Перейти к содержимому
Noroxi

CWE-494 · 202 записей

Download of Code Without Integrity Check

CVE этого класса

204 записей

  • CVE-2022-40799
    75На этой неделе

    Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 34 %

    dlink · dnr-322l firmware29 нояб. 2022 г.

  • CVE-2025-15556
    61На этой неделе

    Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification

    ВысокаяCVSS 7,7KEVГотовый эксплойтEPSS 2 %

    notepad-plus-plus · notepad\+\+2 февр. 2026 г.

  • CVE-2021-44168
    61На этой неделе

    A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %

    fortinet · fortios4 янв. 2022 г.

  • CVE-2026-3502
    61На этой неделе

    TrueConf Client Update Integrity Verification Bypass

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 0 %

    trueconf · trueconf30 мар. 2026 г.

  • CVE-2016-6567
    40В плане

    SHDesigns' Resident Download Manager (as well as the Ethernet Download Manager) does not authenticate firmware downloads before executing code and deploying the

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    shdesigns · resident download manager13 июл. 2018 г.

  • CVE-2001-1125
    40В плане

    Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    symantec · liveupdate5 окт. 2001 г.

  • CVE-2020-1595
    40В плане

    Microsoft SharePoint Remote Code Execution Vulnerability

    КритическаяCVSS 9,9Эксплойта нетEPSS 2 %

    microsoft · sharepoint enterprise server11 сент. 2020 г.

  • CVE-2020-1210
    40В плане

    Microsoft SharePoint Remote Code Execution Vulnerability

    КритическаяCVSS 9,9Эксплойта нетEPSS 2 %

    microsoft · sharepoint enterprise server11 сент. 2020 г.

  • CVE-2002-0671
    39Наблюдать

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the inte

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    pingtel · xpressa firmware23 июл. 2002 г.

  • CVE-2020-28332
    39Наблюдать

    Barco wePresent WiPG-1600W devices download code without an Integrity Check.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    barco · wepresent wipg-1600w firmware24 нояб. 2020 г.

  • CVE-2018-5409
    39Наблюдать

    PrinterLogic Print Management Software updates and executes the code without origin and code verification

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    printerlogic · print management8 мая 2019 г.

  • CVE-2024-27438
    39Наблюдать

    Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · doris21 мар. 2024 г.

  • CVE-2020-7883
    39Наблюдать

    Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote fil

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wowsoft · printchaser28 дек. 2021 г.

  • CVE-2020-2320
    39Наблюдать

    Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    jenkins · installation manager tool3 дек. 2020 г.

  • CVE-2020-7812
    39Наблюдать

    Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    kaoni · ezhttptrans28 мая 2020 г.

  • CVE-2019-19167
    39Наблюдать

    Tobesoft Nexacro14 ActiveX File Download Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tobesoft · nexacro6 мая 2020 г.

  • CVE-2020-7806
    39Наблюдать

    Tobesoft Xplatform ActiveX File Download Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tobesoft · xplatform6 мая 2020 г.

  • CVE-2020-7813
    39Наблюдать

    Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    kaoni · ezhttptrans22 мая 2020 г.

  • CVE-2020-7826
    39Наблюдать

    EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    eyesurfer · bflyinstallerx.ocx17 июл. 2020 г.

  • CVE-2018-14620
    39Наблюдать

    The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    redhat · openstack10 сент. 2018 г.

  • CVE-2020-7873
    39Наблюдать

    Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary f

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ksystem · k-system wellcomm9 сент. 2021 г.

  • CVE-2019-3801
    39Наблюдать

    Java Projects using HTTP to fetch dependencies

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-deployment25 апр. 2019 г.

  • CVE-2020-22658
    39Наблюдать

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ruckuswireless · r310 firmware20 янв. 2023 г.

  • CVE-2025-56513
    39Наблюдать

    NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks.

    КритическаяCVSS 9,8Proof of conceptEPSS 0 %

    nicehash · quickminer30 сент. 2025 г.

  • CVE-2026-30612
    39Наблюдать

    An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    27 авг. 2026 г.

Все классы уязвимостей