CWE-494: CWE-494

72
Total CVEs
16
Critical
46
High
7.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
9
2025
25
2024
11
2023
13
2022
4

Top Affected Vendors

1 Microsoft 5
2 Buildroot 4
3 Huawei 4
4 Sound4 3
5 Phoenixcontact 2
6 Gradle 2
7 Electra Air 2
8 Netgear 1
9 Luckyframe 1
10 Jenkins 1

All CWE-494 CVEs (72)

CVE-2026-22816
7.4

This vulnerability in Gradle's dependency resolution allows an attacker to serve malicious artifacts if they can register a domain name matching an un...

Jan 16, 2026
CVE-2026-22865
7.4

This vulnerability in Gradle's dependency resolution could allow an attacker to disrupt a legitimate repository and force builds to use a malicious re...

Jan 16, 2026
CVE-2023-23110
7.4

This CVE describes a firmware modification vulnerability in multiple Netgear router models where firmware integrity checks use a fixed checksum. Attac...

Feb 2, 2023
CVE-2025-55310
7.3

This vulnerability allows attackers who can modify or replace static HTML files used by Foxit PDF's StartPage feature to inject malicious content that...

Dec 11, 2025
CVE-2023-22635
7.3

This vulnerability in FortiClient for macOS allows local attackers to escalate privileges by modifying the installer during an upgrade process. It aff...

Apr 11, 2023
CVE-2025-63220
7.2

The Sound4 FIRST web-based management interface has a critical vulnerability that allows remote code execution through malicious firmware updates. Att...

Nov 19, 2025
CVE-2025-63215
7.2

The Sound4 IMPACT web management interface has a critical vulnerability allowing remote code execution through malicious firmware updates. Attackers c...

Nov 18, 2025
CVE-2025-30199
7.2

ECOVACS vacuum robot base stations lack firmware update validation, allowing attackers to send malicious over-the-air updates via the insecure connect...

Sep 5, 2025
CVE-2025-31355
7.2

A firmware signature validation bypass vulnerability in Tenda AC6 routers allows attackers to upload malicious firmware updates, leading to arbitrary ...

Aug 20, 2025
CVE-2023-45799
7.2

This vulnerability in MLSoft TCO!stream allows attackers to trick victims into downloading and executing arbitrary files due to insufficient permissio...

Oct 30, 2023
CVE-2023-37220
7.2

CVE-2023-37220 is a vulnerability in Synel Terminals that allows attackers to download and execute arbitrary code without integrity verification. This...

Sep 3, 2023
CVE-2024-30205
7.1

This vulnerability in Emacs Org mode allows remote file contents to be executed as trusted code when opened in Org mode. It affects Emacs versions bef...

Mar 25, 2024
CVE-2024-55459
6.5

A vulnerability in Keras 3.7.0 allows attackers to write arbitrary files to a user's machine by exploiting the get_file function with a malicious tar ...

Jan 8, 2025
CVE-2025-15575
5.3

This vulnerability allows attackers to install malicious firmware on affected devices by bypassing authentication checks during firmware updates. It a...

Feb 12, 2026
CVE-2024-47192
5.3

This vulnerability in Mahara allows attackers to bypass access controls by crafting malicious export download URLs, enabling unauthorized file downloa...

Aug 26, 2025
CVE-2024-33660
4.3

This vulnerability allows an attacker with physical access to manipulate SPI flash memory without detection, potentially compromising system integrity...

Nov 12, 2024
CVE-2025-47904
4.1

Microchip Time Provider 4100 devices before version 2.5 allow attackers to upload malicious firmware updates without cryptographic verification. This ...

Feb 24, 2026
CVE-2026-20056
4.0

This vulnerability allows unauthenticated remote attackers to bypass anti-malware scanning on Cisco Secure Web Appliances by sending specially crafted...

Feb 4, 2026
CVE-2025-66332
3.3

This CVE describes a denial of service vulnerability in Huawei office services where specially crafted requests could cause service disruption. The vu...

Dec 8, 2025
CVE-2025-66333
3.3

This CVE describes a denial-of-service vulnerability in Huawei's office service. Successful exploitation could cause the service to become unresponsiv...

Dec 8, 2025
CVE-2025-66334
3.3

This CVE describes a denial of service vulnerability in Huawei office services where attackers can disrupt service availability. The vulnerability aff...

Dec 8, 2025
CVE-2025-66331
3.3

This CVE describes a denial-of-service vulnerability in Huawei office services where attackers can disrupt service availability. The vulnerability aff...

Dec 8, 2025

About CWE-494 (CWE-494)

Our database tracks 72 CVEs classified as CWE-494, with 16 rated critical and 46 rated high severity. The average CVSS score for CWE-494 vulnerabilities is 7.8.

External reference: View CWE-494 on MITRE CWE →

Monitor CWE-494 Vulnerabilities

Get alerted when new CWE-494 CVEs affect your infrastructure.

Start Monitoring Free