CWE-697
Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.
161 vulnerabilities with CWE-697
CVE-2026-67207
HIGH
Wolf CMS <= 0.8.3.1 - Authenticated Backup Authorization Bypass
CVSS 8.8
CVE-2026-48032
HIGH
Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
CVE-2026-65903
MEDIUM
DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS
CVSS 6.1
CVE-2026-55771
HIGH
CedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities
CVSS 8.8
CVE-2026-22660
HIGH
FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
CVSS 7.2
CVE-2026-59890
MEDIUM
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
CVSS 6.1
CVE-2026-14687
MEDIUM
666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
CVSS 5.3
CVE-2026-14686
LOW
HdrHistogram Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison
CVSS 3.3
CVE-2026-14617
LOW
NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivity
CVSS 3.1
CVE-2026-10097
HIGH
ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security
CVSS 7.5
CVE-2026-49340
HIGH
Sentriz Gonic < 0.21.0 - Authenticated Arbitrary Playlist File Write
CVSS 8.1
CVE-2026-44249
HIGH
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVSS 8.1
CVE-2026-45569
HIGH
Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)
CVSS 8.1
CVE-2026-45567
HIGH
Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
CVSS 8.3
CVE-2026-47202
CRITICAL
Kavita: Pre-Auth Account Takeover
CVE-2026-9369
MEDIUM
NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison
CVSS 5.3
CVE-2026-44196
CRITICAL
Pingvin Share X: TOTP Authentication Bypass via Password-only Login
CVSS 9.1
CVE-2026-35040
MEDIUM
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
CVSS 5.3
CVE-2026-34574
MEDIUM
Parse Server: Session field immutability bypass via falsy-value guard
CVSS 5.4
CVE-2026-34210
HIGH
mppx has Stripe charge credential replay via missing idempotency check
CVSS 8.1
CVE-2026-32322
MEDIUM
soroban-sdk <22.0.11,23.5.3,25.3.0 - Comparison Vulnerability
CVSS 5.3
CVE-2026-26275
HIGH
httpsig-hyper <0.0.23 - Auth Bypass
CVSS 7.5
CVE-2026-21691
MEDIUM
iccdev < 2.3.1.2 - Type Confusion in CIccTag:IsTypeCompressed()
CVSS 5.4
CVE-2025-20343
HIGH
Cisco Identity Services Engine - Denial of Service via RADIUS Request Processing
CVSS 8.6
CVE-2025-12192
MEDIUM
The Events Calendar <6.15.9 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
161