The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Volume of CVEs assigned to CWE-494 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
210 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40799HIGH Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. | Nov 29, 2022 | 8.8 | 80 | YES | NO |
CVE-2026-3502HIGH TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tam | Mar 30, 2026 | 7.8 | 75 | YES | NO |
CVE-2020-5398HIGH In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R | Jan 17, 2020 | 7.5 | 73 | NO | NO |
CVE-2025-15556HIGH Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cry | Feb 3, 2026 | 7.5 | 69 | YES | NO |
CVE-2021-44168HIGH A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbit | Jan 4, 2022 | 7.8 | 63 | YES | NO |
CVE-2026-27180CRITICAL MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore module expose | Feb 18, 2026 | 9.8 | 46 | NO | YES |
CVE-2025-68109HIGH ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded fil | Dec 17, 2025 | 7.2 | 41 | NO | YES |
CVE-2026-9089HIGH The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate | May 21, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-42249CRITICAL Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading up | Apr 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-42248CRITICAL Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verifi | Apr 29, 2026 | 9.8 | 39 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.