CWE-121: CWE-121

1,009
Total CVEs
189
Critical
694
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,009)

CVE-2023-48264
8.1

This vulnerability in Bosch products allows unauthenticated remote attackers to cause denial-of-service or potentially execute arbitrary code by sendi...

Jan 10, 2024
CVE-2023-44305
8.1

CVE-2023-44305 is a stack-based buffer overflow vulnerability in Dell DM5500 appliances that allows unauthenticated remote attackers to crash services...

Dec 4, 2023
CVE-2020-25856
8.1

A stack buffer overflow vulnerability in Realtek RTL8195A Wi-Fi modules allows remote code execution or denial of service when an attacker impersonate...

Feb 3, 2021
CVE-2020-25854
8.1

This vulnerability in Realtek RTL8195A Wi-Fi modules allows remote code execution or denial of service through a stack buffer overflow during WPA2 han...

Feb 3, 2021
CVE-2024-41586
8.0

A stack-based buffer overflow vulnerability in DrayTek Vigor310 devices allows remote attackers to execute arbitrary code by sending a specially craft...

Oct 3, 2024
CVE-2024-41590
8.0

This vulnerability allows authenticated users to exploit buffer overflows in CGI endpoints on DrayTek Vigor310 devices by sending specially crafted PO...

Oct 3, 2024
CVE-2024-41592
8.0

DrayTek Vigor3910 devices have a stack-based buffer overflow vulnerability in the GetCGI function that processes query string parameters. Attackers ca...

Oct 3, 2024
CVE-2024-23959
8.0

This vulnerability allows attackers on the same network to execute arbitrary code on Autel MaxiCharger AC Elite Business C50 charging stations by expl...

Sep 28, 2024
CVE-2024-23967
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code on Autel MaxiCharger AC Elite Business C50 electric vehicle chargers by...

Sep 28, 2024
CVE-2024-23935
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code with root privileges on Alpine Halo9 devices by exploiting a stack-base...

Sep 28, 2024
CVE-2024-44859
8.0

CVE-2024-44859 is a stack buffer overflow vulnerability in the formWrlExtraGet function of Tenda FH1201 routers. This allows attackers to execute arbi...

Sep 4, 2024
CVE-2024-37978
8.0

This vulnerability allows attackers to bypass Secure Boot protections on affected systems, potentially enabling them to load and execute unauthorized ...

Jul 9, 2024
CVE-2024-37971
8.0

This Secure Boot vulnerability allows attackers to bypass security features during the boot process, potentially loading unauthorized code. It affects...

Jul 9, 2024
CVE-2024-35578
8.0

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1806 routers via a stack overflow in the formSetIptv function. Attacke...

May 20, 2024
CVE-2023-51628
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DCS-8300LHV2 IP cameras by exploiting a stack-based b...

May 3, 2024
CVE-2023-51613
8.0

This vulnerability allows network-adjacent attackers with authentication to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw exist...

May 3, 2024
CVE-2023-44431
8.0

This vulnerability allows attackers within Bluetooth range to execute arbitrary code with root privileges on systems running vulnerable BlueZ installa...

May 3, 2024
CVE-2023-41184
8.0

This vulnerability allows attackers on the same network to execute arbitrary code as root on TP-Link Tapo C210 IP cameras. Attackers can bypass authen...

May 3, 2024
CVE-2024-32303
8.0

This CVE describes a stack overflow vulnerability in Tenda AC15 router firmware versions v15.03.20_multi, v15.03.05.19, and v15.03.05.18. The vulnerab...

Apr 17, 2024
CVE-2024-32293
8.0

This CVE describes a stack overflow vulnerability in Tenda W30E routers via the page parameter in the fromDhcpListClient function. Attackers can explo...

Apr 17, 2024
CVE-2024-32310
8.0

This CVE describes a stack overflow vulnerability in Tenda F1203 routers that allows attackers to execute arbitrary code by sending specially crafted ...

Apr 17, 2024
CVE-2024-28925
8.0

This vulnerability allows attackers to bypass Secure Boot protections on affected systems, potentially enabling them to load and execute unauthorized ...

Apr 9, 2024
CVE-2024-26180
8.0

This vulnerability allows attackers to bypass Secure Boot protections on affected systems, potentially enabling them to load and execute unauthorized ...

Apr 9, 2024
CVE-2024-30626
8.0

This CVE describes a stack overflow vulnerability in Tenda FH1205 routers that allows remote attackers to execute arbitrary code by sending specially ...

Mar 29, 2024
CVE-2024-30601
8.0

This vulnerability allows remote attackers to execute arbitrary code on Tenda FH1203 routers by exploiting a stack overflow in the saveParentControlIn...

Mar 28, 2024
CVE-2024-30606
8.0

This vulnerability allows remote attackers to execute arbitrary code on Tenda FH1203 routers by exploiting a stack overflow in the DHCP client list fu...

