CWE-494
Medium likelihoodDownload of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
204 vulnerabilities with CWE-494
CVE-2025-55581
HIGH
D-Link DCS-825L <1.08.01 - Code Injection
CVSS 7.3
CVE-2025-31355
HIGH
Tenda AC6 Firmware V02.03.01.110 - Arbitrary Code Execution via Malicious Firmware Update
CVSS 7.2
CVE-2025-53520
HIGH
EG4 Electronics EG4 12kPV, 18kPV, Flex 21, Flex 18, 6000XP, 12000XP, GridBoss - Unauthenticated Firmware Tampering
CVSS 8.8
CVE-2025-53696
CRITICAL
iSTAR Ultra < 6.9.2 - Unauthenticated Firmware Integrity Bypass
CVE-2025-7620
HIGH
Digitware Cross-Browser Document Creation Component - Drive-By Code Execution
CVSS 8.8
CVE-2025-52937
LOW
PointCloudLibrary PCL <1.14.0 - Buffer Overflow
CVE-2025-28236
CRITICAL
Nautel VX Series transmitters <6.4.0 - RCE
CVSS 9.8
CVE-2025-27593
CRITICAL
SDD Device Drivers - Code Injection
CVSS 9.3
CVE-2025-1058
HIGH
Schneider Electric ASCO 5310 and 5350 - Download of Code Without Integrity Check
CVSS 8.1
CVE-2024-47192
MEDIUM
Mahara < 23.04.9 - Unauthenticated Arbitrary File Download via Export URL
CVSS 5.3
CVE-2024-43169
HIGH
IBM Engineering Requirements Management DOORS Next <7.1 - Info Disc...
CVSS 8.8
CVE-2024-50696
HIGH
SunGrow WiNet-S Firmware < 200.001.00.P025 - Unauthenticated Firmware Update via MQTT Message
CVSS 7.5
CVE-2024-52331
HIGH
ECOVACS Robot Lawnmowers and Vacuums - Arbitrary Firmware Installation via Deterministic Symmetric Key
CVSS 7.5
CVE-2024-42183
LOW
BigFix Patch Download Plug-ins - File Download
CVSS 2.5
CVE-2024-55459
MEDIUM
Keras 3.7.0 - Arbitrary File Write via get_file Tar Download
CVSS 6.5
CVE-2024-54126
HIGH
TP-Link Archer C50 < V4_240917 Authenticated Firmware Signature Bypass
CVE-2024-52583
HIGH
WesHacks - Malicious JavaScript Injection via Leostop Dependency
CVSS 8.2
CVE-2024-48974
CRITICAL
Baxter Life2000 Ventilation System < 06.08.00.00 - Unauthorized Firmware Modification via Missing Integrity Check
CVSS 9.3
CVE-2024-33660
MEDIUM
AMI Aptio V 5.0-5.037 - Unauthenticated Download of Code Without Integrity Check
CVSS 4.3
CVE-2024-45321
HIGH
App::cpanminus <1.7047 - Code Injection
CVSS 8.1
CVE-2024-39819
MEDIUM
Zoom Meeting SDK <6.0.10, Rooms <5.17.13, Workplace Desktop <6.0.10 - Privilege Escalation via Installer Bypass
CVSS 6.7
CVE-2024-39348
HIGH
Synology Router Manager < 1.2.5-8227 - Remote Code Execution via AirPrint Functionality
CVSS 7.5
CVE-2024-30206
HIGH
SIMATIC RTLS Locating Manager -<V3.0.1.1 - Info Disclosure
CVSS 8.8
CVE-2024-33118
HIGH
LuckyFrameWeb 3.5.2 - Arbitrary File Read via fileDownload Method
CVSS 7.5
CVE-2024-28878
CRITICAL
IOSiX IO-1020 Micro ELD < 360 - Unauthenticated Code Execution via Unverified Download
CVSS 9.6
Details
Vulnerabilities
204
Exploit Likelihood
Medium