Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext trans
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compro
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike othe
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of at
FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vuln
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and execute
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when c
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remot
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is abl
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the l
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability
SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS host
apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifi
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.y
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the reposit
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the of
ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu
An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access,
Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency
The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows at
In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w
Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software
A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco S
An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privi
A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a loca
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is
A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, ar
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated
eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai
stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agen
Frequently Asked Questions
What is CWE-494?
CWE-494 (CWE-494) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-494?
There are 49 CVE records associated with CWE-494 in our database. Of these, 7 are critical severity, 22 are high severity, and 8 are medium severity.
How can I protect against CWE-494 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-494 using AI-powered security agents.
Detect CWE-494 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-494 vulnerabilities across your infrastructure.
Get Started