Skip to main content

CWE archive

CWE-494 CVEs

Programmatic archive

210 CVEs tagged with CWE-49436 Critical, 125 High, 41 Medium, 8 Low, 0 Unrated.

CVE-2022-31324

Published Sep 13, 2022

An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45027

Published Sep 1, 2022

An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36671

Published Sep 1, 2022

Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36359

Published Aug 3, 2022

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack tha…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28944

Published May 23, 2022

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Wind…

CVSS 8.8 · High

CVE-2021-41714

Published May 23, 2022

In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22786

Published May 18, 2022

The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation versi…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-24644

Published Mar 10, 2022

ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44168

Published Jan 4, 2022

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbi…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-7883

Published Dec 28, 2021

Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7875

Published Oct 28, 2021

DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7874

Published Sep 9, 2021

Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7873

Published Sep 9, 2021

Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary file download and execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30669

Published Sep 8, 2021

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malici…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30658

Published Sep 8, 2021

This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Big Sur 11.3. A malicious application may bypass Gatekeeper checks.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-38588

Published Aug 11, 2021

In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33879

Published Jun 6, 2021

Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could spoof the contents of an XML document describ…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3485

Published May 24, 2021

An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the Download…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25266

Published Dec 2, 2020

AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, an…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 210 CVEsPage 6 of 9