CWE-121: CWE-121

1,009
Total CVEs
189
Critical
694
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,009)

CVE-2025-20737
7.8

This CVE describes a buffer overflow vulnerability in MediaTek's wlan AP driver where improper bounds checking allows out-of-bounds writes. An attacke...

Nov 4, 2025
CVE-2025-47360
7.8

This vulnerability allows memory corruption during device management message processing in Qualcomm components, potentially enabling remote code execu...

Nov 4, 2025
CVE-2025-62580
7.8

A stack-based buffer overflow vulnerability in Delta Electronics' ASDA-Soft software allows attackers to execute arbitrary code by sending specially c...

Oct 16, 2025
CVE-2025-62579
7.8

A stack-based buffer overflow vulnerability in Delta Electronics' ASDA-Soft software allows attackers to execute arbitrary code by sending specially c...

Oct 16, 2025
CVE-2025-24052
7.8

This CVE addresses vulnerabilities in the third-party Agere Modem driver (ltmdm64.sys) that ships with Windows. Exploitation could allow attackers to ...

Oct 14, 2025
CVE-2025-20717
7.8

This vulnerability in MediaTek wlan AP driver allows local privilege escalation through an out-of-bounds write due to incorrect bounds checking. An at...

Oct 14, 2025
CVE-2025-20718
7.8

This vulnerability in MediaTek WLAN AP drivers allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated system...

Oct 14, 2025
CVE-2025-20713
7.8

This CVE describes an out-of-bounds write vulnerability in MediaTek's wlan AP driver due to incorrect bounds checking. It allows local privilege escal...

Oct 14, 2025
CVE-2025-61856
7.8

A stack-based buffer overflow vulnerability in V-SFT v6.2.7.0 and earlier allows attackers to execute arbitrary code by tricking users into opening ma...

Oct 10, 2025
CVE-2025-58776
7.8

KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability that allows remote code execution when processing specially cra...

Oct 2, 2025
CVE-2025-58775
7.8

A stack-based buffer overflow vulnerability in KEYENCE KV STUDIO and VT5-WX15/WX12 products allows remote code execution when processing specially cra...

Oct 2, 2025
CVE-2025-58317
7.8

Delta Electronics CNCSoft-G2 has a stack-based buffer overflow vulnerability due to improper file validation. Attackers can execute arbitrary code by ...

Sep 24, 2025
CVE-2025-7979
7.8

A stack-based buffer overflow vulnerability in Ashlar-Vellum Graphite's VC6 file parser allows remote attackers to execute arbitrary code when users o...

Sep 17, 2025
CVE-2025-54916
7.8

A stack-based buffer overflow vulnerability in Windows NTFS allows authenticated attackers to execute arbitrary code locally on vulnerable systems. Th...

Sep 9, 2025
CVE-2025-49564
7.8

A stack-based buffer overflow vulnerability in Adobe Illustrator allows arbitrary code execution when a user opens a malicious file. This affects Illu...

Aug 12, 2025
CVE-2025-23284
7.8

This vulnerability in NVIDIA vGPU software allows a malicious guest virtual machine to trigger a stack buffer overflow in the Virtual GPU Manager. Suc...

Aug 2, 2025
CVE-2025-23283
7.8

A stack buffer overflow vulnerability in NVIDIA vGPU Manager for Linux hypervisors allows malicious guest VMs to potentially execute arbitrary code or...

Aug 2, 2025
CVE-2025-33092
7.8

A local user can exploit a stack-based buffer overflow in IBM Db2's db2fm component on Linux systems to execute arbitrary code with elevated privilege...

Jul 29, 2025
CVE-2025-49528
7.8

A stack-based buffer overflow vulnerability in Adobe Illustrator allows arbitrary code execution when a user opens a malicious file. This affects Illu...

Jul 8, 2025
CVE-2025-6663
7.8

This CVE describes a stack-based buffer overflow vulnerability in GStreamer's H266 codec parsing, specifically in SEI message handling. Attackers can ...

Jul 7, 2025
CVE-2025-3481
7.8

This vulnerability allows remote attackers to execute arbitrary code on MedDream PACS Server installations without authentication by sending specially...

May 22, 2025
CVE-2025-3483
7.8

This vulnerability allows remote attackers to execute arbitrary code on MedDream PACS Server installations without authentication by sending specially...

May 22, 2025
CVE-2025-47758
7.8

A stack-based buffer overflow vulnerability in V-SFT v6.2.5.0 and earlier allows attackers to execute arbitrary code by tricking users into opening sp...

May 19, 2025
CVE-2025-47760
7.8

This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of V-SFT software by exploiting a stack-based buf...

