CWE-494 · 202 kayıt
Download of Code Without Integrity Check
Bu sınıftaki CVE’ler
204 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
75Bu hafta | CVE-2022-40799Silahlaştırılmış | Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on thedlink · dnr-322l firmware · CWE-494 | Yüksek8,8 | KEV | %33,7 | 29 Kas 2022 |
61Bu hafta | CVE-2025-15556Silahlaştırılmış | Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verificationnotepad-plus-plus · notepad\+\+ · CWE-494 | Yüksek7,7 | KEV | %1,7 | 2 Şub 2026 |
61Bu hafta | CVE-2021-44168Silahlaştırılmış | A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local fortinet · fortios · CWE-494 | Yüksek7,8 | KEV | %0,9 | 4 Oca 2022 |
61Bu hafta | CVE-2026-3502Silahlaştırılmış | TrueConf Client Update Integrity Verification Bypasstrueconf · trueconf · CWE-494 | Yüksek7,8 | KEV | %0,3 | 30 Mar 2026 |
40Planlayın | CVE-2016-6567İstismar yok | SHDesigns' Resident Download Manager (as well as the Ethernet Download Manager) does not authenticate firmware downloads before executing code and deploying theshdesigns · resident download manager · CWE-494 | Kritik9,8 | — | %2,9 | 13 Tem 2018 |
40Planlayın | CVE-2001-1125İstismar yok | Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to executesymantec · liveupdate · CWE-494 | Kritik9,8 | — | %2,5 | 5 Eki 2001 |
40Planlayın | CVE-2020-1595İstismar yok | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-494 | Kritik9,9 | — | %2,0 | 11 Eyl 2020 |
40Planlayın | CVE-2020-1210İstismar yok | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-494 | Kritik9,9 | — | %1,9 | 11 Eyl 2020 |
39İzleyin | CVE-2002-0671İstismar yok | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the intepingtel · xpressa firmware · CWE-494 | Kritik9,8 | — | %1,2 | 23 Tem 2002 |
39İzleyin | CVE-2020-28332İstismar yok | Barco wePresent WiPG-1600W devices download code without an Integrity Check.barco · wepresent wipg-1600w firmware · CWE-494 | Kritik9,8 | — | %1,1 | 24 Kas 2020 |
39İzleyin | CVE-2018-5409İstismar yok | PrinterLogic Print Management Software updates and executes the code without origin and code verificationprinterlogic · print management · CWE-494 | Kritik9,8 | — | %1,1 | 8 May 2019 |
39İzleyin | CVE-2024-27438İstismar yok | Apache Doris: Downloading arbitrary remote jar files resulting in remote command executionapache · doris · CWE-494 | Kritik9,8 | — | %1,0 | 21 Mar 2024 |
39İzleyin | CVE-2020-7883İstismar yok | Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote filwowsoft · printchaser · CWE-494 | Kritik9,8 | — | %0,9 | 28 Ara 2021 |
39İzleyin | CVE-2020-2320İstismar yok | Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.jenkins · installation manager tool · CWE-494 | Kritik9,8 | — | %0,9 | 3 Ara 2020 |
39İzleyin | CVE-2020-7812İstismar yok | Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerabilitykaoni · ezhttptrans · CWE-494 | Kritik9,8 | — | %0,7 | 28 May 2020 |
39İzleyin | CVE-2019-19167İstismar yok | Tobesoft Nexacro14 ActiveX File Download Vulnerabilitytobesoft · nexacro · CWE-494 | Kritik9,8 | — | %0,7 | 6 May 2020 |
39İzleyin | CVE-2020-7806İstismar yok | Tobesoft Xplatform ActiveX File Download Vulnerabilitytobesoft · xplatform · CWE-494 | Kritik9,8 | — | %0,7 | 6 May 2020 |
39İzleyin | CVE-2020-7813İstismar yok | Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerabilitykaoni · ezhttptrans · CWE-494 | Kritik9,8 | — | %0,7 | 22 May 2020 |
39İzleyin | CVE-2020-7826İstismar yok | EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting eyesurfer · bflyinstallerx.ocx · CWE-494 | Kritik9,8 | — | %0,7 | 17 Tem 2020 |
39İzleyin | CVE-2018-14620İstismar yok | The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage.redhat · openstack · CWE-494 | Kritik9,8 | — | %0,6 | 10 Eyl 2018 |
39İzleyin | CVE-2020-7873İstismar yok | Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary fksystem · k-system wellcomm · CWE-494 | Kritik9,8 | — | %0,6 | 9 Eyl 2021 |
39İzleyin | CVE-2019-3801İstismar yok | Java Projects using HTTP to fetch dependenciescloudfoundry · cf-deployment · CWE-494 | Kritik9,8 | — | %0,6 | 25 Nis 2019 |
39İzleyin | CVE-2020-22658İstismar yok | In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckusruckuswireless · r310 firmware · CWE-494 | Kritik9,8 | — | %0,5 | 20 Oca 2023 |
