Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-494

MITRE ↗

CWE-494

7
CRITICAL
22
HIGH
8
MEDIUM
47 CVEs
10.0
CVE-2026-22306

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext trans

9.8
CVE-2026-27180

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compro

9.8
CVE-2026-2999

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r

9.8
CVE-2026-3000

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r

9.8
CVE-2026-34841

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack

9.8
CVE-2026-42248

Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike othe

9.8
CVE-2026-42249

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of at

8.8
CVE-2026-33075

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vuln

8.8
CVE-2026-40066

Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and execute

8.8
CVE-2026-9089

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and

8.8
CVE-2026-49241

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4

8.8
CVE-2026-55698

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first

8.6
CVE-2026-28500

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc

8.3
CVE-2026-13433

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when c

8.3
CVE-2026-82021

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remot

8.1
CVE-2026-65081

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution

7.8
CVE-2026-3502 KEV

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is abl

7.5
CVE-2025-69263

pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the l

7.5
CVE-2025-15556 KEV

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability

7.5
CVE-2026-25961

SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS host

7.5
CVE-2026-42575

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifi

7.5
CVE-2026-55697

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.y

7.5
CVE-2021-47986

Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the reposit

7.5
CVE-2021-47987

Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the of

7.5
CVE-2026-53970

ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim

7.5
CVE-2026-65097

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download

7.4
CVE-2026-22816

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d

7.4
CVE-2026-22865

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d

7.1
CVE-2026-63310

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu

6.8
CVE-2026-30603

An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access,

5.9
CVE-2026-32148

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency

5.3
CVE-2025-15575

The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows at

5.3
CVE-2026-12259

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to

4.8
CVE-2025-10539

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p

4.4
CVE-2026-21810

HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w

4.1
CVE-2025-47904

Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software

4.0
CVE-2026-20056

A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco S

CVE-2026-1878

An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privi

CVE-2026-3428

A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a loca

CVE-2026-45058

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is

CVE-2026-9037

A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages

CVE-2026-50562

FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, ar

CVE-2026-66398

phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated

CVE-2026-0392

eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is

CVE-2026-48046

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai

CVE-2026-76241

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second

CVE-2026-57910

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agen

Frequently Asked Questions

What is CWE-494?

CWE-494 (CWE-494) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-494?

There are 49 CVE records associated with CWE-494 in our database. Of these, 7 are critical severity, 22 are high severity, and 8 are medium severity.

How can I protect against CWE-494 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-494 using AI-powered security agents.

Detect CWE-494 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-494 vulnerabilities across your infrastructure.

Get Started