CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

200 vulnerabilities with CWE-494
CVE-2025-7620 HIGH
Digitware System Integration - RCE
CVSS 8.8
CVE-2025-52937 LOW
PointCloudLibrary PCL <1.14.0 - Buffer Overflow
CVE-2025-28236 CRITICAL
Nautel VX Series transmitters <6.4.0 - RCE
CVSS 9.8
CVE-2025-27593 CRITICAL
SDD Device Drivers - Code Injection
CVSS 9.3
CVE-2025-1058 HIGH
Device - Code Injection
CVSS 8.1
CVE-2024-47192 MEDIUM
Mahara <24.04.4 - Info Disclosure
CVSS 5.3
CVE-2024-43169 HIGH
IBM Engineering Requirements Management DOORS Next <7.1 - Info Disc...
CVSS 8.8
CVE-2024-50696 HIGH
Sungrowpower Winet-s Firmware - Download Without Integrity Check
CVSS 7.5
CVE-2024-52331 HIGH
ECOVACS - Code Injection
CVSS 7.5
CVE-2024-42183 LOW
BigFix Patch Download Plug-ins - File Download
CVSS 2.5
CVE-2024-55459 MEDIUM
Keras - Download Without Integrity Check
CVSS 6.5
CVE-2024-54126 HIGH
TP-Link Archer C50 - RCE
CVE-2024-52583 HIGH
WesHacks - Info Disclosure
CVSS 8.2
CVE-2024-48974 CRITICAL
Ventilator - Info Disclosure
CVSS 9.3
CVE-2024-33660 MEDIUM
AMI Aptio V < 5.037 - Download Without Integrity Check
CVSS 4.3
CVE-2024-45321 HIGH
App::cpanminus <1.7047 - Code Injection
CVSS 8.1
CVE-2024-39819 MEDIUM
Zoom Meeting Software Development Kit - Download Without Integrity ...
CVSS 6.7
CVE-2024-39348 HIGH
Synology Router Manager - Download Without Integrity Check
CVSS 7.5
CVE-2024-30206 HIGH
SIMATIC RTLS Locating Manager -<V3.0.1.1 - Info Disclosure
CVSS 8.8
CVE-2024-33118 HIGH
Luckyframeweb - Download Without Integrity Check
CVSS 7.5
CVE-2024-28878 CRITICAL
IO-1020 Micro ELD - Code Injection
CVSS 9.6
CVE-2024-28850 HIGH
Johnbillion WP Crontrol < 1.16.2 - Download Without Integrity Check
CVSS 8.1
CVE-2024-30205 HIGH
Emacs <29.3 - Info Disclosure
CVSS 7.1
CVE-2024-27438 CRITICAL
Apache Doris <2.0.4 - RCE
CVSS 9.8
CVE-2023-41921 CRITICAL
Firmware Modification - Code Injection
CVSS 9.8
Details
Vulnerabilities 200
Exploit Likelihood Medium