CWE-697
Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.
161 vulnerabilities with CWE-697
CVE-2025-47416
MEDIUM
Crestron Touchscreen libsymproc - Attacker-Defined Command Execution
CVE-2025-9401
LOW
UTCMS 9 - Incorrect Comparison in Login Component
CVSS 3.7
CVE-2025-54336
CRITICAL
Plesk Obsidian 18.0.70 - Info Disclosure
CVSS 9.8
CVE-2025-27909
MEDIUM
IBM Concert 1.0.0-1.1.0 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.4
CVE-2025-48952
CRITICAL
netalertx < 25.6.7 - Authentication Bypass via PHP Loose Comparison
CVSS 9.4
CVE-2025-4515
MEDIUM
pribai/privategpt < 0.6.2 - Permissive Cross-domain Security Policy via allow_origins Argument
CVSS 4.3
CVE-2025-3102
HIGH
SureTriggers - All-in-One Automation Platform < 1.0.78 - Authentication Bypass
CVSS 8.1
CVE-2024-5528
LOW
GitLab CE/EE <16.11.6, <17.0.4, <17.1.2 - SSRF
CVSS 3.5
CVE-2024-53861
LOW
PyJWT 2.10.0 - Incorrect String Comparison in 'iss' Claim Validation
CVSS 2.2
CVE-2024-9681
MEDIUM
curl 7.74.0-8.10.0 - HSTS Cache Expiry Overwrite via Subdomain Strict-Transport-Security Header
CVSS 6.5
CVE-2024-39534
MEDIUM
Juniper Networks Junos OS Evolved - Info Disclosure
CVSS 5.4
CVE-2024-6641
MEDIUM
WP Hardening - Security Feature Bypass
CVSS 5.3
CVE-2024-41657
HIGH
Casdoor <= 1.577.0 - Authenticated Cross-Origin Request Forgery via Origin Header Prefix Check
CVSS 8.1
CVE-2024-41958
MEDIUM
mailcow < 2024-07 - Authenticated Two-Factor Authentication Bypass
CVSS 6.6
CVE-2024-32862
MEDIUM
ExacqVision Web Service < 24.03 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 6.8
CVE-2024-24621
CRITICAL
Softaculous Webuzo < 4.2.9 - Unauthenticated Authentication Bypass via Password Reset
CVSS 9.8
CVE-2024-5217
CRITICAL
KEV
ServiceNow Washington DC and Vancouver - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-39742
HIGH
IBM MQ Operator 2.0.0-2.0.23 and 3.2.2 - Authentication Bypass via Partial String Comparison
CVSS 8.1
CVE-2024-38522
MEDIUM
hush_line < 0.1.0 - Content Security Policy Bypass
CVSS 6.3
CVE-2024-4032
HIGH
CPython ipaddress Module IP Address Classification Flaw
CVSS 7.5
CVE-2024-34340
CRITICAL
Cacti < 1.2.27 - Type Juggling Authentication Bypass via Loose MD5 Comparison
CVSS 9.1
CVE-2024-2223
HIGH
Bitdefender GravityZone Update Server - Server-Side Request Forgery via Regex Bypass
CVSS 8.1
CVE-2024-28246
MEDIUM
KaTeX 0.11.0-0.16.9 - Cross-Site Scripting via Uppercase Protocol Bypass
CVSS 5.5
CVE-2024-29026
HIGH
owncast < 0.1.2 - Unauthenticated Admin Password Leak via Lenient CORS Policy
CVSS 8.2
CVE-2024-23903
MEDIUM
Jenkins GitLab Branch Source Plugin <684 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
161