Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-697

Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect.

159
Assigned CVEs
139th
Commonality Rank
7.1
Avg CVSS
1.3%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-697 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2005
20 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

159 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-5217CRITICAL
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a
Jul 10, 20249.898YESYES
CVE-2020-5849HIGH
Unraid 6.8.0 allows authentication bypass.
Mar 16, 20207.597YESYES
CVE-2025-3102HIGH
The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty va
Apr 10, 20258.185NOYES
CVE-2020-8864HIGH
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authe
Mar 23, 20208.871NONO
CVE-2023-32571CRITICAL
Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed
Jun 22, 20239.843NONO
CVE-2026-55771HIGH
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals
Jul 13, 20268.838NONO
CVE-2026-44249HIGH
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass
Jun 11, 20268.137NONO
CVE-2025-54336CRITICAL
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any othe
Aug 19, 20259.834NONO
CVE-2026-49340HIGH
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticat
Jun 19, 20268.133NONO
CVE-2021-44971CRITICAL
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sen
Jan 28, 20229.833NONO
View all 159 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
29%
19%
5.0-5.9
13%
16%
6.0-6.9
28%
26%
7.0-7.9
13%
11%
8.0-8.9
14%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
2 CVEs
1.3% of CVEs· 92nd percentile
Metasploit
2 CVEs
1.3% of CVEs· 90th percentile
Nuclei
2 CVEs
1.3% of CVEs· 87th percentile
ExploitDB
1 CVE
0.6% of CVEs· 77th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products