CWE-494 · 202 записей
Download of Code Without Integrity Check
CVE этого класса
204 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
75На этой неделе | CVE-2022-40799Готовый эксплойт | Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on thedlink · dnr-322l firmware · CWE-494 | Высокая8,8 | KEV | 33,7 % | 29 нояб. 2022 г. |
61На этой неделе | CVE-2025-15556Готовый эксплойт | Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verificationnotepad-plus-plus · notepad\+\+ · CWE-494 | Высокая7,7 | KEV | 1,7 % | 2 февр. 2026 г. |
61На этой неделе | CVE-2021-44168Готовый эксплойт | A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local fortinet · fortios · CWE-494 | Высокая7,8 | KEV | 0,9 % | 4 янв. 2022 г. |
61На этой неделе | CVE-2026-3502Готовый эксплойт | TrueConf Client Update Integrity Verification Bypasstrueconf · trueconf · CWE-494 | Высокая7,8 | KEV | 0,3 % | 30 мар. 2026 г. |
40В плане | CVE-2016-6567Эксплойта нет | SHDesigns' Resident Download Manager (as well as the Ethernet Download Manager) does not authenticate firmware downloads before executing code and deploying theshdesigns · resident download manager · CWE-494 | Критическая9,8 | — | 2,9 % | 13 июл. 2018 г. |
40В плане | CVE-2001-1125Эксплойта нет | Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to executesymantec · liveupdate · CWE-494 | Критическая9,8 | — | 2,5 % | 5 окт. 2001 г. |
40В плане | CVE-2020-1595Эксплойта нет | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-494 | Критическая9,9 | — | 2,0 % | 11 сент. 2020 г. |
40В плане | CVE-2020-1210Эксплойта нет | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-494 | Критическая9,9 | — | 1,9 % | 11 сент. 2020 г. |
39Наблюдать | CVE-2002-0671Эксплойта нет | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the intepingtel · xpressa firmware · CWE-494 | Критическая9,8 | — | 1,2 % | 23 июл. 2002 г. |
39Наблюдать | CVE-2020-28332Эксплойта нет | Barco wePresent WiPG-1600W devices download code without an Integrity Check.barco · wepresent wipg-1600w firmware · CWE-494 | Критическая9,8 | — | 1,1 % | 24 нояб. 2020 г. |
39Наблюдать | CVE-2018-5409Эксплойта нет | PrinterLogic Print Management Software updates and executes the code without origin and code verificationprinterlogic · print management · CWE-494 | Критическая9,8 | — | 1,1 % | 8 мая 2019 г. |
39Наблюдать | CVE-2024-27438Эксплойта нет | Apache Doris: Downloading arbitrary remote jar files resulting in remote command executionapache · doris · CWE-494 | Критическая9,8 | — | 1,0 % | 21 мар. 2024 г. |
39Наблюдать | CVE-2020-7883Эксплойта нет | Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote filwowsoft · printchaser · CWE-494 | Критическая9,8 | — | 0,9 % | 28 дек. 2021 г. |
39Наблюдать | CVE-2020-2320Эксплойта нет | Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.jenkins · installation manager tool · CWE-494 | Критическая9,8 | — | 0,9 % | 3 дек. 2020 г. |
39Наблюдать | CVE-2020-7812Эксплойта нет | Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerabilitykaoni · ezhttptrans · CWE-494 | Критическая9,8 | — | 0,7 % | 28 мая 2020 г. |
39Наблюдать | CVE-2019-19167Эксплойта нет | Tobesoft Nexacro14 ActiveX File Download Vulnerabilitytobesoft · nexacro · CWE-494 | Критическая9,8 | — | 0,7 % | 6 мая 2020 г. |
39Наблюдать | CVE-2020-7806Эксплойта нет | Tobesoft Xplatform ActiveX File Download Vulnerabilitytobesoft · xplatform · CWE-494 | Критическая9,8 | — | 0,7 % | 6 мая 2020 г. |
39Наблюдать | CVE-2020-7813Эксплойта нет | Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerabilitykaoni · ezhttptrans · CWE-494 | Критическая9,8 | — | 0,7 % | 22 мая 2020 г. |
39Наблюдать | CVE-2020-7826Эксплойта нет | EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting eyesurfer · bflyinstallerx.ocx · CWE-494 | Критическая9,8 | — | 0,7 % | 17 июл. 2020 г. |
39Наблюдать | CVE-2018-14620Эксплойта нет | The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage.redhat · openstack · CWE-494 | Критическая9,8 | — | 0,6 % | 10 сент. 2018 г. |
39Наблюдать | CVE-2020-7873Эксплойта нет | Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary fksystem · k-system wellcomm · CWE-494 | Критическая9,8 | — | 0,6 % | 9 сент. 2021 г. |
39Наблюдать | CVE-2019-3801Эксплойта нет | Java Projects using HTTP to fetch dependenciescloudfoundry · cf-deployment · CWE-494 | Критическая9,8 | — | 0,6 % | 25 апр. 2019 г. |
39Наблюдать | CVE-2020-22658Эксплойта нет | In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckusruckuswireless · r310 firmware · CWE-494 | Критическая9,8 | — | 0,5 % | 20 янв. 2023 г. |
39Наблюдать | CVE-2025-56513Proof of concept | NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks.nicehash · quickminer · CWE-494 | Критическая9,8 | — | 0,4 % | 30 сент. 2025 г. |
39Наблюдать | CVE-2026-30612Эксплойта нет | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a CWE-494 | Критическая9,8 | — | 0,4 % | 27 авг. 2026 г. |
- CVE-2022-4079975На этой неделе
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 34 %dlink · dnr-322l firmware29 нояб. 2022 г.
