CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

204 vulnerabilities with CWE-494
CVE-2026-9037 CRITICAL
Download of code without integrity check in XCharge C6
CVE-2026-45058 CRITICAL
electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
CVE-2026-9089 HIGH
ConnectWise Automate < 2026.5 - Download of Code Without Integrity Check
CVSS 8.8
CVE-2026-42575 HIGH
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
CVSS 7.5
CVE-2026-32148 MEDIUM
Lockfile checksums not verified in Hex allows dependency integrity bypass
CVSS 5.9
CVE-2026-42249 CRITICAL
Remote Code Execution in Ollama via Update Mechanism
CVSS 9.8
CVE-2026-42248 CRITICAL
Missing Signature Verification for Updates in Ollama
CVSS 9.8
CVE-2026-40066 HIGH
Anviz Products Download of Code Without Integrity Check
CVSS 8.8
CVE-2026-3428 MEDIUM
ASUS Member Center < 1.6.6.4 - Privilege Escalation via Time-of-check Time-of-use Race Condition
CVE-2026-34841 CRITICAL
Axios npm Supply Chain Incident Impacting @usebruno/cli
CVSS 9.8
CVE-2026-30603 MEDIUM
Qianniao QN-L23PA0904 v20250721.1640 - Privilege Escalation
CVSS 6.8
CVE-2026-3502 HIGH KEV
TrueConf Client Update Integrity Verification Bypass
CVSS 7.8
CVE-2026-33075 HIGH
FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml
CVSS 8.8
CVE-2026-28500 HIGH
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVSS 8.6
CVE-2026-1878 MEDIUM
ASUS ROG Driver - Privilege Escalation
CVE-2026-3000 CRITICAL
IDExpert 2.7.3.230719-2.8.4.250925 - Unauthenticated Remote Code Execution via Arbitrary DLL Download
CVSS 9.8
CVE-2026-2999 CRITICAL
IDExpert 2.7.3.230719-2.8.4.250925 - Unauthenticated Remote Code Execution via Arbitrary Executable Download
CVSS 9.8
CVE-2026-27180 CRITICAL
MajorDoMo - Unauthenticated Remote Code Execution via Update URL Poisoning
CVSS 9.8
CVE-2026-25961 HIGH
SumatraPDF 3.5.0-3.5.2 - Remote Code Execution via Update Mechanism TLS Hostname Verification Bypass
CVSS 7.5
CVE-2026-20056 MEDIUM
Cisco Secure Web Appliance - Unauthenticated Malware Archive Bypass via Dynamic Vectoring and Streaming Engine
CVSS 4.0
CVE-2026-22865 HIGH
Gradle < 8.14.4 - Dependency Resolution Bypass via Non-Fatal Repository Exception Handling
CVSS 7.4
CVE-2026-22816 HIGH
Gradle < 8.14.4 - Dependency Resolution Bypass via Unresolvable Host Name
CVSS 7.4
CVE-2025-10539 MEDIUM
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
CVSS 4.8
CVE-2025-47904 MEDIUM
Microchip Time Provider 4100 <2.5 - Code Injection
CVSS 4.1
CVE-2025-15575 MEDIUM
SolaX Power Pocket WiFi - Unauthenticated Firmware Tampering via Unsigned Update Files
CVSS 5.3
Details
Vulnerabilities 204
Exploit Likelihood Medium