CWE-121: CWE-121

1,009
Total CVEs
189
Critical
694
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,009)

CVE-2024-37008
7.8

A stack-based buffer overflow vulnerability in Autodesk Revit allows arbitrary code execution when processing malicious DWG files. Attackers can explo...

Aug 21, 2024
CVE-2024-7013
7.8

A stack-based buffer overflow vulnerability in Control FPWIN Pro programming software allows attackers to execute arbitrary code by tricking users int...

Aug 21, 2024
CVE-2023-50809
7.8

This vulnerability allows remote attackers to execute arbitrary code within the kernel of affected Sonos devices by exploiting a stack buffer overflow...

Aug 12, 2024
CVE-2024-7502
7.8

A stack-based buffer overflow vulnerability in Delta Electronics DIAScreen allows remote code execution when processing malicious DPA files. This affe...

Aug 6, 2024
CVE-2024-7547
7.8

This is a stack-based buffer overflow vulnerability in oFono's SMS PDU decoder that allows local attackers to execute arbitrary code with service acco...

Aug 6, 2024
CVE-2024-7538
7.8

This vulnerability in oFono allows local attackers to execute arbitrary code with root privileges by exploiting a stack-based buffer overflow in AT co...

Aug 6, 2024
CVE-2024-37997
7.8

A stack-based buffer overflow vulnerability in Siemens JT Open, JT2Go, PLM XML SDK, and Teamcenter Visualization products allows remote code execution...

Jul 9, 2024
CVE-2024-23110
7.8

This CVE describes a stack-based buffer overflow vulnerability in Fortinet FortiOS that allows attackers to execute arbitrary code or commands via spe...

Jun 11, 2024
CVE-2024-5507
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Luxion KeyShot Viewer. Attackers can ex...

Jun 6, 2024
CVE-2024-34171
7.8

Fuji Electric Monitouch V-SFT software is vulnerable to a stack-based buffer overflow, allowing attackers to execute arbitrary code on affected system...

May 30, 2024
CVE-2024-24686
7.8

This CVE describes stack-based buffer overflow vulnerabilities in libigl's readOFF function when parsing malicious .off files. Attackers can exploit t...

May 28, 2024
CVE-2024-24684
7.8

This CVE describes multiple stack-based buffer overflow vulnerabilities in libigl v2.5.0's readOFF function. Attackers can exploit these by providing ...

May 28, 2024
CVE-2023-35953
7.8

This vulnerability allows arbitrary code execution via stack-based buffer overflow when libigl parses malicious .off files. Attackers can exploit spec...

May 28, 2024
CVE-2023-35949
7.8

CVE-2023-35949 is a stack-based buffer overflow vulnerability in libigl's OFF file parser that allows arbitrary code execution when processing malicio...

May 28, 2024
CVE-2023-35951
7.8

This vulnerability allows remote code execution through specially crafted .off files in libigl v2.4.0. Attackers can exploit stack-based buffer overfl...

May 28, 2024
CVE-2024-34773
7.8

A stack overflow vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files. This affec...

May 14, 2024
CVE-2023-50235
7.8

A stack-based buffer overflow vulnerability in Hancom Office Show's PPT file parser allows remote attackers to execute arbitrary code when users open ...

May 3, 2024
CVE-2023-42069
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

May 3, 2024
CVE-2023-40485
7.8

A stack-based buffer overflow vulnerability in Maxon Cinema 4D's SKP file parser allows remote attackers to execute arbitrary code when users open mal...

May 3, 2024
CVE-2023-38093
7.8

This is a stack-based buffer overflow vulnerability in Kofax Power PDF's saveAs method that allows remote code execution when users open malicious PDF...

May 3, 2024
CVE-2023-37331
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious GIF files in Kofax Power PDF. Attackers ...

May 3, 2024
CVE-2023-35710
7.8

A stack-based buffer overflow vulnerability in Ashlar-Vellum Cobalt allows remote attackers to execute arbitrary code when users open malicious CO fil...

May 3, 2024
CVE-2023-34287
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious CO...

May 3, 2024
CVE-2024-4192
7.8

Delta Electronics CNCSoft-G2 has a stack-based buffer overflow vulnerability due to improper length validation of user-supplied data. This allows atta...

Apr 30, 2024
CVE-2024-30273
7.8

A stack-based buffer overflow vulnerability in Adobe Illustrator allows arbitrary code execution when a user opens a malicious file. This affects user...

Apr 11, 2024
CVE-2024-20772
7.8

This CVE describes a stack-based buffer overflow vulnerability in Adobe Media Encoder that could allow arbitrary code execution when a user opens a ma...

