CWE-697

Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect.

150 vulnerabilities with CWE-697
CVE-2023-23845 MEDIUM
SolarWinds Platform - Privilege Escalation
CVSS 6.8
CVE-2023-23840 MEDIUM
SolarWinds Platform - Privilege Escalation
CVSS 6.8
CVE-2023-40271 HIGH
Trusted Firmware-M < TF-Mv1.8.0 - Buffer Overflow
CVSS 7.5
CVE-2023-41936 HIGH
Jenkins Google Login Plugin <1.7 - Info Disclosure
CVSS 7.5
CVE-2023-41935 HIGH
Jenkins Azure AD Plugin < 396.v86ce29279947 - Non-Constant Time Comparison in CSRF Nonce Check
CVSS 7.5
CVE-2023-23765 MEDIUM
GitHub Enterprise Server - Info Disclosure
CVSS 4.8
CVE-2023-40037 MEDIUM
Apache NiFi 1.21.0-1.23.0 - Authenticated Connection URL Validation Bypass via Custom Input Formatting
CVSS 6.5
CVE-2023-23764 MEDIUM
GitHub Enterprise Server <3.7.9-3.9.1 - Info Disclosure
CVSS 4.8
CVE-2023-33225 HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-23844 HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-23843 HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-22435 HIGH
Honeywell Experion Server 501.1-501.6hf8 - Denial of Service via Crafted Message
CVSS 7.5
CVE-2023-32627 MEDIUM
Sound Exchange - Denial of Service
CVSS 6.2
CVE-2023-26590 MEDIUM
sound_exchange - Denial of Service via Floating Point Exception in lsx_aiffstartwrite
CVSS 6.2
CVE-2023-36829 MEDIUM
Sentry 23.6.0-23.6.2 - Permissive Cross-domain Security Policy via Origin Header
CVSS 6.8
CVE-2023-32571 CRITICAL
System.Linq.Dynamic.Core 1.0.7.10-1.2.25 - Remote Code Execution via Untrusted Input Parsing
CVSS 9.8
CVE-2023-28936 MEDIUM
Apache OpenMeetings <7.1.0 - Info Disclosure
CVSS 5.3
CVE-2023-23762 MEDIUM
GitHub Enterprise Server <3.9 - Info Disclosure
CVSS 6.5
CVE-2023-27579 HIGH
TensorFlow < 2.12.0 - Denial of Service via Filter Input Channel Parameter
CVSS 7.5
CVE-2023-25675 HIGH
TensorFlow <2.12.0, 2.11.1 - Use After Free
CVSS 7.5
CVE-2023-25673 HIGH
TensorFlow <2.12.0, 2.11.1 - Info Disclosure
CVSS 7.5
CVE-2023-25669 HIGH
TensorFlow <2.12.0, 2.11.1 - Info Disclosure
CVSS 7.5
CVE-2023-25666 HIGH
TensorFlow <2.12.0-2.11.1 - Info Disclosure
CVSS 7.5
CVE-2022-29944 MEDIUM
ONOS 2.5.1 - Incorrect Path Comparison in Intent Framework
CVSS 5.3
CVE-2022-43621 HIGH
D-Link DIR-1935 Firmware < 1.02 - Unauthenticated Authentication Bypass via HNAP Login Request
CVSS 8.8
Details
Vulnerabilities 150