Weaknesses of type CWE-1104

24 results

Uso de componentes de terceiros não mantidos

É quando um projeto depende de bibliotecas, frameworks ou módulos que não recebem mais atualizações de segurança ou correções do desenvolvedor original. Com o tempo, vulnerabilidades descobertas nessas dependências não são patches, deixando a aplicação exposta a ataques conhecidos.

Example

Uma aplicação web usa uma versão antiga de uma biblioteca de autenticação que não recebe atualizações há 3 anos. Uma CVE é divulgada para aquela versão, mas como o mantenedor abandonou o projeto, não há patch disponível — e qualquer pessoa com conhecimento da falha pode explorar a aplicação.

How to mitigate

Audite regularmente as dependências com ferramentas como npm audit, pip check ou OWASP Dependency-Check; remova ou substitua componentes orphans por alternativas ativas; implemente SCA (Software Composition Analysis) no pipeline de CI/CD para detectar dependências desatualizadas automaticamente.

CVE-2023-7102Remote Code Execution (RCE) VulnerabilityEPSS 43.6%CVE-2024-35252HIGHAzure Storage Movement Client Library Denial of Service VulnerabilityEPSS 2.5%CVE-2021-22142MEDIUMKibana Reporting vulnerabilitiesEPSS 1.0%CVE-2025-34192CRITICALVasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL VersionEPSS 0.9%CVE-2022-46871HIGHAn out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.EPSS 0.9%CVE-2026-16634CRITICALTOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99EPSS 0.8%CVE-2025-34193HIGHVasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated RuntimesEPSS 0.7%CVE-2025-10220CRITICALOutdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4EPSS 0.7%CVE-2024-11999HIGHCWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticaEPSS 0.6%CVE-2024-21631MEDIUMInteger overflow in URI leading to potential host spoofingEPSS 0.6%CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2026-3031CRITICALImage::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg libraryEPSS 0.4%CVE-2026-41468CRITICALBeghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template InjectionEPSS 0.4%CVE-2025-12104CRITICALIncorrect Content-Type HeaderEPSS 0.4%CVE-2025-3497HIGHRadiflow iSAP Smart Collector Linux distribution unmaintainedEPSS 0.3%CVE-2026-60368HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-20010HIGHUse of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User ApplEPSS 0.2%CVE-2026-21821HIGHHCL BigFix SCM Reporting is affected by vulnerabilities in jQueryEPSS 0.2%CVE-2025-52658LOWHCL MyXalytics is affected by the use of vulnerable/outdated versionsEPSS 0.2%CVE-2026-56580LOWHCL MyCloud was affected by Using Components with Known VulnerabilityEPSS 0.2%