The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.
Volume of CVEs assigned to CWE-187 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41110CRITICAL Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow a | Jul 24, 2024 | 9.9 | 41 | NO | NO |
CVE-2026-55602HIGH http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or hos | Jun 22, 2026 | 8.6 | 34 | NO | NO |
CVE-2026-35031HIGH Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), wher | Apr 14, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-34785HIGH Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2024-39742CRITICAL IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-F | Jul 8, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-31802CRITICAL In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perfor | Jun 24, 2022 | 9.8 | 29 | NO | NO |
CVE-2026-44837HIGH view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a us | May 26, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-14687MEDIUM A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impacted is the function _deduplicate_results of the file InsightEngine/agent.py of the component InsightEngine sear | Jul 5, 2026 | 5.3 | 26 | NO | NO |
CVE-2026-30874HIGH OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass envi | Mar 19, 2026 | 7.8 | 25 | NO | NO |
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the pa | Jun 23, 2026 | 3.8 | 23 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.