The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required.
Volume of CVEs assigned to CWE-694 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13609HIGH A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claimin | Nov 24, 2025 | 8.2 | 30 | NO | NO |
CVE-2025-59048HIGH OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AWS | Oct 23, 2025 | 8.1 | 27 | NO | NO |
CVE-2026-57024MEDIUM A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, | Jul 9, 2026 | 5.3 | 25 | NO | NO |
CVE-2026-5794MEDIUM A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted r | Apr 28, 2026 | 4.9 | 23 | NO | NO |
CVE-2023-20100MEDIUM A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Contr | Mar 23, 2023 | 6.8 | 23 | NO | NO |
CVE-2021-3436MEDIUM BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known. Zephyr versions >= 1.14.2, >= 2.4.0, >= 2.5.0 contain Use | Oct 5, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-15187MEDIUM In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one always used. If a plugin is compromised, this lowers the level | Sep 17, 2020 | 4.7 | 19 | NO | NO |
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned | Apr 25, 2023 | 3.3 | 16 | NO | NO |
CVE-2024-41146MEDIUM Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS communicatio | Dec 12, 2024 | 4.6 | 15 | NO | NO |
In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers th | Sep 17, 2020 | 2.7 | 15 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.