CWE-121: CWE-121

947
Total CVEs
187
Critical
634
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Totolink 30
4 Adobe 25
5 Microsoft 24
6 Milesight 24
7 Cisco 18
8 Siemens 17
9 Debian 16
10 Deltaww 15

All CWE-121 CVEs (947)

CVE-2024-39791
10.0

CVE-2024-39791 is a critical stack-based buffer overflow vulnerability in Vonets industrial WiFi bridge devices that allows unauthenticated remote att...

Aug 12, 2024
CVE-2022-20701
10.0

This CVE describes multiple critical vulnerabilities in Cisco Small Business RV series routers that allow an attacker to execute arbitrary code, bypas...

Feb 10, 2022
CVE-2022-20703
10.0

Multiple critical vulnerabilities in Cisco Small Business RV Series routers allow attackers to execute arbitrary code, bypass authentication, and caus...

Feb 10, 2022
CVE-2022-20705
10.0

This critical vulnerability in Cisco Small Business RV Series routers allows attackers to bypass authentication, execute arbitrary commands with root ...

Feb 10, 2022
CVE-2022-20707
10.0

This critical vulnerability in Cisco Small Business RV Series routers allows unauthenticated attackers to bypass authentication, execute arbitrary com...

Feb 10, 2022
CVE-2022-20709
10.0

This critical vulnerability in Cisco Small Business RV series routers allows attackers to execute arbitrary code, bypass authentication, and cause den...

Feb 10, 2022
CVE-2022-20711
10.0

This critical vulnerability in Cisco Small Business RV series routers allows unauthenticated remote attackers to execute arbitrary code with root priv...

Feb 10, 2022
CVE-2022-20749
10.0

This critical vulnerability in Cisco Small Business RV series routers allows attackers to execute arbitrary code, bypass authentication, and cause den...

Feb 10, 2022
CVE-2022-20699
10.0

This critical vulnerability in Cisco Small Business routers allows unauthenticated remote attackers to execute arbitrary code, bypass authentication, ...

Feb 10, 2022
CVE-2021-21960
10.0

A critical stack-based buffer overflow vulnerability in Sealevel Systems SeaConnect 370W's LLMNR functionality allows remote attackers to execute arbi...

Feb 4, 2022
CVE-2021-21889
9.9

This vulnerability allows authenticated attackers to execute arbitrary code on Lantronix PremierWave 2050 devices by exploiting a stack-based buffer o...

Dec 22, 2021
CVE-2025-70223
9.8

A stack buffer overflow vulnerability in D-Link DIR-513 routers allows remote attackers to execute arbitrary code via the curTime parameter in the gof...

Mar 4, 2026
CVE-2019-25364
9.8

MailCarrier 2.51 contains a critical buffer overflow vulnerability in its POP3 service that allows remote attackers to execute arbitrary code by sendi...

Feb 18, 2026
CVE-2019-25360
9.8

CVE-2019-25360 is a critical buffer overflow vulnerability in Aida64 Engineer's CSV logging configuration that allows remote code execution. Attackers...

Feb 18, 2026
CVE-2026-2329
9.8

An unauthenticated stack-based buffer overflow vulnerability in Grandstream GXP1600 series VoIP phones allows remote attackers to execute arbitrary co...

Feb 18, 2026
CVE-2019-25319
9.8

CVE-2019-25319 is a critical stack overflow vulnerability in Domain Quester Pro 6.02 that allows remote attackers to execute arbitrary code by exploit...

Feb 12, 2026
CVE-2019-25321
9.8

CVE-2019-25321 is a critical stack overflow vulnerability in FTP Navigator 8.03 that allows attackers to execute arbitrary code by exploiting Structur...

Feb 12, 2026
CVE-2020-37181
9.8

CVE-2020-37181 is a critical stack overflow vulnerability in Torrent FLV Converter 1.51 Build 117 that allows attackers to execute arbitrary code by e...

Feb 11, 2026
CVE-2020-37183
9.8

CVE-2020-37183 is a critical stack overflow vulnerability in Allok RM RMVB to AVI MPEG DVD Converter that allows remote code execution. Attackers can ...

Feb 11, 2026
CVE-2020-37176
9.8

CVE-2020-37176 is a critical stack overflow vulnerability in Torrent 3GP Converter 1.51 that allows remote attackers to execute arbitrary code by expl...

Feb 11, 2026
CVE-2025-70085
9.8

This CVE describes a stack buffer overflow vulnerability in OpenSatKit 2.2.1's file management component. Attackers can exploit this by providing long...

Feb 11, 2026
CVE-2026-22904
9.8

This critical vulnerability allows unauthenticated remote attackers to trigger a stack buffer overflow by sending oversized cookie values. Successful ...

