CWE-1395: Dependency on Vulnerable Third-Party Component
The product has a dependency on a third-party component that contains one or more known vulnerabilities.
48 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-12220 — Busybox 1.31.1 - Multiple Known Vulnerabilities
- CVE-2025-12219 — Vulnerable Components in Azure Access OS
- CVE-2026-4176 — Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
- CVE-2025-10226 — PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address Multiple Vulnerabilities
- CVE-2024-0552 — Intumit inc. SmartRobot - Remote Code Execution
- CVE-2024-26293 — Unauthenticated Path Traversal affecting Avid NEXIS
- CVE-2025-15638 — Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt
- CVE-2026-58586 — Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2024-14031 — Sereal::Encoder versions from 4.000 through 4.009_002 for Perl is vulnerable to a buffer overwrite flaw in the Zstandard library
- CVE-2024-14030 — Sereal::Decoder versions from 4.000 through 4.009_002 for Perl is vulnerable to a buffer overwrite flaw in the Zstandard library
- CVE-2024-12740 — Dependency on Vulnerable Third-Party Component exposes Vulnerabilities in NI Vision Software
- CVE-2025-34203 — Vasion Print (formerly PrinterLogic) Use of Outdated, End-Of-Life, and Vulnerable Third-Party Components
- CVE-2025-11159 — Hitachi Vantara Pentaho Data Integration & Analytics - Dependency on Vulnerable Third-Party Component
- CVE-2026-47906 — Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
- CVE-2025-69275 — Spectrum outdated java library in class-path
- CVE-2025-13823 — Micro820®, Micro850®, Micro870® – Specialized Fuzzing Vulnerabilities
- CVE-2026-55789 — Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
- CVE-2024-32753 — TYCO Illustra Pro Gen 4 - JQuery version
- CVE-2026-34652 — Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
Recently published
- CVE-2026-58235 — Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
- CVE-2026-58586 — Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2026-55789 — Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
- CVE-2026-47906 — Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
- CVE-2026-8993 — Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks
- CVE-2025-31973 — HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'
- CVE-2025-11159 — Hitachi Vantara Pentaho Data Integration & Analytics - Dependency on Vulnerable Third-Party Component
- CVE-2026-34652 — Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
- CVE-2026-34654 — Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
- CVE-2022-4988 — Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries
- CVE-2025-59851 — HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability
- CVE-2025-15638 — Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt
- CVE-2024-14031 — Sereal::Encoder versions from 4.000 through 4.009_002 for Perl is vulnerable to a buffer overwrite flaw in the Zstandard library
- CVE-2024-14030 — Sereal::Decoder versions from 4.000 through 4.009_002 for Perl is vulnerable to a buffer overwrite flaw in the Zstandard library
- CVE-2026-4176 — Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
- CVE-2026-3257 — UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library
- CVE-2026-3381 — Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib
- CVE-2026-0943 — HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability
- CVE-2025-69275 — Spectrum outdated java library in class-path