VYPR

CWE-697

Incorrect Comparison

PillarIncomplete

Description

The product compares two entities in a security-relevant context, but the comparison is incorrect.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-120 · CAPEC-14 · CAPEC-15 · CAPEC-182 · CAPEC-24 · CAPEC-267 · CAPEC-3 · CAPEC-41 · CAPEC-43 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-88 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (199)

page 10 of 10
  • CVE-2024-5528LowFeb 5, 2025
    risk 0.16cvss 3.5epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

  • CVE-2014-125057LowJan 7, 2023
    risk 0.13cvss 3.1epss 0.01

    A vulnerability was found in mrobit robitailletheknot. It has been classified as problematic. This affects an unknown part of the file app/filters.php of the component CSRF Token Handler. The manipulation of the argument _token leads to incorrect comparison. It is possible to…

  • CVE-2026-80227LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the…

  • CVE-2024-53861LowNov 29, 2024
    risk 0.07cvss 2.2epss 0.01

    pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim changed from `isinstance(issuer, list)` to…

  • CVE-2026-67207HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.01

    Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can…

  • CVE-2026-55771HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted null/self branches which could lead to incorrect equality comparisons. The…

  • CVE-2026-22660HigJul 10, 2026
    risk 0.00cvss 7.2epss 0.01

    FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a type mismatch in the bulk delete protection check. The bulk AJAX endpoint in the management…

  • CVE-2026-14687MedJul 5, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impacted is the function _deduplicate_results of the file InsightEngine/agent.py of the component InsightEngine search-result Deduplication. Executing a manipulation can lead to partial string comparison. The attack…

  • CVE-2026-14617LowJul 3, 2026
    risk 0.00cvss 3.1epss 0.00

    A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming Reasoning Tag Filter. The manipulation leads to…

  • CVE-2026-21691MedJan 7, 2026
    risk 0.00cvss 5.4epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccTag:IsTypeCompressed()`. This…

  • CVE-2024-41958MedAug 5, 2024
    risk 0.00cvss 6.6epss 0.01

    mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated attacker to bypass the 2FA protection, enabling unauthorized access to other…

  • CVE-2024-38522MedJun 28, 2024
    risk 0.00cvss 6.3epss 0.00

    Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the `tips.hushline.app` website and bundled by default in this repository is trivial to bypass. This vulnerability has been patched in version 0.1.0.

  • CVE-2023-46656MedOct 25, 2023
    risk 0.00cvss 5.3epss 0.01

    Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2022-47034CriFeb 13, 2023
    risk 0.00cvss 9.8epss 0.01

    A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

  • CVE-2022-4293MedDec 5, 2022
    risk 0.00cvss 5.5epss 0.00

    Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

  • CVE-2022-39308MedOct 14, 2022
    risk 0.00cvss 6.5epss 0.01

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions from 19.2.0 to 19.10.0 (inclusive) are subject to a timing attack in validation of access tokens due to use of regular…

  • CVE-2022-26691MedMay 26, 2022
    risk 0.00cvss 6.7epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.

  • CVE-2022-24787HigApr 4, 2022
    risk 0.00cvss 7.5epss 0.01

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word comparisons giving incorrect results. Even without dirty nonzero bytes, two bytestrings can compare…

  • CVE-2011-3903Dec 13, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 16.0.912.63 does not properly perform regex matching, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.