The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.
Volume of CVEs assigned to CWE-682 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
130 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30780HIGH Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c h | Jun 11, 2022 | 7.5 | 56 | NO | NO |
CVE-2026-16363CRITICAL JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | Jul 21, 2026 | 9.8 | 39 | NO | NO |
CVE-2018-8319CRITICAL A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library | Jul 11, 2018 | 9.8 | 35 | NO | NO |
CVE-2026-47247HIGH libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid i | Jul 21, 2026 | 7.5 | 33 | NO | NO |
CVE-2022-30600CRITICAL A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. | May 18, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-44847CRITICAL A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the hand | Dec 13, 2021 | 9.8 | 33 | NO | NO |
CVE-2026-1229CRITICAL The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas.
E | Feb 24, 2026 | 9.8 | 32 | NO | NO |
CVE-2022-23066CRITICAL In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution | May 9, 2022 | 9.1 | 31 | NO | NO |
CVE-2026-10512HIGH The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so the computed result may not be fully reduced modulo the fie | Jun 25, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-44498HIGH ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MA | May 8, 2026 | 7.5 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.