CWE-697
Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.
150 vulnerabilities with CWE-697
CVE-2026-44249
HIGH
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVSS 8.1
CVE-2026-45569
HIGH
Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)
CVSS 8.1
CVE-2026-45567
HIGH
Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
CVSS 8.3
CVE-2026-47202
CRITICAL
Kavita: Pre-Auth Account Takeover
CVE-2026-9369
MEDIUM
NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison
CVSS 5.3
CVE-2026-44196
CRITICAL
Pingvin Share X: TOTP Authentication Bypass via Password-only Login
CVSS 9.1
CVE-2026-35040
MEDIUM
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
CVSS 5.3
CVE-2026-34574
MEDIUM
Parse Server: Session field immutability bypass via falsy-value guard
CVSS 5.4
CVE-2026-34210
HIGH
mppx has Stripe charge credential replay via missing idempotency check
CVSS 8.1
CVE-2026-32322
MEDIUM
soroban-sdk <22.0.11,23.5.3,25.3.0 - Comparison Vulnerability
CVSS 5.3
CVE-2026-26275
HIGH
httpsig-hyper <0.0.23 - Auth Bypass
CVSS 7.5
CVE-2026-21691
MEDIUM
iccdev < 2.3.1.2 - Type Confusion in CIccTag:IsTypeCompressed()
CVSS 5.4
CVE-2025-20343
HIGH
Cisco Identity Services Engine - Denial of Service via RADIUS Request Processing
CVSS 8.6
CVE-2025-12192
MEDIUM
The Events Calendar <6.15.9 - Info Disclosure
CVSS 5.3
CVE-2025-47416
MEDIUM
Crestron Touchscreen libsymproc - Attacker-Defined Command Execution
CVE-2025-9401
LOW
UTCMS 9 - Incorrect Comparison in Login Component
CVSS 3.7
CVE-2025-54336
CRITICAL
Plesk Obsidian 18.0.70 - Info Disclosure
CVSS 9.8
CVE-2025-27909
MEDIUM
IBM Concert 1.0.0-1.1.0 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.4
CVE-2025-48952
CRITICAL
netalertx < 25.6.7 - Authentication Bypass via PHP Loose Comparison
CVSS 9.4
CVE-2025-4515
MEDIUM
pribai/privategpt < 0.6.2 - Permissive Cross-domain Security Policy via allow_origins Argument
CVSS 4.3
CVE-2025-3102
HIGH
SureTriggers - All-in-One Automation Platform < 1.0.78 - Authentication Bypass
CVSS 8.1
CVE-2024-5528
LOW
GitLab CE/EE <16.11.6, <17.0.4, <17.1.2 - SSRF
CVSS 3.5
CVE-2024-53861
LOW
PyJWT 2.10.0 - Incorrect String Comparison in 'iss' Claim Validation
CVSS 2.2
CVE-2024-9681
MEDIUM
curl 7.74.0-8.10.0 - HSTS Cache Expiry Overwrite via Subdomain Strict-Transport-Security Header
CVSS 6.5
CVE-2024-39534
MEDIUM
Juniper Networks Junos OS Evolved - Info Disclosure
CVSS 5.4
Details
Vulnerabilities
150