CWE-494
Medium likelihoodDownload of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
204 vulnerabilities with CWE-494
CVE-2020-1452
HIGH
SharePoint Enterprise Server and Foundation - Remote Code Execution via Application Package Upload
CVSS 8.6
CVE-2020-1210
CRITICAL
Microsoft SharePoint - Remote Code Execution via Crafted Application Package
CVSS 9.9
CVE-2020-1200
HIGH
Microsoft SharePoint - Remote Code Execution via Application Package Source Markup
CVSS 8.6
CVE-2020-7831
HIGH
inogard ebiz4u - Directory Traversal and Arbitrary File Download via Startup Menu
CVSS 8.8
CVE-2020-7817
MEDIUM
k_upload < 6.2.2018.529 - Arbitrary File Download via Setup.inf
CVSS 5.5
CVE-2020-5772
HIGH
Teltonika TRB2_R_00.02.04.01 - Privilege Escalation
CVSS 7.5
CVE-2020-10926
HIGH
NETGEAR R6700 V1.0.4.84_10.0.58 - RCE
CVSS 8.8
CVE-2020-4125
HIGH
HCL Marketing Operations 9.1.2.4 10.1.x 11.1.0.x - Unauthenticated Arbitrary File Download via Modified Link
CVSS 8.1
CVE-2020-7826
HIGH
EyeSurfer BflyInstallerX.ocx v1.0.0.16 - Code Injection
CVSS 8.8
CVE-2020-7505
HIGH
Schneider-electric Easergy T300 Firmware < 1.5.2 - Download Without Integrity Check
CVSS 7.2
CVE-2020-7812
HIGH
Kaoni ezHTTPTrans < 1.0.0.70 - Remote Code Execution via Ezhttptrans.ocx ActiveX Method
CVSS 7.8
CVE-2020-7813
HIGH
Ezhttptrans.ocx <1.0.0.70 - Code Injection
CVSS 7.8
CVE-2020-9474
HIGH
Siedle SG 150-0 Firmware < 1.2.4 - Remote Code Execution via Backup Functionality
CVSS 8.8
CVE-2020-7806
HIGH
Tobesoft Xplatform <9.2.2.250 - RCE
CVSS 7.8
CVE-2020-5867
HIGH
NGINX Controller Agent <3.3.0 - Info Disclosure
CVSS 8.1
CVE-2020-9759
MEDIUM
LG webOS - Privilege Escalation and Arbitrary File Write via Environment Variable Manipulation
CVSS 4.6
CVE-2020-9751
CRITICAL
Naver Cloud Explorer < 2.2.2.11 - Remote Code Execution via Untrusted Upgrade File Download
CVSS 9.1
CVE-2020-8809
HIGH
Gurux GXDLMS Director <8.5.1905.1301 - RCE
CVSS 8.1
CVE-2020-5398
HIGH
Spring Framework 5.0.0-5.0.15, 5.1.0-5.1.12, 5.2.0-5.2.2 - Reflected File Download via Content-Disposition Header
CVSS 7.5
CVE-2019-19167
HIGH
Tobesoft Nexacro <2019.9.25.1 - RCE
CVSS 7.8
CVE-2019-19166
HIGH
Tobesoft XPlatform <9.2.3 - Code Injection
CVSS 7.8
CVE-2019-19165
HIGH
Inogard Ebiz4u <1.0.5.0 - Code Injection
CVSS 7.2
CVE-2019-3977
HIGH
MikroTik RouterOS < 6.44.5 and < 6.45.6 - Unauthenticated Arbitrary Code Download via Autoupgrade Feature
CVSS 7.5
CVE-2019-9534
HIGH
Cobham EXPLORER 710 <1.07 - Code Injection
CVSS 7.8
CVE-2019-14845
MEDIUM
OpenShift 4.1-4.3 - Man-in-the-Middle Attack via TLS Hostname Verification Bypass
CVSS 5.3
Details
Vulnerabilities
204
Exploit Likelihood
Medium