CWE-697 · 126 records
Incorrect Comparison
CVEs in this class
126 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
88Now | CVE-2020-5849Weaponized | Unraid 6.8.0 allows authentication bypass.unraid · unraid · CWE-697 | High7.5 | KEV | 93.2% | Mar 16, 2020 |
59Plan | CVE-2020-8864No exploit | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-dlink · dir-878 firmware · CWE-697 | High8.8 | — | 80.2% | Mar 23, 2020 |
55Plan | CVE-2025-3102Weaponized | SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creationbrainstormforce · ottokit: all-in-one automation platform · CWE-697 | High8.1 | — | 76.2% | Apr 10, 2025 |
49Plan | CVE-2023-32571Proof of concept | Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods indynamic-linq · linq · CWE-697 | Critical9.8 | — | 34.9% | Jun 22, 2023 |
40Plan | CVE-2021-35973No exploit | NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthentnetgear · wac104 firmware · CWE-697 | Critical9.8 | — | 3.1% | Jun 30, 2021 |
40Plan | CVE-2021-44971No exploit | Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multenda · ac15 firmware · CWE-697 | Critical9.8 | — | 2.1% | Jan 28, 2022 |
39Monitor | CVE-2020-8862No exploit | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0dlink · dap-2610 firmware · CWE-697 | High8.8 | — | 13.3% | Feb 21, 2020 |
39Monitor | CVE-2020-23360No exploit | oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the cheoscommerce · oscommerce · CWE-697 | Critical9.8 | — | 1.2% | Jan 27, 2021 |
39Monitor | CVE-2020-23359No exploit | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the idenwebidsupport · webid · CWE-697 | Critical9.8 | — | 1.2% | Jan 27, 2021 |
39Monitor | CVE-2024-24621No exploit | Softaculous Webuzo Authentication Bypasssoftaculous · webuzo · CWE-697 | Critical9.8 | — | 1.2% | Jul 25, 2024 |
39Monitor | CVE-2021-3833No exploit | Integria IMS incorrect authorizationartica · integria ims · CWE-697 | Critical9.8 | — | 1.1% | Oct 7, 2021 |
39Monitor | CVE-2022-47034No exploit | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.playsms · playsms · CWE-697 | Critical9.8 | — | 0.8% | Feb 13, 2023 |
39Monitor | CVE-2014-125057No exploit | mrobit robitailletheknot CSRF Token filters.php comparisonrobitailletheknot project · robitailletheknot · CWE-697 | Critical9.8 | — | 0.8% | Jan 7, 2023 |
39Monitor | CVE-2025-54336No exploit | In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison.CWE-697 | Critical9.8 | — | 0.5% | Aug 19, 2025 |
37Monitor | CVE-2026-75110No exploit | MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRETmemtensor · memos · CWE-697 | Critical9.3 | — | 0.7% | Aug 17, 2026 |
37Monitor | CVE-2025-48952No exploit | NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHPnetalertx · netalertx · CWE-697 | Critical9.4 | — | 0.6% | Jul 4, 2025 |
36Monitor | CVE-2022-43621No exploit | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-697 | High8.8 | — | 2.1% | Mar 29, 2023 |
36Monitor | CVE-2020-13485No exploit | The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.verbb · knock knock · CWE-697 | Critical9.1 | — | 1.4% | May 25, 2020 |
36Monitor | CVE-2026-73309Proof of concept | XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpointxenforo · xenforo · CWE-697 | Critical9.1 | — | 0.7% | Sep 8, 2026 |
35Monitor | CVE-2026-20333No exploit | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incisco · cisco secure firewall adaptive security appliance (asa) software · CWE-697 | High8.8 | — | 0.3% | Sep 16, 2026 |
34Monitor | CVE-2020-11072No exploit | False-negative validation results in MINT transactions with invalid batonsimpleledger · slp-validate · CWE-697 | High8.6 | — | 1.0% | May 11, 2020 |
34Monitor | CVE-2020-11071No exploit | False-negative validation results in MINT transactions with invalid batonsimpleledger · slpjs · CWE-697 | High8.6 | — | 0.9% | May 11, 2020 |
34Monitor | CVE-2026-22660No exploit | FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpointflaskbb · flaskbb · CWE-697 | High8.6 | — | 0.6% | Jul 10, 2026 |
34Monitor | CVE-2026-67207No exploit | Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreControllerwolfcms · wolfcms · CWE-697 | High8.7 | — | 0.5% | Jul 30, 2026 |
33Monitor | CVE-2026-48032No exploit | Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providerskerberosmansour · hulumi · CWE-697 | High8.3 | — | 0.5% | Jul 24, 2026 |
- CVE-2020-584988Now
Unraid 6.8.0 allows authentication bypass.