May 19, 2025
CVE-2025-30421
7.8

A stack-based buffer overflow vulnerability in NI Circuit Design Suite's SymbolEditor allows attackers to execute arbitrary code or disclose informati...

May 15, 2025
CVE-2025-4447
7.8

A stack-based buffer overflow vulnerability in Eclipse OpenJ9 when used with OpenJDK 8 allows local attackers to execute arbitrary code by modifying a...

May 9, 2025
CVE-2025-24075
7.8

A stack-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on vulnerable systems by tricking use...

Mar 11, 2025
CVE-2025-26595
7.8

A stack-based buffer overflow vulnerability in X.Org and Xwayland allows attackers to execute arbitrary code or cause denial of service. This affects ...

Feb 25, 2025
CVE-2025-24928
7.8

This CVE describes a stack-based buffer overflow vulnerability in libxml2's xmlSnprintfElements function. Attackers can exploit this by providing mali...

Feb 18, 2025
CVE-2025-21163
7.8

A stack-based buffer overflow vulnerability in Adobe Illustrator allows attackers to execute arbitrary code when a user opens a malicious file. This a...

Feb 11, 2025
CVE-2024-11609
7.8

A stack-based buffer overflow vulnerability in AutomationDirect C-More EA9 programming software allows remote attackers to execute arbitrary code when...

Jan 30, 2025
CVE-2024-34579
7.8

This vulnerability in Fuji Electric Alpha5 SMART allows attackers to execute arbitrary code through a stack-based buffer overflow. It affects industri...

Jan 17, 2025
CVE-2025-21128
7.8

CVE-2025-21128 is a stack-based buffer overflow vulnerability in Substance3D Stager that allows arbitrary code execution when a user opens a malicious...

Jan 14, 2025
CVE-2024-45542
7.8

This vulnerability allows memory corruption when a user-space application makes a specific IOCTL call to write board data to the WLAN driver. Attacker...

Jan 6, 2025
CVE-2024-13045
7.8

A stack-based buffer overflow vulnerability in Ashlar-Vellum Cobalt's AR file parser allows remote attackers to execute arbitrary code when a user ope...

Dec 30, 2024
CVE-2024-53959
7.8

CVE-2024-53959 is a stack-based buffer overflow vulnerability in Adobe Framemaker that allows arbitrary code execution when a user opens a malicious f...

Dec 10, 2024
CVE-2024-49543
7.8

A stack-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users r...

Dec 10, 2024
CVE-2024-53041
7.8

A stack-based buffer overflow vulnerability in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation allows remote code execution when pars...

Dec 10, 2024
CVE-2024-43050
7.8

This vulnerability allows local attackers to cause memory corruption in WLAN drivers by sending specially crafted IOCTL calls. It affects systems with...

Dec 2, 2024
CVE-2024-43048
7.8

This vulnerability allows memory corruption when invalid input is passed to the GPU Headroom API call in Qualcomm components. Attackers could potentia...

Dec 2, 2024
CVE-2024-38309
7.8

Multiple stack-based buffer overflow vulnerabilities in Fuji Electric's V-SFT, TELLUS, and TELLUS Lite software allow attackers to execute arbitrary c...

Nov 28, 2024
CVE-2024-11795
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Monitouch V-SFT V8 installations by exploiting a stack-based buf...

Nov 28, 2024
CVE-2024-11799
7.8

A stack-based buffer overflow vulnerability in Fuji Electric Tellus Lite V-Simulator 5 allows remote attackers to execute arbitrary code when users op...

Nov 28, 2024
CVE-2024-11789
7.8

A stack-based buffer overflow vulnerability in Fuji Electric Monitouch V-SFT V10 file parsing allows remote attackers to execute arbitrary code when u...

Nov 28, 2024
CVE-2024-11791
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Monitouch V-SFT installations by tricking users into opening mal...

Nov 28, 2024
CVE-2024-9745
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious TIF files in Tungsten Automation Power P...

Nov 22, 2024
CVE-2024-47131
7.8

This vulnerability allows remote code execution through a stack-based buffer overflow in Delta Electronics DIAScreen's BACnetObjectInfo component. Att...

Nov 11, 2024
CVE-2024-39354
7.8

This vulnerability allows remote code execution through a stack-based buffer overflow in Delta Electronics DIAScreen software. Attackers can exploit i...

Nov 11, 2024
CVE-2024-47410
7.8

A stack-based buffer overflow vulnerability in Adobe Animate allows arbitrary code execution when a user opens a malicious file. This affects users of...

Oct 9, 2024
CVE-2024-41170
7.8

A stack-based buffer overflow vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by tricking users into opening m...

Sep 10, 2024

About CWE-121 (CWE-121)

Our database tracks 1,009 CVEs classified as CWE-121, with 189 rated critical and 694 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free