CWE-697: CWE-697

20
Total CVEs
6
Critical
11
High
8.0
Avg CVSS

Yearly Trend

2025
4
2024
3
2023
7
2021
6

Top Affected Vendors

1 Google 2
2 Unicorn Engine 1
3 Etherpad 1
4 Cvxopt Project 1
5 Voxmedia 1
6 Linux 1
7 Fedoraproject 1
8 Cisco 1
9 Netgear 1
10 Jenkins 1

All CWE-697 CVEs (20)

CVE-2024-24621
9.8

Softaculous Webuzo contains an authentication bypass vulnerability in its password reset functionality that allows remote, unauthenticated attackers t...

Jul 25, 2024
CVE-2023-32571
9.8

CVE-2023-32571 is a remote code execution vulnerability in Dynamic LINQ libraries where untrusted input to methods like Where, Select, and OrderBy can...

Jun 22, 2023
CVE-2022-47034
9.8

A type juggling vulnerability in PlaySMS v1.4.5 and earlier allows attackers to bypass authentication by exploiting PHP's loose comparison operators. ...

Feb 13, 2023
CVE-2021-35973
9.8

This vulnerability allows unauthenticated attackers to bypass authentication on NETGEAR WAC104 wireless access points by adding a specific substring t...

Jun 30, 2021
CVE-2020-23359
9.8

This vulnerability in WeBid 1.2.2 allows attackers to bypass password confirmation during user registration due to improper loose comparison. This aff...

Jan 27, 2021
CVE-2025-48952
9.4

This CVE describes an authentication bypass vulnerability in NetAlertX where attackers can log in without valid credentials using specially crafted 'm...

Jul 4, 2025
CVE-2025-20343
8.6

An unauthenticated remote attacker can cause Cisco Identity Services Engine (ISE) to restart unexpectedly by sending crafted RADIUS access request mes...

Nov 5, 2025
CVE-2025-3102
EPSS 86.9% 8.1

The SureTriggers WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create administrator accounts. T...

Apr 10, 2025
CVE-2021-44078
8.1

This vulnerability in Unicorn Engine allows attackers to escape sandbox restrictions and execute arbitrary code on the host system. It affects systems...

Dec 26, 2021
CVE-2023-46009
7.8

CVE-2023-46009 is a floating point exception vulnerability in gifsicle's resize_stream function that can cause denial of service through application c...

Oct 18, 2023
CVE-2023-41935
7.5

This vulnerability in Jenkins Azure AD Plugin allows attackers to potentially bypass CSRF protection through timing attacks. By exploiting non-constan...

Sep 6, 2023
CVE-2023-22435
7.5

This vulnerability allows remote attackers to cause a denial-of-service (DoS) condition on Experion servers by sending specially crafted messages that...

Jul 13, 2023
CVE-2023-27579
7.5

This CVE describes a floating-point exception (FPE) vulnerability in TensorFlow's TFLite component when constructing models with a filter_input_channe...

Mar 25, 2023
CVE-2023-25666
7.5

This CVE describes a floating point exception vulnerability in TensorFlow's AudioSpectrogram function. Attackers can cause denial of service by trigge...

Mar 25, 2023
CVE-2021-41500
7.5

An incomplete string comparison vulnerability in cvxopt versions up to 1.2.6 allows attackers to create fake Capsule objects that can crash affected a...

Dec 17, 2021
CVE-2021-35970
7.5

CVE-2021-35970 is an information disclosure vulnerability in Coral Talk's GraphQL API where incorrect data type usage in permission checks allows unau...

Jun 30, 2021
CVE-2020-22784
7.5

This vulnerability in Etherpad's UeberDB MySQL connector allows attackers to bypass access controls by exploiting MySQL's behavior of omitting trailin...

Apr 28, 2021
CVE-2024-41958
6.6

This vulnerability allows authenticated attackers to bypass two-factor authentication (2FA) in mailcow: dockerized email systems. Attackers need crede...

Aug 5, 2024
CVE-2021-47370
5.5

A signed/unsigned integer comparison bug in the Linux kernel's MPTCP implementation causes TCP packets to lack required MPTCP extensions when transmit...

May 21, 2024
CVE-2025-12192
5.3

The Events Calendar WordPress plugin versions up to 6.15.9 have an information disclosure vulnerability where unauthenticated attackers can obtain ful...

Nov 5, 2025

About CWE-697 (CWE-697)

Our database tracks 20 CVEs classified as CWE-697, with 6 rated critical and 11 rated high severity. The average CVSS score for CWE-697 vulnerabilities is 8.0.

External reference: View CWE-697 on MITRE CWE →

Monitor CWE-697 Vulnerabilities

Get alerted when new CWE-697 CVEs affect your infrastructure.

Start Monitoring Free