The product accidentally uses the wrong operator, which changes the logic in security-relevant ways.
Volume of CVEs assigned to CWE-480 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-15043CRITICAL DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.
DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates i | Jul 14, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-43114CRITICAL In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
New test case fails unexpectedly whe | May 6, 2026 | 9.4 | 37 | NO | NO |
CVE-2026-48497HIGH Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured wit | Jun 26, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-44722MEDIUM pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused t | Jul 17, 2026 | 6.2 | 27 | NO | NO |
CVE-2026-4748HIGH A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently | Apr 1, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-1947MEDIUM Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3. | May 31, 2022 | 6.5 | 22 | NO | NO |
CVE-2025-52985MEDIUM A Use of Incorrect Operator
vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security | Jul 11, 2025 | 5.3 | 17 | NO | NO |
CVE-2024-35190MEDIUM Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk | May 17, 2024 | 5.3 | 16 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.