Fallos del tipo CWE-1395

51 resultados

Dependência de Componente Externo Vulnerável

Ocorre quando sua aplicação usa uma biblioteca, framework ou dependência de terceiros que contém vulnerabilidades conhecidas. O risco é que um atacante explore essas falhas no componente externo para comprometer sua aplicação, mesmo que seu código próprio esteja seguro.

Ejemplo

Uma aplicação web que usa uma versão antiga da biblioteca Log4j (anterior à correção do Log4Shell) e não faz atualização. Um atacante injeta um payload malicioso que explora a vulnerabilidade na biblioteca, conseguindo RCE no servidor, independentemente de como o desenvolvedor implementou o resto do código.

Cómo mitigar

Mantenha um inventário de todas as dependências, use ferramentas de scanning (OWASP Dependency-Check, npm audit, Snyk) em CI/CD para detectar versões vulneráveis, atualize regularmente bibliotecas e defina uma política de patching rápido para componentes com CVEs críticas.

CVE-2026-0943HIGHHarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerabilityEPSS 0.5%CVE-2026-60455HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.4%CVE-2025-40912CRITICALCryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicodeEPSS 0.4%CVE-2026-3257CRITICALUnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite libraryEPSS 0.4%CVE-2022-4976CRITICALArchive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilitiesEPSS 0.4%CVE-2024-32753HIGHTYCO Illustra Pro Gen 4 - JQuery versionEPSS 0.4%CVE-2026-55789HIGHLogto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service ProvidersEPSS 0.4%CVE-2025-61587LOWWeblate integration with Anubis can lead to Open Redirect via redir parameterEPSS 0.4%CVE-2024-45399MEDIUMIndico has a Cross-Site-Scripting during account creationEPSS 0.4%CVE-2024-26293HIGHUnauthenticated Path Traversal affecting Avid NEXISEPSS 0.4%CVE-2024-14030HIGHSereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard libraryEPSS 0.4%CVE-2024-14031HIGHSereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard libraryEPSS 0.4%CVE-2025-12220CRITICALBusybox 1.31.1 - Multiple Known VulnerabilitiesEPSS 0.3%CVE-2025-12219CRITICALVulnerable Components in Azure Access OSEPSS 0.3%CVE-2025-11159CRITICALHitachi Vantara Pentaho Data Integration & Analytics - Dependency on Vulnerable Third-Party ComponentEPSS 0.3%CVE-2026-69713MEDIUMWindows Secure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2022-4988HIGHAlien::FreeImage versions through 1.001 for Perl contains several vulnerable librariesEPSS 0.3%CVE-2025-40913MEDIUMNet::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflowEPSS 0.3%CVE-2024-6121HIGHNI SystemLink Server Ships Out of Date Redis VersionEPSS 0.3%CVE-2025-15444CRITICALCrypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodiumEPSS 0.3%