Skip to content
Noroxi

CWE-697 · 126 records

Incorrect Comparison

CVEs in this class

126 records

  • Unraid 6.8.0 allows authentication bypass.

    HighCVSS 7.5KEVWeaponizedEPSS 93%

    unraid · unraidMar 16, 2020

  • This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-

    HighCVSS 8.8No exploitEPSS 80%

    dlink · dir-878 firmwareMar 23, 2020

  • SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

    HighCVSS 8.1WeaponizedEPSS 76%

    brainstormforce · ottokit: all-in-one automation platformApr 10, 2025

  • Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods in

    CriticalCVSS 9.8Proof of conceptEPSS 35%

    dynamic-linq · linqJun 22, 2023

  • NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthent

    CriticalCVSS 9.8No exploitEPSS 3%

    netgear · wac104 firmwareJun 30, 2021

  • Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_mul

    CriticalCVSS 9.8No exploitEPSS 2%

    tenda · ac15 firmwareJan 28, 2022

  • CVE-2020-8862
    39Monitor

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0

    HighCVSS 8.8No exploitEPSS 13%

    dlink · dap-2610 firmwareFeb 21, 2020

  • oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the che

    CriticalCVSS 9.8No exploitEPSS 1%

    oscommerce · oscommerceJan 27, 2021

  • WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden

    CriticalCVSS 9.8No exploitEPSS 1%

    webidsupport · webidJan 27, 2021

  • Softaculous Webuzo Authentication Bypass

    CriticalCVSS 9.8No exploitEPSS 1%

    softaculous · webuzoJul 25, 2024

  • CVE-2021-3833
    39Monitor

    Integria IMS incorrect authorization

    CriticalCVSS 9.8No exploitEPSS 1%

    artica · integria imsOct 7, 2021

  • A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

    CriticalCVSS 9.8No exploitEPSS 1%

    playsms · playsmsFeb 13, 2023

  • mrobit robitailletheknot CSRF Token filters.php comparison

    CriticalCVSS 9.8No exploitEPSS 1%

    robitailletheknot project · robitailletheknotJan 7, 2023

  • In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison.

    CriticalCVSS 9.8No exploitEPSS 1%

    Aug 19, 2025

  • MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET

    CriticalCVSS 9.3No exploitEPSS 1%

    memtensor · memosAug 17, 2026

  • NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP

    CriticalCVSS 9.4No exploitEPSS 1%

    netalertx · netalertxJul 4, 2025

  • This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers.

    HighCVSS 8.8No exploitEPSS 2%

    dlink · dir-1935 firmwareMar 29, 2023

  • The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.

    CriticalCVSS 9.1No exploitEPSS 1%

    verbb · knock knockMay 25, 2020

  • XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint

    CriticalCVSS 9.1Proof of conceptEPSS 1%

    xenforo · xenforoSep 8, 2026

  • Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - In

    HighCVSS 8.8No exploitEPSS 0%

    cisco · cisco secure firewall adaptive security appliance (asa) softwareSep 16, 2026

  • False-negative validation results in MINT transactions with invalid baton

    HighCVSS 8.6No exploitEPSS 1%

    simpleledger · slp-validateMay 11, 2020

  • False-negative validation results in MINT transactions with invalid baton

    HighCVSS 8.6No exploitEPSS 1%

    simpleledger · slpjsMay 11, 2020

  • FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint

    HighCVSS 8.6No exploitEPSS 1%

    flaskbb · flaskbbJul 10, 2026

  • Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController

    HighCVSS 8.7No exploitEPSS 1%

    wolfcms · wolfcmsJul 30, 2026

  • Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers

    HighCVSS 8.3No exploitEPSS 1%

    kerberosmansour · hulumiJul 24, 2026

All vulnerability classes