CWE-697— Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.— MITRE CWE catalog
195 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-697page 2 of 4
- CVE-2024-41657HIGHCVSS 8.1EG 8.12024-08-20
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests t…
- CVE-2024-39742HIGHCVSS 8.1EG 8.12024-07-08
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.
- CVE-2024-2223HIGHCVSS 8.1EG 8.12024-04-09
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerab…
- CVE-2021-44078HIGHCVSS 8.1EG 8.12021-12-26
An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It allows local attackers to escape the sandbox. An attacker must first obtain the ability to execute crafted code in the target sandbox in order to exploi…
- CVE-2022-35962HIGHCVSS 8.0EG 8.02022-08-29
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows…
- CVE-2023-46009HIGHCVSS 7.8EG 7.82023-10-18
gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.
- CVE-2020-10027HIGHCVSS 7.8EG 7.82020-05-11
An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later …
- CVE-2020-10024HIGHCVSS 7.8EG 7.82020-05-11
The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This…
- CVE-2026-71855HIGHCVSS 7.5EG 7.52026-09-18
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when …
- CVE-2026-49846HIGHCVSS 7.5EG 7.52026-09-11
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The …
- CVE-2026-10097HIGHCVSS 7.5EG 7.52026-06-25
wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during the Fujisaki-Okamoto re-encryption check in ML-KEM-1024 decapsulation. Ciphertexts that differ from the expected re-encr…
- CVE-2026-26275HIGHCVSS 7.5EG 7.52026-02-19
httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to version 0.0.23 where Digest header verification could incorrectly succeed due to misuse of Rust's `matches!` macro. Specifi…
- CVE-2024-4032HIGHCVSS 7.5EG 7.52024-06-17
The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.I…
- CVE-2024-37131HIGHCVSS 7.5EG 7.52024-06-13
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious action…
- CVE-2023-40271HIGHCVSS 7.5EG 7.52023-09-08
In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algor…
- CVE-2023-41936HIGHCVSS 7.5EG 7.52023-09-06
Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.
- CVE-2023-41935HIGHCVSS 7.5EG 7.52023-09-06
Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing atta…
- CVE-2023-22435HIGHCVSS 7.5EG 7.52023-07-13
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
- CVE-2023-27579HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an end-to-end open source platform for machine learning. Constructing a tflite model with a paramater `filter_input_channel` of less than 1 gives a FPE. This issue has been patched in version 2.12. TensorFlow will also cherry…
- CVE-2023-25675HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.Bincount` segfaults when given a parameter `weights` that is neither the same shape as parameter `arr` nor a len…
- CVE-2023-25673HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
- CVE-2023-25669HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for `tf.raw_ops.AvgPoolGrad`, it can give a floating point exception. A fix is included in Tens…
- CVE-2023-25666HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
- CVE-2022-24787HIGHCVSS 7.5EG 7.52022-04-04
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word comparisons giving incorrect results. Even without dirty non…
- CVE-2021-41500HIGHCVSS 7.5EG 7.52021-12-17
Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attack…
- CVE-2021-3828HIGHCVSS 7.5EG 7.52021-09-27
nltk is vulnerable to Inefficient Regular Expression Complexity
- CVE-2020-23478HIGHCVSS 7.5EG 7.52021-09-22
Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.
- CVE-2021-37550HIGHCVSS 7.5EG 7.52021-08-06
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
- CVE-2021-3649HIGHCVSS 7.5EG 7.52021-07-16
chatwoot is vulnerable to Inefficient Regular Expression Complexity
- CVE-2021-27293HIGHCVSS 7.5EG 7.52021-07-12
RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp …
- CVE-2021-35970HIGHCVSS 7.5EG 7.52021-06-30
Talk 4 in Coral before 4.12.1 allows remote attackers to discover e-mail addresses and other sensitive information via GraphQL because permission checks use an incorrect data type.
- CVE-2020-1920HIGHCVSS 7.5EG 7.52021-06-01
A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed …
- CVE-2020-22784HIGHCVSS 7.5EG 7.52021-04-28
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
- CVE-2020-23355HIGHCVSS 7.5EG 7.52021-01-27
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, …
- CVE-2020-13559HIGHCVSS 7.5EG 7.52021-01-11
A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An attacker can send a malicious packet to tr…
- CVE-2021-3116HIGHCVSS 7.5EG 7.52021-01-11
before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authorization header data because of a boolean confusion (and versus or).
- CVE-2019-20925HIGHCVSS 7.5EG 7.52020-11-24
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.…
- CVE-2020-25696HIGHCVSS 7.5EG 7.52020-11-23
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server…
- CVE-2020-15131HIGHCVSS 7.5EG 7.52020-07-30
In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could cr…
- CVE-2020-15130HIGHCVSS 7.5EG 7.52020-07-30
In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemin…
- CVE-2016-10003HIGHCVSS 7.5EG 7.52017-01-27
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple …
- CVE-2005-2801HIGHCVSS 7.5EG 7.52005-09-06
xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.
- CVE-2021-23146HIGHCVSS 7.1EG 7.52021-11-18
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior…
- CVE-2026-22660HIGHCVSS 7.2EG 7.22026-07-10
FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a type mismatch in the bulk delete protection check. The…
- CVE-2023-33225HIGHCVSS 7.2EG 7.22023-07-26
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
- CVE-2023-23844HIGHCVSS 7.2EG 7.22023-07-26
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
- CVE-2023-23843HIGHCVSS 7.2EG 7.22023-07-26
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2026-61672HIGHCVSS 7.1EG 7.12026-09-18
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes …
- CVE-2026-71892MEDIUMCVSS 6.9EG 6.92026-10-03
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption k…
- CVE-2026-61795MEDIUMCVSS 6.8EG 6.82026-09-18
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validates …
Map vulnerabilities like CWE-697 to your infrastructure
EchelonGraph correlates every CVE — across CWE-697 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →