← Back
CWE-494

209 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Download of Code Without Integrity Check

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

JSON object

Loading...

CVEs (209)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rapid7
2Insightvm
Nexpose
Jun 17, 2026
Dec 8, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Ra...Show more
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself. Show less
1Dlink
1Dnr 322l Firmware
Jun 17, 2026
Nov 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
2Debian
Sinatrarb
2Debian Linux
Sinatra
Jun 17, 2026
Nov 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attac...Show more
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.Show less
1Esri
1Arcgis Server
Jun 17, 2026
Oct 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in...Show more
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide users with warnings against running unsigned executables downloaded from the internet.Show less
1Pentasecurity
1Wapples
Jun 17, 2026
Sep 13, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request.
1Softlinkint
1Oliver V5 Library
Jun 17, 2026
Sep 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input.
1Xxyopen
1Novel Plus
Jun 17, 2026
Sep 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.
1Wisa
1Smart Wing Cms
Jun 17, 2026
Aug 17, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.
2Debian
Djangoproject
2Debian Linux
Django
Jun 17, 2026
Aug 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of...Show more
An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.Show less
1Iobit
5Advanced System Care
Driver BoosterItop Screen Recorder+2 more
Jul 9, 2026
Jul 6, 2022
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config...Show more
IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.Show less
1Hitachienergy
1Txpert Hub Coretec 4 Firmware
Jun 17, 2026
Jun 7, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the system and obtain an acc...Show more
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the system and obtain an account with sufficient privilege to upload a malicious firmware to the product. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0; 2.0.1; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.Show less
293cx
BoomCaphyon+26 more
70Advanced Installer
Angry Birds SpaceArchive Password Recovery+67 more
Jul 9, 2026
Jun 6, 2022
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in...Show more
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.Show less
1Emcosoftware
8Msi Package Builder
Network InventoryNetwork Software Scanner+5 more
Jul 9, 2026
May 23, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8...Show more
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.Show less
1Tipask
1Tipask
Jun 17, 2026
May 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing i...Show more
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.Show less
1Zoom
2Meetings
Rooms
Jun 17, 2026
May 18, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue...Show more
The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.Show less
1Zzinc
1Keymouse Firmware
Jul 9, 2026
Mar 10, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of K...Show more
ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.Show less
1Fortinet
1Fortios
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially c...Show more
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.Show less
1Wowsoft
1Printchaser
Jun 17, 2026
Dec 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged...Show more
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.Show less
1Dext5
1Dext5upload
Jun 17, 2026
Oct 28, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged fo...Show more
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.Show less
1Tobesoft
1Nexacro
Jun 17, 2026
Sep 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incompl...Show more
Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.Show less