CWE-697: Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.
78 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-3102 — SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
- CVE-2024-24621 — Softaculous Webuzo Authentication Bypass
- CVE-2025-48952 — NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP
- CVE-2024-34340 — Authentication Bypass when using using older password hashes
- CVE-2025-20343 — Cisco Identity Services Engine Radius Suppression Denial of Service Vulnerability
- CVE-2024-29026 — Owncast cross origin request
- CVE-2026-75110 — MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
- CVE-2026-47202 — Kavita: Pre-Auth Account Takeover
- CVE-2026-73309 — XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
- CVE-2026-44196 — Pingvin Share X: TOTP Authentication Bypass via Password-only Login
- CVE-2026-26275 — httpsig-hyper has Improper Digest Verification that May Allow Message Integrity Bypass
- CVE-2026-55771 — CedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities
- CVE-2026-67207 — Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
- CVE-2026-22660 — FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
- CVE-2026-48032 — Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
- CVE-2026-10097 — ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery
- CVE-2026-45567 — Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
- CVE-2026-44249 — Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
- CVE-2026-18664 — Wrong interpretation of ACL ranges
- CVE-2026-49340 — gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
Recently published
- CVE-2026-56101 — OpenBSD ieee80211_crypto_tkip.c TKIP MIC Countermeasure Logic Inversion DoS
- CVE-2026-73309 — XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
- CVE-2026-80227 — SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
- CVE-2026-18664 — Wrong interpretation of ACL ranges
- CVE-2026-73258 — Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart
- CVE-2026-75110 — MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
- CVE-2026-50029 — js-toml has silent type confusion via falsy-primitive duplicate-key bypass
- CVE-2026-20765 — Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allo
- CVE-2026-67207 — Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
- CVE-2026-48032 — Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
- CVE-2026-65903 — DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS
- CVE-2026-55771 — CedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities
- CVE-2026-22660 — FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
- CVE-2026-59890 — setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
- CVE-2026-14687 — 666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
- CVE-2026-14686 — HdrHistogram Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison
- CVE-2026-14617 — NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivity
- CVE-2026-10097 — ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery
- CVE-2026-49340 — gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
- CVE-2026-44249 — Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking