The product uses an expression in which operator precedence causes incorrect logic to be used.
Volume of CVEs assigned to CWE-783 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32896HIGH there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti | Jun 13, 2024 | 7.8 | 66 | YES | NO |
CVE-2026-7270HIGH An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers.
The bug ma | Apr 30, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-25233CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, | Feb 3, 2026 | 9.1 | 26 | NO | NO |
CVE-2022-20477HIGH In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to lo | Dec 13, 2022 | 7.8 | 25 | NO | NO |
CVE-2024-20480HIGH A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to ca | Sep 25, 2024 | 8.6 | 24 | NO | NO |
CVE-2026-0209MEDIUM Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured. | Apr 14, 2026 | 6.9 | 22 | NO | NO |
CVE-2024-44093HIGH In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additio | Sep 13, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-34741HIGH In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility setting | Aug 15, 2024 | 7.8 | 21 | NO | NO |
CVE-2024-34726HIGH In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with | Jul 9, 2024 | 7.8 | 21 | NO | NO |
CVE-2024-34723HIGH In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logic error in the code. This could lead to | Jul 9, 2024 | 7.8 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.