CWE-697 · 126 kayıt
Incorrect Comparison
Bu sınıftaki CVE’ler
126 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
88Hemen | CVE-2020-5849Silahlaştırılmış | Unraid 6.8.0 allows authentication bypass.unraid · unraid · CWE-697 | Yüksek7,5 | KEV | %93,2 | 16 Mar 2020 |
59Planlayın | CVE-2020-8864İstismar yok | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-dlink · dir-878 firmware · CWE-697 | Yüksek8,8 | — | %80,2 | 23 Mar 2020 |
55Planlayın | CVE-2025-3102Silahlaştırılmış | SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creationbrainstormforce · ottokit: all-in-one automation platform · CWE-697 | Yüksek8,1 | — | %76,2 | 10 Nis 2025 |
49Planlayın | CVE-2023-32571Kavram kanıtı | Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods indynamic-linq · linq · CWE-697 | Kritik9,8 | — | %34,9 | 22 Haz 2023 |
40Planlayın | CVE-2021-35973İstismar yok | NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthentnetgear · wac104 firmware · CWE-697 | Kritik9,8 | — | %3,1 | 30 Haz 2021 |
40Planlayın | CVE-2021-44971İstismar yok | Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multenda · ac15 firmware · CWE-697 | Kritik9,8 | — | %2,1 | 28 Oca 2022 |
39İzleyin | CVE-2020-8862İstismar yok | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0dlink · dap-2610 firmware · CWE-697 | Yüksek8,8 | — | %13,3 | 21 Şub 2020 |
39İzleyin | CVE-2020-23360İstismar yok | oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the cheoscommerce · oscommerce · CWE-697 | Kritik9,8 | — | %1,2 | 27 Oca 2021 |
39İzleyin | CVE-2020-23359İstismar yok | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the idenwebidsupport · webid · CWE-697 | Kritik9,8 | — | %1,2 | 27 Oca 2021 |
39İzleyin | CVE-2024-24621İstismar yok | Softaculous Webuzo Authentication Bypasssoftaculous · webuzo · CWE-697 | Kritik9,8 | — | %1,2 | 25 Tem 2024 |
39İzleyin | CVE-2021-3833İstismar yok | Integria IMS incorrect authorizationartica · integria ims · CWE-697 | Kritik9,8 | — | %1,1 | 7 Eki 2021 |
39İzleyin | CVE-2022-47034İstismar yok | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.playsms · playsms · CWE-697 | Kritik9,8 | — | %0,8 | 13 Şub 2023 |
39İzleyin | CVE-2014-125057İstismar yok | mrobit robitailletheknot CSRF Token filters.php comparisonrobitailletheknot project · robitailletheknot · CWE-697 | Kritik9,8 | — | %0,8 | 7 Oca 2023 |
39İzleyin | CVE-2025-54336İstismar yok | In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison.CWE-697 | Kritik9,8 | — | %0,5 | 19 Ağu 2025 |
37İzleyin | CVE-2026-75110İstismar yok | MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRETmemtensor · memos · CWE-697 | Kritik9,3 | — | %0,7 | 17 Ağu 2026 |
37İzleyin | CVE-2025-48952İstismar yok | NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHPnetalertx · netalertx · CWE-697 | Kritik9,4 | — | %0,6 | 4 Tem 2025 |
36İzleyin | CVE-2022-43621İstismar yok | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-697 | Yüksek8,8 | — | %2,1 | 29 Mar 2023 |
36İzleyin | CVE-2020-13485İstismar yok | The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.verbb · knock knock · CWE-697 | Kritik9,1 | — | %1,4 | 25 May 2020 |
36İzleyin | CVE-2026-73309Kavram kanıtı | XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpointxenforo · xenforo · CWE-697 | Kritik9,1 | — | %0,7 | 8 Eyl 2026 |
35İzleyin | CVE-2026-20333İstismar yok | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incisco · cisco secure firewall adaptive security appliance (asa) software · CWE-697 | Yüksek8,8 | — | %0,3 | 16 Eyl 2026 |
34İzleyin | CVE-2020-11072İstismar yok | False-negative validation results in MINT transactions with invalid batonsimpleledger · slp-validate · CWE-697 | Yüksek8,6 | — | %1,0 | 11 May 2020 |
34İzleyin | CVE-2020-11071İstismar yok | False-negative validation results in MINT transactions with invalid batonsimpleledger · slpjs · CWE-697 | Yüksek8,6 | — | %0,9 | 11 May 2020 |
34İzleyin | CVE-2026-22660İstismar yok | FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpointflaskbb · flaskbb · CWE-697 | Yüksek8,6 | — | %0,6 | 10 Tem 2026 |