39İzleyin | CVE-2025-56513Kavram kanıtı | NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks.nicehash · quickminer · CWE-494 | Kritik9,8 | — | %0,4 | 30 Eyl 2025 |
39İzleyin | CVE-2026-30612İstismar yok | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a CWE-494 | Kritik9,8 | — | %0,4 | 27 Ağu 2026 |
- CVE-2022-4079975Bu hafta
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %34dlink · dnr-322l firmware29 Kas 2022
- CVE-2025-1555661Bu hafta
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
YüksekCVSS 7,7KEVSilahlaştırılmışEPSS %2notepad-plus-plus · notepad\+\+2 Şub 2026
- CVE-2021-4416861Bu hafta
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1fortinet · fortios4 Oca 2022
- CVE-2026-350261Bu hafta
TrueConf Client Update Integrity Verification Bypass
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %0trueconf · trueconf30 Mar 2026
- CVE-2016-656740Planlayın
SHDesigns' Resident Download Manager (as well as the Ethernet Download Manager) does not authenticate firmware downloads before executing code and deploying the
KritikCVSS 9,8İstismar yokEPSS %3shdesigns · resident download manager13 Tem 2018
- CVE-2001-112540Planlayın
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute
KritikCVSS 9,8İstismar yokEPSS %2symantec · liveupdate5 Eki 2001
- CVE-2020-159540Planlayın
Microsoft SharePoint Remote Code Execution Vulnerability
KritikCVSS 9,9İstismar yokEPSS %2microsoft · sharepoint enterprise server11 Eyl 2020
- CVE-2020-121040Planlayın
Microsoft SharePoint Remote Code Execution Vulnerability
KritikCVSS 9,9İstismar yokEPSS %2microsoft · sharepoint enterprise server11 Eyl 2020
- CVE-2002-067139İzleyin
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the inte
KritikCVSS 9,8İstismar yokEPSS %1pingtel · xpressa firmware23 Tem 2002
- CVE-2020-2833239İzleyin
Barco wePresent WiPG-1600W devices download code without an Integrity Check.
KritikCVSS 9,8İstismar yokEPSS %1barco · wepresent wipg-1600w firmware24 Kas 2020
- CVE-2018-540939İzleyin
PrinterLogic Print Management Software updates and executes the code without origin and code verification
KritikCVSS 9,8İstismar yokEPSS %1printerlogic · print management8 May 2019
- CVE-2024-2743839İzleyin
Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution
KritikCVSS 9,8İstismar yokEPSS %1apache · doris21 Mar 2024
- CVE-2020-788339İzleyin
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote fil
KritikCVSS 9,8İstismar yokEPSS %1wowsoft · printchaser28 Ara 2021
- CVE-2020-232039İzleyin
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
KritikCVSS 9,8İstismar yokEPSS %1jenkins · installation manager tool3 Ara 2020
- CVE-2020-781239İzleyin
Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1kaoni · ezhttptrans28 May 2020
- CVE-2019-1916739İzleyin
Tobesoft Nexacro14 ActiveX File Download Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1tobesoft · nexacro6 May 2020
- CVE-2020-780639İzleyin
Tobesoft Xplatform ActiveX File Download Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1tobesoft · xplatform6 May 2020
- CVE-2020-781339İzleyin
Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1kaoni · ezhttptrans22 May 2020
- CVE-2020-782639İzleyin
EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting
KritikCVSS 9,8İstismar yokEPSS %1eyesurfer · bflyinstallerx.ocx17 Tem 2020
- CVE-2018-1462039İzleyin
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage.
KritikCVSS 9,8İstismar yokEPSS %1redhat · openstack10 Eyl 2018
- CVE-2020-787339İzleyin
Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary f
KritikCVSS 9,8İstismar yokEPSS %1ksystem · k-system wellcomm9 Eyl 2021
- CVE-2019-380139İzleyin
Java Projects using HTTP to fetch dependencies
KritikCVSS 9,8İstismar yokEPSS %1cloudfoundry · cf-deployment25 Nis 2019
- CVE-2020-2265839İzleyin
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus
KritikCVSS 9,8İstismar yokEPSS %1ruckuswireless · r310 firmware20 Oca 2023
- CVE-2025-5651339İzleyin
NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks.
KritikCVSS 9,8Kavram kanıtıEPSS %0nicehash · quickminer30 Eyl 2025
- CVE-2026-3061239İzleyin
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a
KritikCVSS 9,8İstismar yokEPSS %027 Ağu 2026