CWE-494
Medium likelihoodDownload of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
211 vulnerabilities with CWE-494
CVE-2024-39819
MEDIUM
Zoom Meeting SDK <6.0.10, Rooms <5.17.13, Workplace Desktop <6.0.10 - Privilege Escalation via Installer Bypass
CVSS 6.7
CVE-2024-39348
HIGH
Synology Router Manager < 1.2.5-8227 - Remote Code Execution via AirPrint Functionality
CVSS 7.5
CVE-2024-30206
HIGH
SIMATIC RTLS Locating Manager -<V3.0.1.1 - Info Disclosure
CVSS 8.8
CVE-2024-33118
HIGH
LuckyFrameWeb 3.5.2 - Arbitrary File Read via fileDownload Method
CVSS 7.5
CVE-2024-28878
CRITICAL
IOSiX IO-1020 Micro ELD < 360 - Unauthenticated Code Execution via Unverified Download
CVSS 9.6
CVE-2024-28850
HIGH
WP Crontrol < 1.16.2 - Authenticated Remote Code Execution via PHP Cron Event Tampering
CVSS 8.1
CVE-2024-30205
HIGH
Emacs < 29.3 and Org Mode < 9.6.23 - Unauthenticated Download of Code Without Integrity Check
CVSS 7.1
CVE-2024-27438
CRITICAL
Apache Doris 1.2.0-2.0.4 - Remote Code Execution via Unchecked JDBC Driver File
CVSS 9.8
CVE-2023-41921
CRITICAL
Firmware Modification - Code Injection
CVSS 9.8
CVE-2023-39474
HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Remote Code Execution via Unvalidated JAR Download
CVSS 8.8
CVE-2023-47353
HIGH
imou_go 1.0.11 - Arbitrary File Download via DownloadFirmwareService
CVSS 8.8
CVE-2023-5592
HIGH
PHOENIX CONTACT MULTIPROG and ProConOS eCLR - Unauthenticated Code Download Without Integrity Check
CVSS 7.5
CVE-2023-46144
MEDIUM
PLCnext - Info Disclosure
CVSS 6.5
CVE-2023-46143
HIGH
PHOENIX CONTACT Classic Line PLCs - Unauthenticated Application Modification
CVSS 7.5
CVE-2023-5630
MEDIUM
Schneider-electric Eb450 Firmware - Download Without Integrity Check
CVSS 6.5
CVE-2023-45842
HIGH
Buildroot 2023.08.1 and dev commit 622698d7847 - Arbitrary Command Execution via Package Hash Checking Bypass
CVSS 8.1
CVE-2023-45841
HIGH
Buildroot 2023.08.1 and dev commit 622698d7847 - Arbitrary Command Execution via Package Hash Checking Bypass
CVSS 8.1
CVE-2023-45840
HIGH
Buildroot 2023.08.1 and dev commit 622698d7847 - Arbitrary Command Execution via Package Hash Checking Bypass
CVSS 8.1
CVE-2023-45839
HIGH
Buildroot 2023.08.1 and dev commit 622698d7847 - Remote Code Execution via Package Hash Check Bypass
CVSS 8.1
CVE-2023-45838
HIGH
Buildroot 2023.08.1 and dev commit 622698d7847 - Arbitrary Command Execution via Package Hash Checking Bypass
CVSS 8.1
CVE-2023-43608
HIGH
Buildroot 2023.08.1 and dev commit 622698d7847 - Arbitrary Command Execution via BR_NO_CHECK_HASH_FOR
CVSS 8.1
CVE-2023-46887
HIGH
Dreamer CMS <4.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-5984
HIGH
ION8650 and ION8800 Firmware - Authenticated Firmware Upload Without Integrity Check
CVSS 7.2
CVE-2023-45799
HIGH
MLSoft TCO!stream < 8.0.23.215 - Unauthenticated Arbitrary File Download and Execution
CVSS 7.2
CVE-2023-45821
MEDIUM
Artifact Hub < 1.16.0 - Credential Hijacking via Docker Registry Domain Spoofing
CVSS 5.4
Details
Vulnerabilities
211
Exploit Likelihood
Medium