Apr 10, 2024
CVE-2024-29061
7.8

CVE-2024-29061 is a Secure Boot security feature bypass vulnerability that allows attackers to bypass Secure Boot protections on affected systems. Thi...

Apr 9, 2024
CVE-2024-27337
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious TIF files in Kofax Power PDF. Attackers ...

Apr 3, 2024
CVE-2024-1941
7.8

Delta Electronics CNCSoft-B versions 1.0.0.4 and prior contain a stack-based buffer overflow vulnerability that could allow remote attackers to execut...

Mar 1, 2024
CVE-2024-23804
7.8

A stack overflow vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by tricking users into opening malicious PSOB...

Feb 13, 2024
CVE-2024-23797
7.8

A stack overflow vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by tricking users into opening malicious WRL ...

Feb 13, 2024
CVE-2023-7206
7.8

This vulnerability in Horner Automation Cscape allows local attackers to execute arbitrary code by tricking users into opening malicious CSP files. It...

Jan 15, 2024
CVE-2023-35704
7.8

This vulnerability allows arbitrary code execution when a user opens a malicious .fst file in GTKWave. Attackers can exploit stack-based buffer overfl...

Jan 8, 2024
CVE-2023-35702
7.8

This CVE describes multiple stack-based buffer overflow vulnerabilities in GTKWave's FST LEB128 varint parsing functionality. Attackers can craft mali...

Jan 8, 2024
CVE-2023-5944
7.8

Delta Electronics DOPSoft software contains a stack-based buffer overflow vulnerability that allows arbitrary code execution when a user opens a speci...

Dec 4, 2023
CVE-2023-35127
7.8

A stack-based buffer overflow vulnerability in Fuji Electric Tellus Lite V-Simulator allows remote attackers to execute arbitrary code by tricking a u...

Nov 22, 2023
CVE-2023-36729
7.8

This vulnerability allows an authenticated attacker to exploit the Named Pipe File System to elevate privileges on a Windows system. It affects Window...

Oct 10, 2023
CVE-2023-45601
7.8

This vulnerability allows remote code execution through stack overflow when parsing malicious IGS files in Siemens Parasolid and Tecnomatix Plant Simu...

Oct 10, 2023
CVE-2019-16470
7.8

A stack-based buffer overflow vulnerability in Adobe Acrobat Reader allows attackers to execute arbitrary code when a user opens a malicious PDF file....

Sep 11, 2023
CVE-2023-4685
7.8

Delta Electronics' CNCSoft-B and DOPSoft software contain a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code ...

Sep 7, 2023
CVE-2023-37375
7.8

A stack-based buffer overflow vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by tricking users into opening m...

Jul 11, 2023
CVE-2023-1709
7.8

This vulnerability in Datalogics Library APDFL allows attackers to trigger a stack-based buffer overflow by providing documents with corrupted fonts. ...

Jun 7, 2023
CVE-2023-29503
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting a stack-based buffer overflow in project file parsing. Systems running aff...

Jun 6, 2023
CVE-2023-29284
7.8

This CVE describes a stack-based buffer overflow vulnerability in Adobe Substance 3D Painter that allows arbitrary code execution when a user opens a ...

May 11, 2023
CVE-2023-26390
7.8

Adobe Substance 3D Stager versions 2.0.1 and earlier contain a stack-based buffer overflow vulnerability that allows arbitrary code execution when a u...

Apr 12, 2023
CVE-2023-26383
7.8

CVE-2023-26383 is a stack-based buffer overflow vulnerability in Adobe Substance 3D Stager that allows arbitrary code execution when a user opens a ma...

Apr 12, 2023
CVE-2022-43613
7.8

CVE-2022-43613 is a stack-based buffer overflow vulnerability in CorelDRAW Graphics Suite that allows remote code execution when processing malicious ...

Mar 29, 2023
CVE-2022-28305
7.8

This is a stack-based buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious OBJ fi...

Mar 29, 2023
CVE-2022-27648
7.8

CVE-2022-27648 is a stack-based buffer overflow vulnerability in KOYO Screen Creator 0.1.1.1 that allows remote attackers to execute arbitrary code wh...

Mar 29, 2023
CVE-2023-26337
7.8

This CVE describes a stack-based buffer overflow vulnerability in Adobe Dimension that could allow arbitrary code execution when a user opens a malici...

Mar 28, 2023

About CWE-121 (CWE-121)

Our database tracks 1,009 CVEs classified as CWE-121, with 189 rated critical and 694 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free