The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.
Volume of CVEs assigned to CWE-1023 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7473MEDIUM On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) t | Jun 5, 2026 | 5.8 | 69 | YES | NO |
CVE-2026-4599CRITICAL Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigInt | Mar 23, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-48761MEDIUM Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAt | Jul 14, 2026 | 6.1 | 28 | NO | NO |
CVE-2026-53839MEDIUM OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can expl | Jun 12, 2026 | 6.5 | 28 | NO | NO |
CVE-2026-48587MEDIUM An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
`django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` | Jun 3, 2026 | 5.3 | 26 | NO | NO |
CVE-2026-4748HIGH A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently | Apr 1, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-53859MEDIUM OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived | Jun 16, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-62000HIGH BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection method that evaluates file content based on header bytes. An | Dec 18, 2025 | 7.1 | 24 | NO | NO |
CVE-2021-23146HIGH An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre | Nov 18, 2021 | 7.5 | 24 | NO | NO |
CVE-2025-46722HIGH vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHash | May 29, 2025 | 7.3 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.