34İzleyin | CVE-2026-67207İstismar yok | Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreControllerwolfcms · wolfcms · CWE-697 | Yüksek8,7 | — | %0,5 | 30 Tem 2026 |
33İzleyin | CVE-2026-48032İstismar yok | Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providerskerberosmansour · hulumi · CWE-697 | Yüksek8,3 | — | %0,5 | 24 Tem 2026 |
- CVE-2020-584988Hemen
Unraid 6.8.0 allows authentication bypass.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %93unraid · unraid16 Mar 2020
- CVE-2020-886459Planlayın
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-
YüksekCVSS 8,8İstismar yokEPSS %80dlink · dir-878 firmware23 Mar 2020
- CVE-2025-310255Planlayın
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
YüksekCVSS 8,1SilahlaştırılmışEPSS %76brainstormforce · ottokit: all-in-one automation platform10 Nis 2025
- CVE-2023-3257149Planlayın
Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods in
KritikCVSS 9,8Kavram kanıtıEPSS %35dynamic-linq · linq22 Haz 2023
- CVE-2021-3597340Planlayın
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthent
KritikCVSS 9,8İstismar yokEPSS %3netgear · wac104 firmware30 Haz 2021
- CVE-2021-4497140Planlayın
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_mul
KritikCVSS 9,8İstismar yokEPSS %2tenda · ac15 firmware28 Oca 2022
- CVE-2020-886239İzleyin
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0
YüksekCVSS 8,8İstismar yokEPSS %13dlink · dap-2610 firmware21 Şub 2020
- CVE-2020-2336039İzleyin
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the che
KritikCVSS 9,8İstismar yokEPSS %1oscommerce · oscommerce27 Oca 2021
- CVE-2020-2335939İzleyin
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden
KritikCVSS 9,8İstismar yokEPSS %1webidsupport · webid27 Oca 2021
- CVE-2024-2462139İzleyin
Softaculous Webuzo Authentication Bypass
KritikCVSS 9,8İstismar yokEPSS %1softaculous · webuzo25 Tem 2024
- CVE-2021-383339İzleyin
Integria IMS incorrect authorization
KritikCVSS 9,8İstismar yokEPSS %1artica · integria ims7 Eki 2021
- CVE-2022-4703439İzleyin
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.
KritikCVSS 9,8İstismar yokEPSS %1playsms · playsms13 Şub 2023
- CVE-2014-12505739İzleyin
mrobit robitailletheknot CSRF Token filters.php comparison
KritikCVSS 9,8İstismar yokEPSS %1robitailletheknot project · robitailletheknot7 Oca 2023
- CVE-2025-5433639İzleyin
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison.
KritikCVSS 9,8İstismar yokEPSS %119 Ağu 2025
- CVE-2026-7511037İzleyin
MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
KritikCVSS 9,3İstismar yokEPSS %1memtensor · memos17 Ağu 2026
- CVE-2025-4895237İzleyin
NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP
KritikCVSS 9,4İstismar yokEPSS %1netalertx · netalertx4 Tem 2025
- CVE-2022-4362136İzleyin
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers.
YüksekCVSS 8,8İstismar yokEPSS %2dlink · dir-1935 firmware29 Mar 2023
- CVE-2020-1348536İzleyin
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
KritikCVSS 9,1İstismar yokEPSS %1verbb · knock knock25 May 2020
- CVE-2026-7330936İzleyin
XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
KritikCVSS 9,1Kavram kanıtıEPSS %1xenforo · xenforo8 Eyl 2026
- CVE-2026-2033335İzleyin
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - In
YüksekCVSS 8,8İstismar yokEPSS %0cisco · cisco secure firewall adaptive security appliance (asa) software16 Eyl 2026
- CVE-2020-1107234İzleyin
False-negative validation results in MINT transactions with invalid baton
YüksekCVSS 8,6İstismar yokEPSS %1simpleledger · slp-validate11 May 2020
- CVE-2020-1107134İzleyin
False-negative validation results in MINT transactions with invalid baton
YüksekCVSS 8,6İstismar yokEPSS %1simpleledger · slpjs11 May 2020
- CVE-2026-2266034İzleyin
FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
YüksekCVSS 8,6İstismar yokEPSS %1flaskbb · flaskbb10 Tem 2026
- CVE-2026-6720734İzleyin
Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
YüksekCVSS 8,7İstismar yokEPSS %1wolfcms · wolfcms30 Tem 2026
- CVE-2026-4803233İzleyin
Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
YüksekCVSS 8,3İstismar yokEPSS %1kerberosmansour · hulumi24 Tem 2026