Fallos del tipo CWE-1104

24 resultados

Uso de componentes de terceiros não mantidos

A aplicação depende de bibliotecas, frameworks ou módulos de terceiros que não recebem mais atualizações de segurança nem correções de bugs. Quando vulnerabilidades são descobertas nesses componentes, a equipe fica exposta porque não há patches disponíveis ou porque atualizá-los é impraticável.

Ejemplo

Uma aplicação Node.js usa uma versão antiga de um parser XML que tinha 5 anos sem atualização. Um CVE é publicado para injeção XXE justamente nesse parser; como o projeto foi abandonado pelos mantenedores, não há correção e a empresa fica vulnerável indefinidamente.

Cómo mitigar

Audite regularmente dependências com ferramentas como SBOM, retire componentes mortos do inventário e migre para alternativas mantidas ativamente. Implemente política de end-of-life claro para dependências e monitore anúncios de segurança dos projetos que usa.

CVE-2023-7102Remote Code Execution (RCE) VulnerabilityEPSS 43.6%CVE-2024-35252HIGHAzure Storage Movement Client Library Denial of Service VulnerabilityEPSS 2.5%CVE-2021-22142MEDIUMKibana Reporting vulnerabilitiesEPSS 1.0%CVE-2025-34192CRITICALVasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL VersionEPSS 0.9%CVE-2022-46871HIGHAn out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.EPSS 0.9%CVE-2026-16634CRITICALTOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99EPSS 0.8%CVE-2025-34193HIGHVasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated RuntimesEPSS 0.7%CVE-2025-10220CRITICALOutdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4EPSS 0.7%CVE-2024-11999HIGHCWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticaEPSS 0.6%CVE-2024-21631MEDIUMInteger overflow in URI leading to potential host spoofingEPSS 0.6%CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2026-3031CRITICALImage::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg libraryEPSS 0.4%CVE-2026-41468CRITICALBeghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template InjectionEPSS 0.4%CVE-2025-12104CRITICALIncorrect Content-Type HeaderEPSS 0.4%CVE-2025-3497HIGHRadiflow iSAP Smart Collector Linux distribution unmaintainedEPSS 0.3%CVE-2026-60368HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-20010HIGHUse of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User ApplEPSS 0.2%CVE-2026-21821HIGHHCL BigFix SCM Reporting is affected by vulnerabilities in jQueryEPSS 0.2%CVE-2025-52658LOWHCL MyXalytics is affected by the use of vulnerable/outdated versionsEPSS 0.2%CVE-2026-56580LOWHCL MyCloud was affected by Using Components with Known VulnerabilityEPSS 0.2%