Cyber Resilience

CWE · MITRE source

CWE-681Incorrect Conversion between Numeric Types

Abstraction: Base · CVEs in our corpus: 128

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
  • SA-8 Security and Privacy Engineering Principles
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2016-3074 9.09.80.36972016-04-26
CVE-2022-34169 8.47.50.81042022-07-19
CVE-2009-0231 8.38.80.37452009-07-15
CVE-2018-8786 8.19.80.08162018-11-29
CVE-2019-19317 7.99.80.04282019-12-05
CVE-2019-14842 7.69.80.01852019-11-26
CVE-2020-35926 7.69.80.01522020-12-31
CVE-2021-38187 7.69.80.01442021-08-08
CVE-2021-36357 7.59.80.01182021-10-22
CVE-2022-40138 7.59.80.00962022-10-11
CVE-2022-43663 7.28.10.14042023-03-20
CVE-2023-46848 7.18.60.10222023-11-03
CVE-2017-7308 7.07.80.17832017-03-29
CVE-2020-12417 7.08.80.02692020-07-09
CVE-2022-36025 7.09.10.00902022-09-24
CVE-2021-21860 6.98.80.01632021-08-16
CVE-2021-21861 6.98.80.01632021-08-16
CVE-2023-24884 6.98.80.01642023-04-11
CVE-2024-26162 6.98.80.02022024-03-12
CVE-2008-3282 6.87.80.10762008-08-29
CVE-2020-6096 6.88.10.05352020-04-01
CVE-2021-23997 6.78.80.00822021-06-24
CVE-2018-10887 6.58.10.02052018-07-10
CVE-2020-13985 6.57.50.04812020-12-11
CVE-2021-27478 6.58.20.01112022-05-12