CWE-494
209 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
CVEs (209)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition....Show more |
IO-1020 Micro ELD downloads source code or an executable from an
adjacent location and executes the code without sufficiently verifying
the origin or integrity of the code.
|
WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative users to create events in the WP-Cron system that store and execute PHP code subject to the restricti...Show more |
2Debian Gnu3Debian Linux EmacsOrg ModeJun 17, 2026 Mar 25, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23. |
Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. Once the attacker is authorized to create...Show more |
An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files. |
1Phoenixcontact 2Multiprog Proconos EclrJun 17, 2026 Dec 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity ch...Show more |
1Phoenixcontact 9Axc F 1152 Firmware Axc F 2152 FirmwareAxc F 3152 Firmware+6 moreJun 17, 2026 Dec 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices. |
1Phoenixcontact 18Automationworx Software Suite Axc 1050 FirmwareAxc 1050 Xc Firmware+15 moreJun 17, 2026 Dec 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. |
1Schneider Electric 16Eb450 Firmware Eb45e FirmwareEh450 Firmware+13 moreJun 17, 2026 Dec 14, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a
privileged user to install an untrusted firmware.
|
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary com...Show more |
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary com...Show more |
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary com...Show more |
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary com...Show more |
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary com...Show more |
A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in t...Show more |
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability. |
1Schneider Electric 2Ion8650 Firmware Ion8800 FirmwareJun 17, 2026 Nov 15, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be uploaded when an authorized admin user begins a firmware update procedure which could result in full contr...Show more |
In MLSoft TCO!stream versions 8.0.22.1115 and below, a vulnerability exists due to insufficient permission validation. This allows an attacker to make the victim download and execute arbitrary files.
|
Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a security audit of Artifact Hub's code base a security researcher identified...Show more |