CWE-697

Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect.

161 vulnerabilities with CWE-697
CVE-2026-67207 HIGH
Wolf CMS <= 0.8.3.1 - Authenticated Backup Authorization Bypass
CVSS 8.8
CVE-2026-48032 HIGH
Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
CVE-2026-65903 MEDIUM
DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS
CVSS 6.1
CVE-2026-55771 HIGH
CedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities
CVSS 8.8
CVE-2026-22660 HIGH
FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
CVSS 7.2
CVE-2026-59890 MEDIUM
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
CVSS 6.1
CVE-2026-14687 MEDIUM
666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
CVSS 5.3
CVE-2026-14686 LOW
HdrHistogram Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison
CVSS 3.3
CVE-2026-14617 LOW
NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivity
CVSS 3.1
CVE-2026-10097 HIGH
ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security
CVSS 7.5
CVE-2026-49340 HIGH
Sentriz Gonic < 0.21.0 - Authenticated Arbitrary Playlist File Write
CVSS 8.1
CVE-2026-44249 HIGH
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVSS 8.1
CVE-2026-45569 HIGH
Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)
CVSS 8.1
CVE-2026-45567 HIGH
Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
CVSS 8.3
CVE-2026-47202 CRITICAL
Kavita: Pre-Auth Account Takeover
CVE-2026-9369 MEDIUM
NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison
CVSS 5.3
CVE-2026-44196 CRITICAL
Pingvin Share X: TOTP Authentication Bypass via Password-only Login
CVSS 9.1
CVE-2026-35040 MEDIUM
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
CVSS 5.3
CVE-2026-34574 MEDIUM
Parse Server: Session field immutability bypass via falsy-value guard
CVSS 5.4
CVE-2026-34210 HIGH
mppx has Stripe charge credential replay via missing idempotency check
CVSS 8.1
CVE-2026-32322 MEDIUM
soroban-sdk <22.0.11,23.5.3,25.3.0 - Comparison Vulnerability
CVSS 5.3
CVE-2026-26275 HIGH
httpsig-hyper <0.0.23 - Auth Bypass
CVSS 7.5
CVE-2026-21691 MEDIUM
iccdev < 2.3.1.2 - Type Confusion in CIccTag:IsTypeCompressed()
CVSS 5.4
CVE-2025-20343 HIGH
Cisco Identity Services Engine - Denial of Service via RADIUS Request Processing
CVSS 8.6
CVE-2025-12192 MEDIUM
The Events Calendar <6.15.9 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 161