İçeriğe atla
Noroxi

CWE-494 · 202 kayıt

Download of Code Without Integrity Check

Bu sınıftaki CVE’ler

204 kayıt

  • CVE-2022-40799
    75Bu hafta

    Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %34

    dlink · dnr-322l firmware29 Kas 2022

  • CVE-2025-15556
    61Bu hafta

    Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification

    YüksekCVSS 7,7KEVSilahlaştırılmışEPSS %2

    notepad-plus-plus · notepad\+\+2 Şub 2026

  • CVE-2021-44168
    61Bu hafta

    A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1

    fortinet · fortios4 Oca 2022

  • CVE-2026-3502
    61Bu hafta

    TrueConf Client Update Integrity Verification Bypass

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %0

    trueconf · trueconf30 Mar 2026

  • CVE-2016-6567
    40Planlayın

    SHDesigns' Resident Download Manager (as well as the Ethernet Download Manager) does not authenticate firmware downloads before executing code and deploying the

    KritikCVSS 9,8İstismar yokEPSS %3

    shdesigns · resident download manager13 Tem 2018

  • CVE-2001-1125
    40Planlayın

    Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute

    KritikCVSS 9,8İstismar yokEPSS %2

    symantec · liveupdate5 Eki 2001

  • CVE-2020-1595
    40Planlayın

    Microsoft SharePoint Remote Code Execution Vulnerability

    KritikCVSS 9,9İstismar yokEPSS %2

    microsoft · sharepoint enterprise server11 Eyl 2020

  • CVE-2020-1210
    40Planlayın

    Microsoft SharePoint Remote Code Execution Vulnerability

    KritikCVSS 9,9İstismar yokEPSS %2

    microsoft · sharepoint enterprise server11 Eyl 2020

  • CVE-2002-0671
    39İzleyin

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the inte

    KritikCVSS 9,8İstismar yokEPSS %1

    pingtel · xpressa firmware23 Tem 2002

  • CVE-2020-28332
    39İzleyin

    Barco wePresent WiPG-1600W devices download code without an Integrity Check.

    KritikCVSS 9,8İstismar yokEPSS %1

    barco · wepresent wipg-1600w firmware24 Kas 2020

  • CVE-2018-5409
    39İzleyin

    PrinterLogic Print Management Software updates and executes the code without origin and code verification

    KritikCVSS 9,8İstismar yokEPSS %1

    printerlogic · print management8 May 2019

  • CVE-2024-27438
    39İzleyin

    Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution

    KritikCVSS 9,8İstismar yokEPSS %1

    apache · doris21 Mar 2024

  • CVE-2020-7883
    39İzleyin

    Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote fil

    KritikCVSS 9,8İstismar yokEPSS %1

    wowsoft · printchaser28 Ara 2021

  • CVE-2020-2320
    39İzleyin

    Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.

    KritikCVSS 9,8İstismar yokEPSS %1

    jenkins · installation manager tool3 Ara 2020

  • CVE-2020-7812
    39İzleyin

    Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    kaoni · ezhttptrans28 May 2020

  • CVE-2019-19167
    39İzleyin

    Tobesoft Nexacro14 ActiveX File Download Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    tobesoft · nexacro6 May 2020

  • CVE-2020-7806
    39İzleyin

    Tobesoft Xplatform ActiveX File Download Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    tobesoft · xplatform6 May 2020

  • CVE-2020-7813
    39İzleyin

    Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    kaoni · ezhttptrans22 May 2020

  • CVE-2020-7826
    39İzleyin

    EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting

    KritikCVSS 9,8İstismar yokEPSS %1

    eyesurfer · bflyinstallerx.ocx17 Tem 2020

  • CVE-2018-14620
    39İzleyin

    The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage.

    KritikCVSS 9,8İstismar yokEPSS %1

    redhat · openstack10 Eyl 2018

  • CVE-2020-7873
    39İzleyin

    Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary f

    KritikCVSS 9,8İstismar yokEPSS %1

    ksystem · k-system wellcomm9 Eyl 2021

  • CVE-2019-3801
    39İzleyin

    Java Projects using HTTP to fetch dependencies

    KritikCVSS 9,8İstismar yokEPSS %1

    cloudfoundry · cf-deployment25 Nis 2019

  • CVE-2020-22658
    39İzleyin

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus

    KritikCVSS 9,8İstismar yokEPSS %1

    ruckuswireless · r310 firmware20 Oca 2023

  • CVE-2025-56513
    39İzleyin

    NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks.

    KritikCVSS 9,8Kavram kanıtıEPSS %0

    nicehash · quickminer30 Eyl 2025

  • CVE-2026-30612
    39İzleyin

    An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a

    KritikCVSS 9,8İstismar yokEPSS %0

    27 Ağu 2026

Tüm zafiyet sınıfları