The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.
Volume of CVEs assigned to CWE-1104 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7102CRITICAL Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Applian | Dec 24, 2023 | 9.8 | 67 | NO | YES |
CVE-2026-60368HIGH Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2. | Jul 22, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-3031CRITICAL Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library.
Image::EPEG includes Epeg 0.9.0 that was last updated in 2004.
Epeg is a fast JPEG t | Jul 16, 2026 | 9.8 | 38 | NO | NO |
CVE-2023-37524HIGH HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no | Jun 27, 2026 | 7.8 | 33 | NO | NO |
CVE-2025-10220CRITICAL Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execu | Sep 10, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-12104CRITICAL Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | Oct 23, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-34192CRITICAL Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to 20.0.2140 (macOS/Linux client deployments) are built agains | Sep 19, 2025 | 9.8 | 32 | NO | NO |
CVE-2026-21821HIGH The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security u | May 13, 2026 | 8.3 | 30 | NO | NO |
CVE-2026-41468HIGH Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same a | Apr 22, 2026 | 8.7 | 30 | NO | NO |
CVE-2025-34193CRITICAL Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstall | Sep 19, 2025 | 9.8 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.