CWE-697 · 126 записей
Incorrect Comparison
CVE этого класса
126 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
88Срочно | CVE-2020-5849Готовый эксплойт | Unraid 6.8.0 allows authentication bypass.unraid · unraid · CWE-697 | Высокая7,5 | KEV | 93,2 % | 16 мар. 2020 г. |
59В плане | CVE-2020-8864Эксплойта нет | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-dlink · dir-878 firmware · CWE-697 | Высокая8,8 | — | 80,2 % | 23 мар. 2020 г. |
55В плане | CVE-2025-3102Готовый эксплойт | SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creationbrainstormforce · ottokit: all-in-one automation platform · CWE-697 | Высокая8,1 | — | 76,2 % | 10 апр. 2025 г. |
49В плане | CVE-2023-32571Proof of concept | Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods indynamic-linq · linq · CWE-697 | Критическая9,8 | — | 34,9 % | 22 июн. 2023 г. |
40В плане | CVE-2021-35973Эксплойта нет | NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthentnetgear · wac104 firmware · CWE-697 | Критическая9,8 | — | 3,1 % | 30 июн. 2021 г. |
40В плане | CVE-2021-44971Эксплойта нет | Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multenda · ac15 firmware · CWE-697 | Критическая9,8 | — | 2,1 % | 28 янв. 2022 г. |
39Наблюдать | CVE-2020-8862Эксплойта нет | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0dlink · dap-2610 firmware · CWE-697 | Высокая8,8 | — | 13,3 % | 21 февр. 2020 г. |
39Наблюдать | CVE-2020-23360Эксплойта нет | oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the cheoscommerce · oscommerce · CWE-697 | Критическая9,8 | — | 1,2 % | 27 янв. 2021 г. |
39Наблюдать | CVE-2020-23359Эксплойта нет | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the idenwebidsupport · webid · CWE-697 | Критическая9,8 | — | 1,2 % | 27 янв. 2021 г. |
39Наблюдать | CVE-2024-24621Эксплойта нет | Softaculous Webuzo Authentication Bypasssoftaculous · webuzo · CWE-697 | Критическая9,8 | — | 1,2 % | 25 июл. 2024 г. |
39Наблюдать | CVE-2021-3833Эксплойта нет | Integria IMS incorrect authorizationartica · integria ims · CWE-697 | Критическая9,8 | — | 1,1 % | 7 окт. 2021 г. |
39Наблюдать | CVE-2022-47034Эксплойта нет | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.playsms · playsms · CWE-697 | Критическая9,8 | — | 0,8 % | 13 февр. 2023 г. |
39Наблюдать | CVE-2014-125057Эксплойта нет | mrobit robitailletheknot CSRF Token filters.php comparisonrobitailletheknot project · robitailletheknot · CWE-697 | Критическая9,8 | — | 0,8 % | 7 янв. 2023 г. |
39Наблюдать | CVE-2025-54336Эксплойта нет | In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison.CWE-697 | Критическая9,8 | — | 0,5 % | 19 авг. 2025 г. |
37Наблюдать | CVE-2026-75110Эксплойта нет | MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRETmemtensor · memos · CWE-697 | Критическая9,3 | — | 0,7 % | 17 авг. 2026 г. |
37Наблюдать | CVE-2025-48952Эксплойта нет | NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHPnetalertx · netalertx · CWE-697 | Критическая9,4 | — | 0,6 % | 4 июл. 2025 г. |
36Наблюдать | CVE-2022-43621Эксплойта нет | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-697 | Высокая8,8 | — | 2,1 % | 29 мар. 2023 г. |
36Наблюдать | CVE-2020-13485Эксплойта нет | The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.verbb · knock knock · CWE-697 | Критическая9,1 | — | 1,4 % | 25 мая 2020 г. |
36Наблюдать | CVE-2026-73309Proof of concept | XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpointxenforo · xenforo · CWE-697 | Критическая9,1 | — | 0,7 % | 8 сент. 2026 г. |
35Наблюдать | CVE-2026-20333Эксплойта нет | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incisco · cisco secure firewall adaptive security appliance (asa) software · CWE-697 | Высокая8,8 | — | 0,3 % | 16 сент. 2026 г. |
34Наблюдать | CVE-2020-11072Эксплойта нет | False-negative validation results in MINT transactions with invalid batonsimpleledger · slp-validate · CWE-697 | Высокая8,6 | — | 1,0 % | 11 мая 2020 г. |
34Наблюдать | CVE-2020-11071Эксплойта нет | False-negative validation results in MINT transactions with invalid batonsimpleledger · slpjs · CWE-697 | Высокая8,6 | — | 0,9 % | 11 мая 2020 г. |
34Наблюдать | CVE-2026-22660Эксплойта нет | FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpointflaskbb · flaskbb · CWE-697 | Высокая8,6 | — | 0,6 % | 10 июл. 2026 г. |
34Наблюдать | CVE-2026-67207Эксплойта нет | Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreControllerwolfcms · wolfcms · CWE-697 | Высокая8,7 | — | 0,5 % | 30 июл. 2026 г. |
33Наблюдать | CVE-2026-48032Эксплойта нет | Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providerskerberosmansour · hulumi · CWE-697 | Высокая8,3 | — | 0,5 % | 24 июл. 2026 г. |
- CVE-2020-584988Срочно
Unraid 6.8.0 allows authentication bypass.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 93 %unraid · unraid16 мар. 2020 г.
