CWE-494
Medium likelihoodDownload of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
200 vulnerabilities with CWE-494
CVE-2026-32148
HIGH
Lockfile checksums not verified in Hex allows dependency integrity bypass
CVE-2026-42249
HIGH
Remote Code Execution in Ollama via Update Mechanism
CVE-2026-42248
HIGH
Missing Signature Verification for Updates in Ollama
CVE-2026-40066
HIGH
Anviz Products Download of Code Without Integrity Check
CVSS 8.8
CVE-2026-3428
MEDIUM
Asus Member Center(华硕大厅) < 1.6.6.4 and earlier - Privilege Escalation
CVE-2026-34841
CRITICAL
Axios npm Supply Chain Incident Impacting @usebruno/cli
CVSS 9.8
CVE-2026-30603
MEDIUM
Qianniao QN-L23PA0904 v20250721.1640 - Privilege Escalation
CVSS 6.8
CVE-2026-3502
HIGH
KEV
TrueConf Client Update Integrity Verification Bypass
CVSS 7.8
CVE-2026-33075
HIGH
FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml
CVSS 8.8
CVE-2026-28500
HIGH
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVSS 8.6
CVE-2026-1878
MEDIUM
ASUS ROG Driver - Privilege Escalation
CVE-2026-3000
CRITICAL
IDExpert Windows Logon Agent - RCE
CVSS 9.8
CVE-2026-2999
CRITICAL
IDExpert Windows Logon Agent - RCE
CVSS 9.8
CVE-2026-27180
CRITICAL
MajorDoMo - Unauthenticated RCE
CVSS 9.8
CVE-2026-25961
HIGH
SumatraPDF <3.5.2 - RCE
CVSS 7.5
CVE-2026-20056
MEDIUM
Cisco AsyncOS - Auth Bypass
CVSS 4.0
CVE-2026-22865
HIGH
Gradle <9.3.0 - Info Disclosure
CVSS 7.4
CVE-2026-22816
HIGH
Gradle <9.3.0 - Info Disclosure
CVSS 7.4
CVE-2025-10539
MEDIUM
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
CVSS 4.8
CVE-2025-47904
MEDIUM
Microchip Time Provider 4100 <2.5 - Code Injection
CVSS 4.1
CVE-2025-15575
MEDIUM
Firmware Update - Code Injection
CVSS 5.3
CVE-2025-15556
HIGH
KEV
Notepad-plus-plus Notepad++ < 8.8.9 - Download Without Integrity Check
CVSS 7.5
CVE-2025-69263
HIGH
Pnpm < 10.26.0 - Download Without Integrity Check
CVSS 7.5
CVE-2025-68109
CRITICAL
Churchcrm < 6.5.3 - Remote Code Execution
CVSS 9.1
CVE-2025-65855
MEDIUM
Netun Solutions HelpFlash IoT v18_178_221102_ASCII_PRO_1R5_50 - RCE
CVSS 6.6
Details
Vulnerabilities
200
Exploit Likelihood
Medium