVE-2025-48510HIGH Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability. | Nov 24, 2025 | 7.1 | 23 | NO | NO |
CVE-2019-20924MEDIUM A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which trigger an invariant in the IndexBoundsBuilder. This issue af | Nov 23, 2020 | 6.5 | 22 | NO | NO |
CVE-2018-20802MEDIUM A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting QueryPlanner. This issue affects Mo | Nov 23, 2020 | 6.5 | 22 | NO | NO |
CVE-2024-1713HIGH A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during autovacuum.
| Mar 14, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-25948HIGH Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgr | Jul 13, 2023 | 7.5 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.