CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

200 vulnerabilities with CWE-494
CVE-2026-32148 HIGH
Lockfile checksums not verified in Hex allows dependency integrity bypass
CVE-2026-42249 HIGH
Remote Code Execution in Ollama via Update Mechanism
CVE-2026-42248 HIGH
Missing Signature Verification for Updates in Ollama
CVE-2026-40066 HIGH
Anviz Products Download of Code Without Integrity Check
CVSS 8.8
CVE-2026-3428 MEDIUM
Asus Member Center(华硕大厅) < 1.6.6.4 and earlier - Privilege Escalation
CVE-2026-34841 CRITICAL
Axios npm Supply Chain Incident Impacting @usebruno/cli
CVSS 9.8
CVE-2026-30603 MEDIUM
Qianniao QN-L23PA0904 v20250721.1640 - Privilege Escalation
CVSS 6.8
CVE-2026-3502 HIGH KEV
TrueConf Client Update Integrity Verification Bypass
CVSS 7.8
CVE-2026-33075 HIGH
FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml
CVSS 8.8
CVE-2026-28500 HIGH
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVSS 8.6
CVE-2026-1878 MEDIUM
ASUS ROG Driver - Privilege Escalation
CVE-2026-3000 CRITICAL
IDExpert Windows Logon Agent - RCE
CVSS 9.8
CVE-2026-2999 CRITICAL
IDExpert Windows Logon Agent - RCE
CVSS 9.8
CVE-2026-27180 CRITICAL
MajorDoMo - Unauthenticated RCE
CVSS 9.8
CVE-2026-25961 HIGH
SumatraPDF <3.5.2 - RCE
CVSS 7.5
CVE-2026-20056 MEDIUM
Cisco AsyncOS - Auth Bypass
CVSS 4.0
CVE-2026-22865 HIGH
Gradle <9.3.0 - Info Disclosure
CVSS 7.4
CVE-2026-22816 HIGH
Gradle <9.3.0 - Info Disclosure
CVSS 7.4
CVE-2025-10539 MEDIUM
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
CVSS 4.8
CVE-2025-47904 MEDIUM
Microchip Time Provider 4100 <2.5 - Code Injection
CVSS 4.1
CVE-2025-15575 MEDIUM
Firmware Update - Code Injection
CVSS 5.3
CVE-2025-15556 HIGH KEV
Notepad-plus-plus Notepad++ < 8.8.9 - Download Without Integrity Check
CVSS 7.5
CVE-2025-69263 HIGH
Pnpm < 10.26.0 - Download Without Integrity Check
CVSS 7.5
CVE-2025-68109 CRITICAL
Churchcrm < 6.5.3 - Remote Code Execution
CVSS 9.1
CVE-2025-65855 MEDIUM
Netun Solutions HelpFlash IoT v18_178_221102_ASCII_PRO_1R5_50 - RCE
CVSS 6.6
Details
Vulnerabilities 200
Exploit Likelihood Medium