CWE-494: Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
139 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-68109 — ChurchCRM vulnerable to RCE with database restore functionality
- CVE-2025-15556 — Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
- CVE-2026-3502 — TrueConf Client Update Integrity Verification Bypass
- CVE-2026-3000 — Changing|IDExpert Windows Logon Agent - Remote Code Execution
- CVE-2026-2999 — Changing|IDExpert Windows Logon Agent - Remote Code Execution
- CVE-2024-28878 — IOSIX IO-1020 Micro ELD Download of Code Without Integrity Check
- CVE-2026-33075 — FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml
- CVE-2025-53696 — iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the
- CVE-2025-27593 — RCE due to Device Driver
- CVE-2024-48974 — Life2000 Ventilator does not perform proper file integrity checks when adopting firmware updates
- CVE-2025-35115 — Agiloft insecure download of system packages
- CVE-2025-14265 — Improper server-side validation in ScreenConnect extension framework
- CVE-2025-7620 — DSIC|Cross-browser Components for Official Document Creation - Remote Code Execution
- CVE-2025-53520 — EG4 Electronics EG4 Inverters Download of Code Without Integrity Check
- CVE-2025-11493 — Self-Update Verification Mechanism Process in ConnectWise Automate
- CVE-2024-43169 — IBM Engineering Requirements Management DOORS Next file download
- CVE-2026-22865 — Gradle's failure to disable repositories failing to answer can expose builds to malicious artifacts
- CVE-2026-22816 — Gradle fails to disable repositories which can expose builds to malicious artifacts
- CVE-2026-22306 — Critical flaw impacting OZOLS ERP's automatic update channel
- CVE-2024-52583 — WesHacks code includes links to Leostop tracking spyware infested files
Recently published
- CVE-2026-79963 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-62654 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated
- CVE-2026-85427 — MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILE
- CVE-2026-82021 — Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference
- CVE-2026-21810 — HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checking
- CVE-2026-65081 — NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution
- CVE-2026-65097 — NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download
- CVE-2026-57910 — WatchGuard Agent improper authentication allows unauthenticated remote code execution
- CVE-2026-63310 — NLTK before 3.9.3 Missing Post-Download Integrity Verification
- CVE-2026-22306 — Critical flaw impacting OZOLS ERP's automatic update channel
- CVE-2026-76241 — stigmem Plugin Signature Enforcement Bypass via Configuration
- CVE-2026-53970 — ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb
- CVE-2026-13433 — IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
- CVE-2026-48046 — Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler
- CVE-2026-0392 — eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update
- CVE-2026-12259 — Improper Input Validation in nltk/nltk
- CVE-2026-66398 — phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API
- CVE-2026-50562 — FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows
- CVE-2021-47987 — Parse Server - Arbitrary Code Execution via Malicious Version Tags
- CVE-2021-47986 — Parse Server - Unreviewed Code Execution via Malicious Version Tags