İçeriğe atla
Noroxi

CWE-697 · 126 kayıt

Incorrect Comparison

Bu sınıftaki CVE’ler

126 kayıt

  • Unraid 6.8.0 allows authentication bypass.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %93

    unraid · unraid16 Mar 2020

  • CVE-2020-8864
    59Planlayın

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-

    YüksekCVSS 8,8İstismar yokEPSS %80

    dlink · dir-878 firmware23 Mar 2020

  • CVE-2025-3102
    55Planlayın

    SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

    YüksekCVSS 8,1SilahlaştırılmışEPSS %76

    brainstormforce · ottokit: all-in-one automation platform10 Nis 2025

  • CVE-2023-32571
    49Planlayın

    Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods in

    KritikCVSS 9,8Kavram kanıtıEPSS %35

    dynamic-linq · linq22 Haz 2023

  • CVE-2021-35973
    40Planlayın

    NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthent

    KritikCVSS 9,8İstismar yokEPSS %3

    netgear · wac104 firmware30 Haz 2021

  • CVE-2021-44971
    40Planlayın

    Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_mul

    KritikCVSS 9,8İstismar yokEPSS %2

    tenda · ac15 firmware28 Oca 2022

  • CVE-2020-8862
    39İzleyin

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0

    YüksekCVSS 8,8İstismar yokEPSS %13

    dlink · dap-2610 firmware21 Şub 2020

  • CVE-2020-23360
    39İzleyin

    oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the che

    KritikCVSS 9,8İstismar yokEPSS %1

    oscommerce · oscommerce27 Oca 2021

  • CVE-2020-23359
    39İzleyin

    WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden

    KritikCVSS 9,8İstismar yokEPSS %1

    webidsupport · webid27 Oca 2021

  • CVE-2024-24621
    39İzleyin

    Softaculous Webuzo Authentication Bypass

    KritikCVSS 9,8İstismar yokEPSS %1

    softaculous · webuzo25 Tem 2024

  • CVE-2021-3833
    39İzleyin

    Integria IMS incorrect authorization

    KritikCVSS 9,8İstismar yokEPSS %1

    artica · integria ims7 Eki 2021

  • CVE-2022-47034
    39İzleyin

    A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

    KritikCVSS 9,8İstismar yokEPSS %1

    playsms · playsms13 Şub 2023

  • CVE-2014-125057
    39İzleyin

    mrobit robitailletheknot CSRF Token filters.php comparison

    KritikCVSS 9,8İstismar yokEPSS %1

    robitailletheknot project · robitailletheknot7 Oca 2023

  • CVE-2025-54336
    39İzleyin

    In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison.

    KritikCVSS 9,8İstismar yokEPSS %1

    19 Ağu 2025

  • CVE-2026-75110
    37İzleyin

    MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET

    KritikCVSS 9,3İstismar yokEPSS %1

    memtensor · memos17 Ağu 2026

  • CVE-2025-48952
    37İzleyin

    NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP

    KritikCVSS 9,4İstismar yokEPSS %1

    netalertx · netalertx4 Tem 2025

  • CVE-2022-43621
    36İzleyin

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers.

    YüksekCVSS 8,8İstismar yokEPSS %2

    dlink · dir-1935 firmware29 Mar 2023

  • CVE-2020-13485
    36İzleyin

    The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.

    KritikCVSS 9,1İstismar yokEPSS %1

    verbb · knock knock25 May 2020

  • CVE-2026-73309
    36İzleyin

    XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint

    KritikCVSS 9,1Kavram kanıtıEPSS %1

    xenforo · xenforo8 Eyl 2026

  • CVE-2026-20333
    35İzleyin

    Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - In

    YüksekCVSS 8,8İstismar yokEPSS %0

    cisco · cisco secure firewall adaptive security appliance (asa) software16 Eyl 2026

  • CVE-2020-11072
    34İzleyin

    False-negative validation results in MINT transactions with invalid baton

    YüksekCVSS 8,6İstismar yokEPSS %1

    simpleledger · slp-validate11 May 2020

  • CVE-2020-11071
    34İzleyin

    False-negative validation results in MINT transactions with invalid baton

    YüksekCVSS 8,6İstismar yokEPSS %1

    simpleledger · slpjs11 May 2020

  • CVE-2026-22660
    34İzleyin

    FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint

    YüksekCVSS 8,6İstismar yokEPSS %1

    flaskbb · flaskbb10 Tem 2026

  • CVE-2026-67207
    34İzleyin

    Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController

    YüksekCVSS 8,7İstismar yokEPSS %1

    wolfcms · wolfcms30 Tem 2026

  • CVE-2026-48032
    33İzleyin

    Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers

    YüksekCVSS 8,3İstismar yokEPSS %1

    kerberosmansour · hulumi24 Tem 2026

Tüm zafiyet sınıfları