VulnSea

CWE-494

CVEs classified under CWE-494, newest first.

29 CVEsRSS

CVE-2026-93534Medium· 6.3PoC
3d ago

A vulnerability was identified in spatie Scotty up to 1.4.2

A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without i…

Twilightspatie · ScottyEPSS 0.20%via NVD
CVE-2026-7006High· 7.3PoC
3d ago

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …

MidnightSublime HQ Pty Ltd · Sublime Text 4EPSS 0.10%via NVD
CVE-2026-91098Critical· 9.8
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.67%via NVD
CVE-2026-91102Critical· 9.8⚖ disputed
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.25%via NVD
CVE-2026-92128High· 7.5
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to def…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to def…

Twilightjenkins · script_securityEPSS 0.22%via NVD
CVE-2026-63696Critical· 9.1
6d ago

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code ex…

MidnightDell · SmartFabric OS10 SoftwareEPSS 0.32%via NVD
CVE-2026-81052Medium· 6.8
1w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code ex…

Sunlitdell · thinosEPSS 0.14%via NVD
CVE-2026-79963High· 7.4
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potent…

Twilightdell · secure_connect_gatewayEPSS 0.18%via NVD
CVE-2026-12259Medium· 5.3
1w ago

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

Sunlitnltk · nltkEPSS 0.10%via OSV
CVE-2026-62654Medium· 6.8
1w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a netwo…

SunlitSiemens · Reyrolle 7SR5EPSS 0.11%via NVD
CVE-2026-85427High· 8.1
2w ago

MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message to the MOOSDB

MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message to the MOOSDB. Attackers can publi…

TwilightEPSS 0.42%via NVD
CVE-2026-80047High· 7.8
2w ago

Hugging Face Transformers library writes remote code to disk prior to consent check

A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches …

TwilightHugging Face · TransformersEPSS 0.08%via CVEORG
CVE-2026-82021High· 8.3
3w ago

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branc…

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branc…

TwilightEPSS 0.23%via NVD
CVE-2026-57910Critical· 9.3
3w ago

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

MidnightWatchGuard · WatchGuard AgentEPSS 0.20%via NVD
CVE-2026-63310High· 7.1
1mo ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.12%via NVD
CVE-2026-76241High
1mo ago

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by les…

Twilightstigmem-node · stigmem-nodeEPSS 0.09%via NVD
GHSA-xhcr-cqfr-m3hvHigh
1mo ago

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
CVE-2026-56864High· 8.1
1mo ago

golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB (CVE-2026-56864)

A flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver mal…

TwilightRed Hat · Red Hat Advanced Cluster Security for Kubernetes 4.11EPSS 0.30%via CSAF
CVE-2026-48046Critical· 9.3PoC
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process d…

Abyssaltruelockmc · streambertEPSS 0.35%via NVD
CVE-2026-55697High· 7.5
2mo ago

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

Twilightpnpm · pnpmEPSS 0.19%via GHSA
CVE-2026-55698High· 8.8
2mo ago

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

Twilightpnpm · pnpmEPSS 0.30%via GHSA
GHSA-gv7w-rqvm-qjhrHigh· 8.1
3mo ago

Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

Twilightesbuild · esbuildvia GHSA
CVE-2026-40066High· 8.8
5mo ago

Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded

Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.

Twilightanviz · cx7_firmwareEPSS 0.41%via NVD
CVE-2026-1878Medium· 5.4
6mo ago

An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM

An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which e…

SunlitASUS · Driver( Keyboard & Mouse )EPSS 0.13%via NVD
CVE-2025-69263High· 7.5PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when…

MidnightRed Hat · pnpmEPSS 0.43%via NVD
CVE-2022-24140Medium· 6.6
4y ago

IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file

IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the product…

Sunlitiobit · advanced_system_careEPSS 0.72%via NVD
CVE-2022-27438High· 8.1PoC
4y ago

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check…

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check…

Midnightcaphyon · advanced_installerEPSS 2.0%via NVD
CVE-2022-28944High· 8.8PoC
4y ago

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote …

Midnightemcosoftware · msi_package_builderEPSS 1.5%via NVD
CVE-2022-24644High· 8.8PoC
4y ago

ZZ Inc

ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.

Midnightzzinc · keymouse_firmwareEPSS 1.9%via NVD
CWE-494 vulnerabilities (CVEs) · VulnSea