MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=
Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authentic
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, om
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to vers
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e
httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to vers
wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during t
FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administra
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage retur
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to
DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden t
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for B
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard
A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impacted is the function _deduplicate_results of the fil
js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in
Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allo
A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function Gatewa
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unau
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P
When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address
Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriag
Frequently Asked Questions
What is CWE-697?
CWE-697 (CWE-697) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-697?
There are 30 CVE records associated with CWE-697 in our database. Of these, 2 are critical severity, 10 are high severity, and 11 are medium severity.
How can I protect against CWE-697 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-697 using AI-powered security agents.
Detect CWE-697 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-697 vulnerabilities across your infrastructure.
Get Started