CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

200 vulnerabilities with CWE-494
CVE-2020-7817 MEDIUM
MyBrowserPlus - Info Disclosure
CVSS 5.5
CVE-2020-5772 HIGH
Teltonika TRB2_R_00.02.04.01 - Privilege Escalation
CVSS 7.5
CVE-2020-10926 HIGH
NETGEAR R6700 V1.0.4.84_10.0.58 - RCE
CVSS 8.8
CVE-2020-4125 HIGH
IBM Marketing Operations < 10.1.0.3 - Download Without Integrity Check
CVSS 8.1
CVE-2020-7826 HIGH
EyeSurfer BflyInstallerX.ocx v1.0.0.16 - Code Injection
CVSS 8.8
CVE-2020-7505 HIGH
Schneider-electric Easergy T300 Firmware < 1.5.2 - Download Without Integrity Check
CVSS 7.2
CVE-2020-7812 HIGH
Ezhttptrans.ocx <1.0.0.70 - RCE
CVSS 7.8
CVE-2020-7813 HIGH
Ezhttptrans.ocx <1.0.0.70 - Code Injection
CVSS 7.8
CVE-2020-9474 HIGH
Siedle SG 150-0 Firmware < 1.2.4 - Download Without Integrity Check
CVSS 8.8
CVE-2020-7806 HIGH
Tobesoft Xplatform <9.2.2.250 - RCE
CVSS 7.8
CVE-2020-5867 HIGH
NGINX Controller Agent <3.3.0 - Info Disclosure
CVSS 8.1
CVE-2020-9759 MEDIUM
LG Webos - Download Without Integrity Check
CVSS 4.6
CVE-2020-9751 CRITICAL
Naver Cloud Explorer < 2.2.2.11 - Download Without Integrity Check
CVSS 9.1
CVE-2020-8809 HIGH
Gurux GXDLMS Director <8.5.1905.1301 - RCE
CVSS 8.1
CVE-2020-5398 HIGH
Vmware Spring Framework < 5.0.16 - XSS
CVSS 7.5
CVE-2019-19167 HIGH
Tobesoft Nexacro <2019.9.25.1 - RCE
CVSS 7.8
CVE-2019-19166 HIGH
Tobesoft XPlatform <9.2.3 - Code Injection
CVSS 7.8
CVE-2019-19165 HIGH
Inogard Ebiz4u <1.0.5.0 - Code Injection
CVSS 7.2
CVE-2019-3977 HIGH
Mikrotik Routeros < 6.44.5 - Download Without Integrity Check
CVSS 7.5
CVE-2019-9534 HIGH
Cobham EXPLORER 710 <1.07 - Code Injection
CVSS 7.8
CVE-2019-14845 MEDIUM
Redhat Openshift < 4.3 - Download Without Integrity Check
CVSS 5.3
CVE-2019-16760 MEDIUM
Cargo <Rust 1.26.0 - Info Disclosure
CVSS 4.6
CVE-2019-13534 HIGH
Philips IntelliVue - Code Injection
CVSS 7.2
CVE-2019-12809 HIGH
Yes24 Viewer Activex - Download Without Integrity Check
CVSS 8.8
CVE-2019-12162 HIGH
Upwork Time Tracker <5.2.2.716 - Code Injection
CVSS 7.8
Details
Vulnerabilities 200
Exploit Likelihood Medium