CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

211 vulnerabilities with CWE-494
CVE-2026-66398 CRITICAL
phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API
CVE-2026-50562 CRITICAL
FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows
CVE-2026-55698 HIGH
pnpm < 10.34.2 and 11.0.0-11.5.2 - Lockfile-Selected Code Execution
CVSS 8.8
CVE-2026-55697 HIGH
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVSS 7.5
CVE-2026-49241 HIGH
Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code Extension
CVSS 8.8
CVE-2026-9037 CRITICAL
Download of code without integrity check in XCharge C6
CVE-2026-45058 CRITICAL
electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
CVE-2026-9089 HIGH
ConnectWise Automate < 2026.5 - Download of Code Without Integrity Check
CVSS 8.8
CVE-2026-42575 HIGH
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
CVSS 7.5
CVE-2026-32148 MEDIUM
Lockfile checksums not verified in Hex allows dependency integrity bypass
CVSS 5.9
CVE-2026-42249 CRITICAL
Remote Code Execution in Ollama via Update Mechanism
CVSS 9.8
CVE-2026-42248 CRITICAL
Missing Signature Verification for Updates in Ollama
CVSS 9.8
CVE-2026-40066 HIGH
Anviz Products Download of Code Without Integrity Check
CVSS 8.8
CVE-2026-3428 MEDIUM
ASUS Member Center < 1.6.6.4 - Privilege Escalation via Time-of-check Time-of-use Race Condition
CVE-2026-34841 CRITICAL
Axios npm Supply Chain Incident Impacting @usebruno/cli
CVSS 9.8
CVE-2026-30603 MEDIUM
Qianniao QN-L23PA0904 v20250721.1640 - Privilege Escalation
CVSS 6.8
CVE-2026-3502 HIGH KEV
TrueConf Client Update Integrity Verification Bypass
CVSS 7.8
CVE-2026-33075 HIGH
FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml
CVSS 8.8
CVE-2026-28500 HIGH
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVSS 8.6
CVE-2026-1878 MEDIUM
ASUS ROG Driver - Privilege Escalation
CVE-2026-3000 CRITICAL
IDExpert 2.7.3.230719-2.8.4.250925 - Unauthenticated Remote Code Execution via Arbitrary DLL Download
CVSS 9.8
CVE-2026-2999 CRITICAL
IDExpert 2.7.3.230719-2.8.4.250925 - Unauthenticated Remote Code Execution via Arbitrary Executable Download
CVSS 9.8
CVE-2026-27180 CRITICAL
MajorDoMo - Unauthenticated Remote Code Execution via Update URL Poisoning
CVSS 9.8
CVE-2026-25961 HIGH
SumatraPDF 3.5.0-3.5.2 - Remote Code Execution via Update Mechanism TLS Hostname Verification Bypass
CVSS 7.5
CVE-2026-20056 MEDIUM
Cisco Secure Web Appliance - Unauthenticated Malware Archive Bypass via Dynamic Vectoring and Streaming Engine
CVSS 4.0
Details
Vulnerabilities 211
Exploit Likelihood Medium