- CVE-2020-886459В плане
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-
ВысокаяCVSS 8,8Эксплойта нетEPSS 80 %dlink · dir-878 firmware23 мар. 2020 г.
- CVE-2025-310255В плане
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
ВысокаяCVSS 8,1Готовый эксплойтEPSS 76 %brainstormforce · ottokit: all-in-one automation platform10 апр. 2025 г.
- CVE-2023-3257149В плане
Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods in
КритическаяCVSS 9,8Proof of conceptEPSS 35 %dynamic-linq · linq22 июн. 2023 г.
- CVE-2021-3597340В плане
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthent
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %netgear · wac104 firmware30 июн. 2021 г.
- CVE-2021-4497140В плане
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_mul
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tenda · ac15 firmware28 янв. 2022 г.
- CVE-2020-886239Наблюдать
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0
ВысокаяCVSS 8,8Эксплойта нетEPSS 13 %dlink · dap-2610 firmware21 февр. 2020 г.
- CVE-2020-2336039Наблюдать
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the che
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oscommerce · oscommerce27 янв. 2021 г.
- CVE-2020-2335939Наблюдать
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %webidsupport · webid27 янв. 2021 г.
- CVE-2024-2462139Наблюдать
Softaculous Webuzo Authentication Bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %softaculous · webuzo25 июл. 2024 г.
- CVE-2021-383339Наблюдать
Integria IMS incorrect authorization
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %artica · integria ims7 окт. 2021 г.
- CVE-2022-4703439Наблюдать
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %playsms · playsms13 февр. 2023 г.
- CVE-2014-12505739Наблюдать
mrobit robitailletheknot CSRF Token filters.php comparison
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %robitailletheknot project · robitailletheknot7 янв. 2023 г.
- CVE-2025-5433639Наблюдать
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %19 авг. 2025 г.
- CVE-2026-7511037Наблюдать
MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %memtensor · memos17 авг. 2026 г.
- CVE-2025-4895237Наблюдать
NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %netalertx · netalertx4 июл. 2025 г.
- CVE-2022-4362136Наблюдать
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2020-1348536Наблюдать
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %verbb · knock knock25 мая 2020 г.
- CVE-2026-7330936Наблюдать
XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
КритическаяCVSS 9,1Proof of conceptEPSS 1 %xenforo · xenforo8 сент. 2026 г.
- CVE-2026-2033335Наблюдать
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - In
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %cisco · cisco secure firewall adaptive security appliance (asa) software16 сент. 2026 г.
- CVE-2020-1107234Наблюдать
False-negative validation results in MINT transactions with invalid baton
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %simpleledger · slp-validate11 мая 2020 г.
- CVE-2020-1107134Наблюдать
False-negative validation results in MINT transactions with invalid baton
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %simpleledger · slpjs11 мая 2020 г.
- CVE-2026-2266034Наблюдать
FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %flaskbb · flaskbb10 июл. 2026 г.
- CVE-2026-6720734Наблюдать
Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %wolfcms · wolfcms30 июл. 2026 г.
- CVE-2026-4803233Наблюдать
Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %kerberosmansour · hulumi24 июл. 2026 г.