Mar 28, 2024
CVE-2024-30583
8.0

This CVE describes a stack overflow vulnerability in Tenda FH1202 routers that allows remote code execution. Attackers can exploit the mitInterface pa...

Mar 28, 2024
CVE-2024-25756
8.0

A stack-based buffer overflow vulnerability in Tenda AC9 v.3.0 routers allows remote attackers to execute arbitrary code via the formWifiBasicSet func...

Feb 22, 2024
CVE-2023-35634
8.0

This vulnerability allows an unauthenticated attacker within Bluetooth range to execute arbitrary code on affected Windows systems by sending speciall...

Dec 12, 2023
CVE-2022-24973
8.0

This is a stack-based buffer overflow vulnerability in TP-Link TL-WR940N routers that allows authenticated attackers on the same network to execute ar...

Mar 28, 2023
CVE-2023-23780
8.0

This CVE describes a stack-based buffer overflow vulnerability in Fortinet FortiWeb web application firewalls. Attackers can exploit it via specially ...

Feb 16, 2023
CVE-2021-44158
8.0

ASUS RT-AX56U Wi-Fi routers have a stack-based buffer overflow vulnerability in their httpd service. An authenticated attacker on the local network ca...

Jan 3, 2022
CVE-2021-27246
8.0

This vulnerability allows attackers on the same network to execute arbitrary code as root on TP-Link Archer A7 AC1750 routers without authentication. ...

Apr 14, 2021
CVE-2025-20618
7.9

A stack-based buffer overflow vulnerability in Intel PROSet/Wireless WiFi Software for Windows allows privileged local users to cause denial of servic...

May 13, 2025
CVE-2022-33264
7.9

CVE-2022-33264 is a stack-based buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when parsing OTASP Key Generati...

Jun 6, 2023
CVE-2019-25435
7.8

CVE-2019-25435 is a local buffer overflow vulnerability in Sricam DeviceViewer 3.12.0.1 that allows authenticated attackers to execute arbitrary code ...

Feb 20, 2026
CVE-2025-70083
7.8

A stack buffer overflow vulnerability in OpenSatKit 2.2.1 allows remote attackers to execute arbitrary code by sending specially crafted telecommands ...

Feb 11, 2026
CVE-2026-22923
7.8

A data validation vulnerability in NX software versions before V2512 allows local attackers to manipulate internal data during PDF export, potentially...

Feb 10, 2026
CVE-2026-0660
7.8

A stack-based buffer overflow vulnerability in Autodesk 3ds Max allows arbitrary code execution when parsing malicious GIF files. This affects users w...

Feb 4, 2026
CVE-2026-25502
7.8

A stack-based buffer overflow vulnerability in iccDEV's icFixXml() function allows attackers to execute arbitrary code by crafting malicious NamedColo...

Feb 3, 2026
CVE-2026-1361
7.8

CVE-2026-1361 is a stack-based buffer overflow vulnerability in Delta Electronics' ASDA-Soft software that allows attackers to execute arbitrary code ...

Jan 27, 2026
CVE-2026-21224
7.8

A stack-based buffer overflow vulnerability in Azure Connected Machine Agent allows authenticated attackers to execute arbitrary code with elevated pr...

Jan 13, 2026
CVE-2025-20797
7.8

This CVE describes a buffer overflow vulnerability in MediaTek battery management software that allows local privilege escalation. Attackers with init...

Jan 6, 2026
CVE-2025-14423
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious LBM image files in GIMP. The flaw is a s...

Dec 23, 2025
CVE-2025-14936
7.8

This is a stack-based buffer overflow vulnerability in NSF Unidata NetCDF-C library that allows remote code execution when processing malicious NetCDF...

Dec 23, 2025
CVE-2025-14932
7.8

A stack-based buffer overflow vulnerability in NSF Unidata NetCDF-C allows remote attackers to execute arbitrary code when users process malicious fil...

Dec 23, 2025
CVE-2025-14934
7.8

This is a stack-based buffer overflow vulnerability in NSF Unidata NetCDF-C that allows remote attackers to execute arbitrary code. Attackers can expl...

Dec 23, 2025
CVE-2025-34451
7.8

A stack-based buffer overflow vulnerability exists in proxychains-ng versions up to 4.17, allowing attackers to cause denial of service or potentially...

Dec 18, 2025
CVE-2025-34450
7.8

A stack-based buffer overflow vulnerability in rtl_433's parse_rfraw() function allows attackers to cause denial of service or potentially execute arb...

Dec 18, 2025
CVE-2025-64469
7.8

A stack-based buffer overflow vulnerability in NI LabVIEW's LVResFile::FindRsrcListEntry() function allows attackers to execute arbitrary code or disc...

Dec 18, 2025

About CWE-121 (CWE-121)

Our database tracks 1,009 CVEs classified as CWE-121, with 189 rated critical and 694 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free