Feb 9, 2026
CVE-2026-22903
9.8

An unauthenticated remote attacker can crash or potentially execute arbitrary code on lighttpd web servers by sending a specially crafted HTTP request...

Feb 9, 2026
CVE-2020-37161
9.8

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code....

Feb 7, 2026
CVE-2025-67187
9.8

A stack-based buffer overflow vulnerability in TOTOLINK A950RG routers allows remote attackers to execute arbitrary code by sending specially crafted ...

Feb 3, 2026
CVE-2026-24465
9.8

A stack-based buffer overflow vulnerability in ELECOM wireless LAN access point devices allows remote attackers to execute arbitrary code by sending s...

Feb 3, 2026
CVE-2026-0791
9.8

This vulnerability allows remote attackers to execute arbitrary code on ALGO 8180 IP Audio Alerter devices without authentication by sending specially...

Jan 23, 2026
CVE-2026-0792
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on ALGO 8180 IP Audio Alerter devices by sending specially crafte...

Jan 23, 2026
CVE-2025-69764
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX3 routers by exploiting a stack-based buffer overflow in the formGetIp...

Jan 22, 2026
CVE-2025-69762
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX3 routers by exploiting a stack overflow in the formSetIptv function. ...

Jan 21, 2026
CVE-2025-69763
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX3 routers by exploiting a stack overflow in the formSetIptv function v...

Jan 21, 2026
CVE-2025-69766
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX3 routers by exploiting a stack-based buffer overflow in the formGetIp...

Jan 21, 2026
CVE-2023-54330
9.8

This CVE describes a critical remote stack-based buffer overflow vulnerability in Inbit Messenger versions 4.6.0 to 4.9.0. Unauthenticated attackers c...

Jan 13, 2026
CVE-2023-54334
9.8

Explorer32++ 1.3.5.531 contains a critical buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows remote code executi...

Jan 13, 2026
CVE-2023-54329
9.8

CVE-2023-54329 is a critical remote command execution vulnerability in Inbit Messenger versions 4.6.0 through 4.9.0. Unauthenticated attackers can exp...

Jan 13, 2026
CVE-2026-22189
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Panda3D's egg-mkfont tool. Attackers can exploit this by supplying an exces...

Jan 7, 2026
CVE-2025-34468
9.8

A stack-based buffer overflow vulnerability in libcoap allows remote attackers to crash applications or potentially execute arbitrary code when proxy ...

Dec 31, 2025
CVE-2025-68706
9.8

A stack-based buffer overflow vulnerability in KuWFi 4G LTE AC900 devices allows attackers to crash the web server or potentially execute arbitrary co...

Dec 29, 2025
CVE-2025-11542
9.8

A stack-based buffer overflow vulnerability in Sharp Display Solutions projectors allows attackers to execute arbitrary commands and programs by sendi...

Dec 22, 2025
CVE-2025-11541
9.8

A stack-based buffer overflow vulnerability in Sharp Display Solutions projectors allows attackers to execute arbitrary commands and programs by sendi...

Dec 22, 2025
CVE-2024-58299
9.8

PCMan FTP Server 2.0 contains a critical buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. At...

Dec 12, 2025
CVE-2025-41732
9.8

This critical vulnerability allows unauthenticated remote attackers to exploit unsafe sscanf calls in the check_cookie() function, leading to stack bu...

Dec 10, 2025
CVE-2025-41730
9.8

An unauthenticated remote attacker can exploit unsafe sscanf calls in the check_account() function to write arbitrary data into fixed-size stack buffe...

Dec 10, 2025
CVE-2025-11785
9.8

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 allows remote code execution by sending an excessively large 'meter' par...

Dec 2, 2025
CVE-2025-11786
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices. An attacker can inject arbitrary sh...

Dec 2, 2025
CVE-2025-11782
9.8

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 allows remote code execution by sending an overly long 'meter' parameter...

Dec 2, 2025
CVE-2025-11783
9.8

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 allows remote attackers to execute arbitrary code by sending spec...

Dec 2, 2025
CVE-2025-11784
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices. An attacker can exploit this by sen...

Dec 2, 2025
CVE-2025-11779
9.8

A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 allows remote attackers to execute arbitrary code via the 'SetLan...

Dec 2, 2025
CVE-2025-62691
9.8

This critical vulnerability in MaLion and MaLionCloud Security Point for Windows allows remote unauthenticated attackers to execute arbitrary code wit...

Nov 25, 2025

About CWE-121 (CWE-121)

Our database tracks 947 CVEs classified as CWE-121, with 187 rated critical and 634 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free