Weaknesses of type CWE-1104

29 results

Uso de componentes de terceiros não mantidos

É quando um projeto depende de bibliotecas, frameworks ou módulos que não recebem mais atualizações de segurança ou correções do desenvolvedor original. Com o tempo, vulnerabilidades descobertas nessas dependências não são patches, deixando a aplicação exposta a ataques conhecidos.

Example

Uma aplicação web usa uma versão antiga de uma biblioteca de autenticação que não recebe atualizações há 3 anos. Uma CVE é divulgada para aquela versão, mas como o mantenedor abandonou o projeto, não há patch disponível — e qualquer pessoa com conhecimento da falha pode explorar a aplicação.

How to mitigate

Audite regularmente as dependências com ferramentas como npm audit, pip check ou OWASP Dependency-Check; remova ou substitua componentes orphans por alternativas ativas; implemente SCA (Software Composition Analysis) no pipeline de CI/CD para detectar dependências desatualizadas automaticamente.

CVE-2023-7102—Remote Code Execution (RCE) VulnerabilityEPSS 44.6%CVE-2024-35252HIGHAzure Storage Movement Client Library Denial of Service VulnerabilityEPSS 2.5%CVE-2021-22142MEDIUMKibana Reporting vulnerabilitiesEPSS 1.0%CVE-2025-34192CRITICALVasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL VersionEPSS 1.0%CVE-2022-46871HIGHAn out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.EPSS 0.9%CVE-2026-16634CRITICALTOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99EPSS 0.8%CVE-2025-34193HIGHVasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated RuntimesEPSS 0.8%CVE-2025-10220CRITICALOutdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4EPSS 0.7%CVE-2026-3031CRITICALImage::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg libraryEPSS 0.7%CVE-2026-11325HIGHcloudflare/pages-action is deprecated — migration required by September 18th, 2026EPSS 0.7%CVE-2026-41468CRITICALBeghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template InjectionEPSS 0.7%CVE-2024-11999HIGHCWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticaEPSS 0.6%CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2024-21631MEDIUMInteger overflow in URI leading to potential host spoofingEPSS 0.6%CVE-2026-60368HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-66788LOWLighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tagEPSS 0.4%CVE-2025-12104CRITICALIncorrect Content-Type HeaderEPSS 0.4%CVE-2025-3497HIGHRadiflow iSAP Smart Collector Linux distribution unmaintainedEPSS 0.3%CVE-2026-12554HIGHHP Easy Start for macOS - Security UpdateEPSS 0.3%CVE-2026-56580LOWHCL MyCloud was affected by Using Components with Known VulnerabilityEPSS 0.3%