Vulnerable dependencies
Modern applications are mostly other people's code. You inherit the security of everything you pulled in, and everything those pulled in.
A typical project has hundreds of these, most of them added indirectly by something else, many maintained by volunteers. You are unlikely to have read any of it. That is not an argument against using libraries, it is an argument for knowing what you actually depend on, because you cannot react to a flaw in something you did not know you were running.
Checked against the primary source.
