CWE-697

Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect.

150 vulnerabilities with CWE-697
CVE-2026-44249 HIGH
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVSS 8.1
CVE-2026-45569 HIGH
Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)
CVSS 8.1
CVE-2026-45567 HIGH
Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
CVSS 8.3
CVE-2026-47202 CRITICAL
Kavita: Pre-Auth Account Takeover
CVE-2026-9369 MEDIUM
NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison
CVSS 5.3
CVE-2026-44196 CRITICAL
Pingvin Share X: TOTP Authentication Bypass via Password-only Login
CVSS 9.1
CVE-2026-35040 MEDIUM
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
CVSS 5.3
CVE-2026-34574 MEDIUM
Parse Server: Session field immutability bypass via falsy-value guard
CVSS 5.4
CVE-2026-34210 HIGH
mppx has Stripe charge credential replay via missing idempotency check
CVSS 8.1
CVE-2026-32322 MEDIUM
soroban-sdk <22.0.11,23.5.3,25.3.0 - Comparison Vulnerability
CVSS 5.3
CVE-2026-26275 HIGH
httpsig-hyper <0.0.23 - Auth Bypass
CVSS 7.5
CVE-2026-21691 MEDIUM
iccdev < 2.3.1.2 - Type Confusion in CIccTag:IsTypeCompressed()
CVSS 5.4
CVE-2025-20343 HIGH
Cisco Identity Services Engine - Denial of Service via RADIUS Request Processing
CVSS 8.6
CVE-2025-12192 MEDIUM
The Events Calendar <6.15.9 - Info Disclosure
CVSS 5.3
CVE-2025-47416 MEDIUM
Crestron Touchscreen libsymproc - Attacker-Defined Command Execution
CVE-2025-9401 LOW
UTCMS 9 - Incorrect Comparison in Login Component
CVSS 3.7
CVE-2025-54336 CRITICAL
Plesk Obsidian 18.0.70 - Info Disclosure
CVSS 9.8
CVE-2025-27909 MEDIUM
IBM Concert 1.0.0-1.1.0 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.4
CVE-2025-48952 CRITICAL
netalertx < 25.6.7 - Authentication Bypass via PHP Loose Comparison
CVSS 9.4
CVE-2025-4515 MEDIUM
pribai/privategpt < 0.6.2 - Permissive Cross-domain Security Policy via allow_origins Argument
CVSS 4.3
CVE-2025-3102 HIGH
SureTriggers - All-in-One Automation Platform < 1.0.78 - Authentication Bypass
CVSS 8.1
CVE-2024-5528 LOW
GitLab CE/EE <16.11.6, <17.0.4, <17.1.2 - SSRF
CVSS 3.5
CVE-2024-53861 LOW
PyJWT 2.10.0 - Incorrect String Comparison in 'iss' Claim Validation
CVSS 2.2
CVE-2024-9681 MEDIUM
curl 7.74.0-8.10.0 - HSTS Cache Expiry Overwrite via Subdomain Strict-Transport-Security Header
CVSS 6.5
CVE-2024-39534 MEDIUM
Juniper Networks Junos OS Evolved - Info Disclosure
CVSS 5.4
Details
Vulnerabilities 150