CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

200 vulnerabilities with CWE-494
CVE-2023-27025 HIGH
RuoYi <4.7.6 - Info Disclosure
CVSS 7.5
CVE-2023-28818 MEDIUM
Veritas NetBackup IT Analytics <11.2.0 - Code Injection
CVSS 5.3
CVE-2023-27574 CRITICAL
Shadowsocksx-ng - Download Without Integrity Check
CVSS 9.8
CVE-2023-23110 HIGH
Netgear Wnr612v2 Firmware < 1.0.0.3 - Download Without Integrity Check
CVSS 7.4
CVE-2022-24117 CRITICAL
General Electric Renewable Energy - Info Disclosure
CVSS 9.8
CVE-2022-46430 MEDIUM
TP-Link TL-WR740N <v3.12.4 - Authenticated RCE/DoS
CVSS 4.8
CVE-2022-46428 MEDIUM
TP-Link TL-WR1043ND V1 <3.13.15 - Authenticated RCE/DoS
CVSS 4.8
CVE-2022-46423 HIGH
Netgear WNR2000v1 <1.2.3.7 - MITM/DoS
CVSS 8.1
CVE-2022-37908 MEDIUM
Arubanetworks Sd-wan - Download Without Integrity Check
CVSS 5.8
CVE-2022-4261 MEDIUM
Rapid7 Insightvm < 6.6.172 - Download Without Integrity Check
CVSS 4.4
CVE-2022-40799 HIGH KEV
Dlink Dnr-322l Firmware < 2.60b15 - Download Without Integrity Check
CVSS 8.8
CVE-2022-45442 HIGH
Sinatra < 2.2.3 - Download Without Integrity Check
CVSS 8.8
CVE-2022-38199 MEDIUM
Esri ArcGIS Server - Remote File Download
CVSS 6.1
CVE-2022-31324 MEDIUM
Penta Security Systems Inc WAPPLES <6.0 r3 4.10-hotfix1 - File Down...
CVSS 6.5
CVE-2022-36671 HIGH
Xxyopen Novel-plus - Download Without Integrity Check
CVSS 7.5
CVE-2022-36359 HIGH
Django <3.2.15, <4.0.7 - RFD
CVSS 8.8
CVE-2022-24140 MEDIUM
IOBit Products - Info Disclosure
CVSS 6.6
CVE-2022-27438 HIGH
Caphyon Advanced Installer < 19.4 - Download Without Integrity Check
CVSS 8.1
CVE-2022-28944 HIGH
EMCO Software products < various - RCE
CVSS 8.8
CVE-2022-22786 HIGH
Zoom Meetings < 5.10.0 - Download Without Integrity Check
CVSS 7.5
CVE-2022-24644 HIGH
ZZ Inc. KeyMouse <3.08 - RCE
CVSS 8.8
CVE-2021-45027 HIGH
Softlinkint Oliver V5 Library - Download Without Integrity Check
CVSS 7.5
CVE-2021-26639 HIGH
Wisa Smart Wing Cms < r18715.20211229 - Improper Input Validation
CVSS 8.1
CVE-2021-35532 MEDIUM
Hitachi Energy TXpert Hub CoreTec <2.2.1 - Code Injection
CVSS 6.7
CVE-2021-41714 HIGH
Tipask < 3.5.9 - Download Without Integrity Check
CVSS 7.7
Details
Vulnerabilities 200
Exploit Likelihood Medium