CWE-1357— Reliance on Insufficiently Trustworthy Component
The product is built from multiple separate components, but it uses a component that is not sufficiently trusted to meet expectations for security, reliability, updateability, and maintainability.— MITRE CWE catalog
9 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1357page 1 of 1
- CVE-2024-26024HIGHCVSS 8.4EG 8.42024-05-28
SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.
- CVE-2024-28042HIGHCVSS 8.4EG 8.42024-05-15
SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.
- CVE-2024-3313HIGHCVSS 8.4EG 8.42024-04-09
SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Server 2021 and Substation Server 2021.
- CVE-2025-32800CRITICALCVSS 9.8EG 9.82025-06-16
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload…
- CVE-2026-47619HIGHCVSS 8.1EG 8.12026-08-04
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and informatio…
- CVE-2026-66783HIGHCVSS 4.4EG 8.22026-08-18
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), t…
- CVE-2026-67275MEDIUMCVSS 6.5EG 6.52026-08-26
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poi…
- CVE-2026-75569HIGHCVSS 7.7EG 7.72026-08-19
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with writ…
- CVE-2026-85469HIGHCVSS 8.0EG 8.02026-09-16
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to injec…
Map vulnerabilities like CWE-1357 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1357 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →