The product compares two entities in a security-relevant context, but the comparison is incorrect.
Volume of CVEs assigned to CWE-697 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
159 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5217CRITICAL ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a | Jul 10, 2024 | 9.8 | 98 | YES | YES |
CVE-2020-5849HIGH Unraid 6.8.0 allows authentication bypass. | Mar 16, 2020 | 7.5 | 97 | YES | YES |
CVE-2025-3102HIGH The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty va | Apr 10, 2025 | 8.1 | 85 | NO | YES |
CVE-2020-8864HIGH This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authe | Mar 23, 2020 | 8.8 | 71 | NO | NO |
CVE-2023-32571CRITICAL Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed | Jun 22, 2023 | 9.8 | 43 | NO | NO |
CVE-2026-55771HIGH CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals | Jul 13, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-44249HIGH Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass | Jun 11, 2026 | 8.1 | 37 | NO | NO |
CVE-2025-54336CRITICAL In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any othe | Aug 19, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-49340HIGH gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticat | Jun 19, 2026 | 8.1 | 33 | NO | NO |
CVE-2021-44971CRITICAL Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sen | Jan 28, 2022 | 9.8 | 33 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.