CWE-494
Medium likelihoodDownload of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
211 vulnerabilities with CWE-494
CVE-2020-25266
MEDIUM
appimaged < 1.0.3 - Unauthenticated Arbitrary Code Execution via Crafted File Download
CVSS 5.5
CVE-2020-28332
CRITICAL
Barco wePresent WiPG-1600W Firmware - Unauthenticated Firmware Update Integrity Bypass
CVSS 9.8
CVE-2020-28213
HIGH
EcoStruxure Control Expert - Unauthorized Command Execution via Modbus Requests
CVSS 8.8
CVE-2020-15604
HIGH
Trend Micro Security 2019 < 15.0 - Improper Certificate Validation
CVSS 7.5
CVE-2020-1595
CRITICAL
Microsoft SharePoint - Remote Code Execution via Unsafe API Data Input
CVSS 9.9
CVE-2020-1576
HIGH
Microsoft SharePoint - Remote Code Execution via Crafted Application Package
CVSS 8.5
CVE-2020-1453
HIGH
Microsoft SharePoint - Remote Code Execution via Crafted Application Package
CVSS 8.6
CVE-2020-1452
HIGH
SharePoint Enterprise Server and Foundation - Remote Code Execution via Application Package Upload
CVSS 8.6
CVE-2020-1210
CRITICAL
Microsoft SharePoint - Remote Code Execution via Crafted Application Package
CVSS 9.9
CVE-2020-1200
HIGH
Microsoft SharePoint - Remote Code Execution via Application Package Source Markup
CVSS 8.6
CVE-2020-7831
HIGH
inogard ebiz4u - Directory Traversal and Arbitrary File Download via Startup Menu
CVSS 8.8
CVE-2020-7817
MEDIUM
k_upload < 6.2.2018.529 - Arbitrary File Download via Setup.inf
CVSS 5.5
CVE-2020-5772
HIGH
Teltonika TRB2_R_00.02.04.01 - Privilege Escalation
CVSS 7.5
CVE-2020-10926
HIGH
NETGEAR R6700 V1.0.4.84_10.0.58 - RCE
CVSS 8.8
CVE-2020-4125
HIGH
HCL Marketing Operations 9.1.2.4 10.1.x 11.1.0.x - Unauthenticated Arbitrary File Download via Modified Link
CVSS 8.1
CVE-2020-7826
HIGH
EyeSurfer BflyInstallerX.ocx v1.0.0.16 - Code Injection
CVSS 8.8
CVE-2020-7505
HIGH
Schneider-electric Easergy T300 Firmware < 1.5.2 - Download Without Integrity Check
CVSS 7.2
CVE-2020-7812
HIGH
Kaoni ezHTTPTrans < 1.0.0.70 - Remote Code Execution via Ezhttptrans.ocx ActiveX Method
CVSS 7.8
CVE-2020-7813
HIGH
Ezhttptrans.ocx <1.0.0.70 - Code Injection
CVSS 7.8
CVE-2020-9474
HIGH
Siedle SG 150-0 Firmware < 1.2.4 - Remote Code Execution via Backup Functionality
CVSS 8.8
CVE-2020-7806
HIGH
Tobesoft Xplatform <9.2.2.250 - RCE
CVSS 7.8
CVE-2020-5867
HIGH
NGINX Controller Agent <3.3.0 - Info Disclosure
CVSS 8.1
CVE-2020-9759
MEDIUM
LG webOS - Privilege Escalation and Arbitrary File Write via Environment Variable Manipulation
CVSS 4.6
CVE-2020-9751
CRITICAL
Naver Cloud Explorer < 2.2.2.11 - Remote Code Execution via Untrusted Upgrade File Download
CVSS 9.1
CVE-2020-8809
HIGH
Gurux GXDLMS Director <8.5.1905.1301 - RCE
CVSS 8.1
Details
Vulnerabilities
211
Exploit Likelihood
Medium