The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.
Volume of CVEs assigned to CWE-353 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7574HIGH Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a v | Jun 24, 2026 | 8.7 | 38 | NO | NO |
CVE-2026-45787CRITICAL electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no | May 28, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-48995HIGH pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfi | Jun 25, 2026 | 7.5 | 33 | NO | NO |
CVE-2020-7878CRITICAL An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity ch | Dec 28, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-7808CRITICAL In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloa | May 21, 2020 | 9.8 | 30 | NO | NO |
CVE-2026-12705MEDIUM Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE).
This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update To | Jul 17, 2026 | 6.4 | 29 | NO | NO |
CVE-2026-42428HIGH OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detectio | Apr 28, 2026 | 7.1 | 28 | NO | NO |
CVE-2021-26608CRITICAL An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrit | Sep 9, 2021 | 9.8 | 28 | NO | NO |
CVE-2019-19160HIGH Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp). | Jun 29, 2020 | 8.8 | 28 | NO | NO |
CVE-2026-3856CRITICAL IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the | Mar 17, 2026 | 9.1 | 27 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.