- CVE-2025-1555661На этой неделе
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
ВысокаяCVSS 7,7KEVГотовый эксплойтEPSS 2 %notepad-plus-plus · notepad\+\+2 февр. 2026 г.
- CVE-2021-4416861На этой неделе
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %fortinet · fortios4 янв. 2022 г.
- CVE-2026-350261На этой неделе
TrueConf Client Update Integrity Verification Bypass
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 0 %trueconf · trueconf30 мар. 2026 г.
- CVE-2016-656740В плане
SHDesigns' Resident Download Manager (as well as the Ethernet Download Manager) does not authenticate firmware downloads before executing code and deploying the
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %shdesigns · resident download manager13 июл. 2018 г.
- CVE-2001-112540В плане
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %symantec · liveupdate5 окт. 2001 г.
- CVE-2020-159540В плане
Microsoft SharePoint Remote Code Execution Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %microsoft · sharepoint enterprise server11 сент. 2020 г.
- CVE-2020-121040В плане
Microsoft SharePoint Remote Code Execution Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %microsoft · sharepoint enterprise server11 сент. 2020 г.
- CVE-2002-067139Наблюдать
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the inte
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pingtel · xpressa firmware23 июл. 2002 г.
- CVE-2020-2833239Наблюдать
Barco wePresent WiPG-1600W devices download code without an Integrity Check.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %barco · wepresent wipg-1600w firmware24 нояб. 2020 г.
- CVE-2018-540939Наблюдать
PrinterLogic Print Management Software updates and executes the code without origin and code verification
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %printerlogic · print management8 мая 2019 г.
- CVE-2024-2743839Наблюдать
Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · doris21 мар. 2024 г.
- CVE-2020-788339Наблюдать
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote fil
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wowsoft · printchaser28 дек. 2021 г.
- CVE-2020-232039Наблюдать
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jenkins · installation manager tool3 дек. 2020 г.
- CVE-2020-781239Наблюдать
Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kaoni · ezhttptrans28 мая 2020 г.
- CVE-2019-1916739Наблюдать
Tobesoft Nexacro14 ActiveX File Download Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tobesoft · nexacro6 мая 2020 г.
- CVE-2020-780639Наблюдать
Tobesoft Xplatform ActiveX File Download Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tobesoft · xplatform6 мая 2020 г.
- CVE-2020-781339Наблюдать
Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kaoni · ezhttptrans22 мая 2020 г.
- CVE-2020-782639Наблюдать
EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %eyesurfer · bflyinstallerx.ocx17 июл. 2020 г.
- CVE-2018-1462039Наблюдать
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redhat · openstack10 сент. 2018 г.
- CVE-2020-787339Наблюдать
Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary f
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ksystem · k-system wellcomm9 сент. 2021 г.
- CVE-2019-380139Наблюдать
Java Projects using HTTP to fetch dependencies
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cloudfoundry · cf-deployment25 апр. 2019 г.
- CVE-2020-2265839Наблюдать
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ruckuswireless · r310 firmware20 янв. 2023 г.
- CVE-2025-5651339Наблюдать
NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks.
КритическаяCVSS 9,8Proof of conceptEPSS 0 %nicehash · quickminer30 сент. 2025 г.
- CVE-2026-3061239Наблюдать
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %27 авг. 2026 г.