HighCVSS 7.5KEVWeaponizedEPSS 93%unraid · unraidMar 16, 2020
- CVE-2020-886459Plan
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-
HighCVSS 8.8No exploitEPSS 80%dlink · dir-878 firmwareMar 23, 2020
- CVE-2025-310255Plan
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
HighCVSS 8.1WeaponizedEPSS 76%brainstormforce · ottokit: all-in-one automation platformApr 10, 2025
- CVE-2023-3257149Plan
Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods in
CriticalCVSS 9.8Proof of conceptEPSS 35%dynamic-linq · linqJun 22, 2023
- CVE-2021-3597340Plan
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthent
CriticalCVSS 9.8No exploitEPSS 3%netgear · wac104 firmwareJun 30, 2021
- CVE-2021-4497140Plan
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_mul
CriticalCVSS 9.8No exploitEPSS 2%tenda · ac15 firmwareJan 28, 2022
- CVE-2020-886239Monitor
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0
HighCVSS 8.8No exploitEPSS 13%dlink · dap-2610 firmwareFeb 21, 2020
- CVE-2020-2336039Monitor
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the che
CriticalCVSS 9.8No exploitEPSS 1%oscommerce · oscommerceJan 27, 2021
- CVE-2020-2335939Monitor
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden
CriticalCVSS 9.8No exploitEPSS 1%webidsupport · webidJan 27, 2021
- CVE-2024-2462139Monitor
Softaculous Webuzo Authentication Bypass
CriticalCVSS 9.8No exploitEPSS 1%softaculous · webuzoJul 25, 2024
- CVE-2021-383339Monitor
Integria IMS incorrect authorization
CriticalCVSS 9.8No exploitEPSS 1%artica · integria imsOct 7, 2021
- CVE-2022-4703439Monitor
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.
CriticalCVSS 9.8No exploitEPSS 1%playsms · playsmsFeb 13, 2023
- CVE-2014-12505739Monitor
mrobit robitailletheknot CSRF Token filters.php comparison
CriticalCVSS 9.8No exploitEPSS 1%robitailletheknot project · robitailletheknotJan 7, 2023
- CVE-2025-5433639Monitor
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison.
CriticalCVSS 9.8No exploitEPSS 1%Aug 19, 2025
- CVE-2026-7511037Monitor
MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
CriticalCVSS 9.3No exploitEPSS 1%memtensor · memosAug 17, 2026
- CVE-2025-4895237Monitor
NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP
CriticalCVSS 9.4No exploitEPSS 1%netalertx · netalertxJul 4, 2025
- CVE-2022-4362136Monitor
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers.
HighCVSS 8.8No exploitEPSS 2%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2020-1348536Monitor
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
CriticalCVSS 9.1No exploitEPSS 1%verbb · knock knockMay 25, 2020
- CVE-2026-7330936Monitor
XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
CriticalCVSS 9.1Proof of conceptEPSS 1%xenforo · xenforoSep 8, 2026
- CVE-2026-2033335Monitor
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - In
HighCVSS 8.8No exploitEPSS 0%cisco · cisco secure firewall adaptive security appliance (asa) softwareSep 16, 2026
- CVE-2020-1107234Monitor
False-negative validation results in MINT transactions with invalid baton
HighCVSS 8.6No exploitEPSS 1%simpleledger · slp-validateMay 11, 2020
- CVE-2020-1107134Monitor
False-negative validation results in MINT transactions with invalid baton
HighCVSS 8.6No exploitEPSS 1%simpleledger · slpjsMay 11, 2020
- CVE-2026-2266034Monitor
FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
HighCVSS 8.6No exploitEPSS 1%flaskbb · flaskbbJul 10, 2026
- CVE-2026-6720734Monitor
Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
HighCVSS 8.7No exploitEPSS 1%wolfcms · wolfcmsJul 30, 2026
- CVE-2026-4803233Monitor
Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
HighCVSS 8.3No exploitEPSS 1%kerberosmansour · hulumiJul 24, 2026