CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

211 vulnerabilities with CWE-494
CVE-2022-24140 MEDIUM
IOBit Products - Info Disclosure
CVSS 6.6
CVE-2022-27438 HIGH
Advanced Installer < 19.4 - Remote Code Execution via CustomDetection Parameter
CVSS 8.1
CVE-2022-28944 HIGH
EMCO Software products < various - RCE
CVSS 8.8
CVE-2022-22786 HIGH
Zoom Meetings and Rooms < 5.10.0 - Unauthenticated Version Downgrade via Update Process
CVSS 7.5
CVE-2022-24644 HIGH
ZZ Inc. KeyMouse <=3.08 - Unauthenticated Update Code Execution
CVSS 8.8
CVE-2021-47987 HIGH
Parse Server - Arbitrary Code Execution via Malicious Version Tags
CVSS 7.5
CVE-2021-47986 HIGH
Parse Server - Unreviewed Code Execution via Malicious Version Tags
CVSS 7.5
CVE-2021-45027 HIGH
Oliver v5 Library Server < 5.00.008.053 - Arbitrary File Download via FileServlet
CVSS 7.5
CVE-2021-26639 HIGH
WISA Smart Wing CMS < r18715.20211229 - Unauthenticated Arbitrary File Read via Input Validation Bypass
CVSS 8.1
CVE-2021-35532 MEDIUM
Hitachi Energy TXpert Hub CoreTec <2.2.1 - Code Injection
CVSS 6.7
CVE-2021-41714 HIGH
Tipask < 3.5.9 - Authenticated Arbitrary File Read via Attachment Download
CVSS 7.7
CVE-2021-44168 LOW KEV
FortiOS < 6.0.14 - Authenticated Arbitrary File Write via Restore Command
CVSS 3.3
CVE-2021-30669 MEDIUM
macOS 10.14-10.14.4 and 11.0-11.3 - Gatekeeper Bypass via Logic Issue
CVSS 5.5
CVE-2021-30658 MEDIUM
macOS Big Sur <11.3 - Privilege Escalation
CVSS 5.5
CVE-2021-38588 HIGH
cPanel < 96.0.13 - Download of Code Without Integrity Check
CVSS 8.1
CVE-2021-33879 HIGH
Tencent GameLoop < 4.1.21.90 - Remote Code Execution via MITM Update Spoofing
CVSS 8.1
CVE-2021-3485 MEDIUM
Bitdefender Endpoint Security Tools for Linux < 6.2.21.155 - Remote Code Execution via Product Update DownloadFile
CVSS 6.4
CVE-2020-22658 CRITICAL
Ruckus APs and SmartZone Controllers - Unauthorized Firmware Image Boot
CVSS 9.8
CVE-2020-22654 CRITICAL
Ruckus APs and SmartZone Controllers - Firmware MD5 Checksum Bypass
CVSS 9.8
CVE-2020-7883 CRITICAL
Printchaser <v2.2021.804.1 - Code Injection
CVSS 9.8
CVE-2020-7875 HIGH
DEXT5 Upload <5.0.0.117 - Code Injection
CVSS 7.5
CVE-2020-7874 HIGH
NEXACRO14 Runtime ActiveX Control 14.0.0.0-14.0.1.3600 - Arbitrary File Download and Execution
CVSS 8.8
CVE-2020-7873 HIGH
Younglimwon Co., Ltd - Code Injection
CVSS 8.8
CVE-2020-29032 HIGH
Secomea GateManager < 9.4.621054022 - Authenticated Code Execution via Firmware Archive Upload
CVSS 8.4
CVE-2020-2320 CRITICAL
Jenkins Plugin Installation Manager Tool <2.1.3 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 211
Exploit Likelihood Medium