Skip to main content

CWE archive

CWE-1104 CVEs

Programmatic archive

24 CVEs tagged with CWE-11048 Critical, 11 High, 2 Medium, 3 Low, 0 Unrated.

CVE-2026-16634

Published Jul 24, 2026

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vul…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
37.5

CVE-2026-60368

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56580

Published Jul 21, 2026

HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.

CVSS 2.2 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-3031

Published Jul 16, 2026

Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2023-37524

Published Jun 27, 2026

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service.  Since .NET Framework 4.5 has reached end-of-life and n…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-21821

Published May 13, 2026

The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-41468

Published Apr 22, 2026

Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
30.9

CVE-2025-55277

Published Mar 26, 2026

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available across the internet and craft a…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-20010

Published Nov 11, 2025

Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of pri…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-10220

Published Sep 10, 2025

Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to exec…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-48862

Published Aug 14, 2025

Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the p…

CVSS 7.1 · High

CVE-2025-3497

Published Jul 9, 2025

The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vu…

CVSS 8.7 · High

CVE-2025-40906

Published May 16, 2025

BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE…

CVSS 9.8 · Critical

CVE-2024-11999

Published Dec 17, 2024

CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into H…

CVSS 8.7 · High

CVE-2024-8885

Published Oct 2, 2024

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.

CVSS 8.8 · High

CVE-2024-21631

Published Jan 3, 2024

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI's components, which may caus…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22142

Published Nov 22, 2023

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46871

Published Dec 22, 2022

An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1