CWE-1104: Use of Unmaintained Third Party Components
The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.
28 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-12104 — Incorrect Content-Type Header
- CVE-2025-10220 — Outdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4
- CVE-2025-3497 — Radiflow iSAP Smart Collector Linux distribution unmaintained
- CVE-2025-20010 — Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 with
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2026-3031 — Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library
- CVE-2025-34192 — Vasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL Version
- CVE-2026-41468 — Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection
- CVE-2026-11325 — cloudflare/pages-action is deprecated — migration required by September 18th, 2026
- CVE-2025-48862 — Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup fi
- CVE-2026-12554 — HP Easy Start for macOS - Security Update
- CVE-2026-21821 — HCL BigFix SCM Reporting is affected by vulnerabilities in jQuery
- CVE-2023-37524 — HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service
- CVE-2026-21752 — HCL Hive is affected by a use of vulnerable third-party components
- CVE-2025-34193 — Vasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated Runtimes
- CVE-2024-23581 — HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerability
- CVE-2026-21753 — HCL Hive is affected by multiple security vulnerabilities.
- CVE-2025-52658 — HCL MyXalytics is affected by the use of vulnerable/outdated versions
- CVE-2026-66788 — Lighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tag
- CVE-2025-55277 — HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability
Recently published
- CVE-2026-21753 — HCL Hive is affected by multiple security vulnerabilities.
- CVE-2026-12554 — HP Easy Start for macOS - Security Update
- CVE-2026-21752 — HCL Hive is affected by a use of vulnerable third-party components
- CVE-2026-66788 — Lighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tag
- CVE-2026-11325 — cloudflare/pages-action is deprecated — migration required by September 18th, 2026
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2026-56580 — HCL MyCloud was affected by Using Components with Known Vulnerability
- CVE-2026-3031 — Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library
- CVE-2023-37524 — HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service
- CVE-2024-23581 — HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerability
- CVE-2026-21821 — HCL BigFix SCM Reporting is affected by vulnerabilities in jQuery
- CVE-2026-41468 — Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection
- CVE-2025-55277 — HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability
- CVE-2025-20010 — Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 with
- CVE-2025-12104 — Incorrect Content-Type Header
- CVE-2025-52658 — HCL MyXalytics is affected by the use of vulnerable/outdated versions
- CVE-2025-34193 — Vasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated Runtimes
- CVE-2025-34192 — Vasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL Version
- CVE-2025-10220 — Outdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4
- CVE-2025-48862 — Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup fi