CWE-494
209 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
CVEs (209)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Ra...Show more |
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. |
2Debian Sinatrarb2Debian Linux SinatraJun 17, 2026 Nov 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attac...Show more |
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in...Show more |
An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request. |
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input. |
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API. |
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system. |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Aug 3, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of...Show more |
1Iobit 5Advanced System Care Driver BoosterItop Screen Recorder+2 moreJul 9, 2026 Jul 6, 2022 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config...Show more |
1Hitachienergy 1Txpert Hub Coretec 4 Firmware Jun 17, 2026 Jun 7, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the system and obtain an acc...Show more |
293cx BoomCaphyon+26 more70Advanced Installer Angry Birds SpaceArchive Password Recovery+67 moreJul 9, 2026 Jun 6, 2022 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in...Show more |
1Emcosoftware 8Msi Package Builder Network InventoryNetwork Software Scanner+5 moreJul 9, 2026 May 23, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8...Show more |
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing i...Show more |
The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue...Show more |
ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of K...Show more |
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially c...Show more |
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged...Show more |
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged fo...Show more |
Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incompl...Show more |