Falhas do tipo CWE-1104

24 resultados

Uso de componentes de terceiros desatualizados ou não mantidos

Ocorre quando uma aplicação depende de bibliotecas, frameworks ou pacotes de terceiros que deixaram de receber atualizações de segurança ou manutenção. Sem patches regulares, vulnerabilidades conhecidas permanecem exploráveis e o código fica exposto a riscos crescentes ao longo do tempo.

Exemplo

Uma aplicação web que usa uma versão antiga de uma biblioteca de parsing JSON que contém uma falha de injeção, mas o mantenedor original abandonou o projeto. Quando a vulnerabilidade vira pública, não há patch disponível e o time precisa fazer um refator urgente ou ficar vulnerável.

Como mitigar

Realize auditoria regular de dependências (com ferramentas como OWASP Dependency-Check, npm audit ou Snyk), identifique componentes sem manutenção ativa e substitua por alternativas mantidas. Defina políticas de atualização de dependências e monitore contínuamente a saúde dos projetos dos quais você depende.

CVE-2023-7102Remote Code Execution (RCE) VulnerabilityEPSS 43.6%CVE-2024-35252HIGHAzure Storage Movement Client Library Denial of Service VulnerabilityEPSS 2.5%CVE-2021-22142MEDIUMKibana Reporting vulnerabilitiesEPSS 1.0%CVE-2025-34192CRITICALVasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL VersionEPSS 0.9%CVE-2022-46871HIGHAn out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.EPSS 0.9%CVE-2026-16634CRITICALTOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99EPSS 0.8%CVE-2025-34193HIGHVasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated RuntimesEPSS 0.7%CVE-2025-10220CRITICALOutdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4EPSS 0.7%CVE-2024-11999HIGHCWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticaEPSS 0.6%CVE-2024-21631MEDIUMInteger overflow in URI leading to potential host spoofingEPSS 0.6%CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2026-3031CRITICALImage::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg libraryEPSS 0.4%CVE-2026-41468CRITICALBeghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template InjectionEPSS 0.4%CVE-2025-12104CRITICALIncorrect Content-Type HeaderEPSS 0.4%CVE-2025-3497HIGHRadiflow iSAP Smart Collector Linux distribution unmaintainedEPSS 0.3%CVE-2026-60368HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-20010HIGHUse of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User ApplEPSS 0.2%CVE-2026-21821HIGHHCL BigFix SCM Reporting is affected by vulnerabilities in jQueryEPSS 0.2%CVE-2025-52658LOWHCL MyXalytics is affected by the use of vulnerable/outdated versionsEPSS 0.2%CVE-2026-56580LOWHCL MyCloud was affected by Using Components with Known VulnerabilityEPSS 0.2%