CWE-494: CWE-494
Yearly Trend
Top Affected Vendors
All CWE-494 CVEs (72)
This vulnerability in Gradle's dependency resolution allows an attacker to serve malicious artifacts if they can register a domain name matching an un...
Jan 16, 2026This vulnerability in Gradle's dependency resolution could allow an attacker to disrupt a legitimate repository and force builds to use a malicious re...
Jan 16, 2026This CVE describes a firmware modification vulnerability in multiple Netgear router models where firmware integrity checks use a fixed checksum. Attac...
Feb 2, 2023This vulnerability allows attackers who can modify or replace static HTML files used by Foxit PDF's StartPage feature to inject malicious content that...
Dec 11, 2025This vulnerability in FortiClient for macOS allows local attackers to escalate privileges by modifying the installer during an upgrade process. It aff...
Apr 11, 2023The Sound4 FIRST web-based management interface has a critical vulnerability that allows remote code execution through malicious firmware updates. Att...
Nov 19, 2025The Sound4 IMPACT web management interface has a critical vulnerability allowing remote code execution through malicious firmware updates. Attackers c...
Nov 18, 2025ECOVACS vacuum robot base stations lack firmware update validation, allowing attackers to send malicious over-the-air updates via the insecure connect...
Sep 5, 2025A firmware signature validation bypass vulnerability in Tenda AC6 routers allows attackers to upload malicious firmware updates, leading to arbitrary ...
Aug 20, 2025This vulnerability in MLSoft TCO!stream allows attackers to trick victims into downloading and executing arbitrary files due to insufficient permissio...
Oct 30, 2023CVE-2023-37220 is a vulnerability in Synel Terminals that allows attackers to download and execute arbitrary code without integrity verification. This...
Sep 3, 2023This vulnerability in Emacs Org mode allows remote file contents to be executed as trusted code when opened in Org mode. It affects Emacs versions bef...
Mar 25, 2024A vulnerability in Keras 3.7.0 allows attackers to write arbitrary files to a user's machine by exploiting the get_file function with a malicious tar ...
Jan 8, 2025This vulnerability allows attackers to install malicious firmware on affected devices by bypassing authentication checks during firmware updates. It a...
Feb 12, 2026This vulnerability in Mahara allows attackers to bypass access controls by crafting malicious export download URLs, enabling unauthorized file downloa...
Aug 26, 2025This vulnerability allows an attacker with physical access to manipulate SPI flash memory without detection, potentially compromising system integrity...
Nov 12, 2024Microchip Time Provider 4100 devices before version 2.5 allow attackers to upload malicious firmware updates without cryptographic verification. This ...
Feb 24, 2026This vulnerability allows unauthenticated remote attackers to bypass anti-malware scanning on Cisco Secure Web Appliances by sending specially crafted...
Feb 4, 2026This CVE describes a denial of service vulnerability in Huawei office services where specially crafted requests could cause service disruption. The vu...
Dec 8, 2025This CVE describes a denial-of-service vulnerability in Huawei's office service. Successful exploitation could cause the service to become unresponsiv...
Dec 8, 2025This CVE describes a denial of service vulnerability in Huawei office services where attackers can disrupt service availability. The vulnerability aff...
Dec 8, 2025This CVE describes a denial-of-service vulnerability in Huawei office services where attackers can disrupt service availability. The vulnerability aff...
Dec 8, 2025About CWE-494 (CWE-494)
Our database tracks 72 CVEs classified as CWE-494, with 16 rated critical and 46 rated high severity. The average CVSS score for CWE-494 vulnerabilities is 7.8.
External reference: View CWE-494 on MITRE CWE →
Monitor CWE-494 Vulnerabilities
Get alerted when new CWE-494 CVEs affect your infrastructure.
Start Monitoring Free