CWE-121: CWE-121

1,010
Total CVEs
190
Critical
694
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,010)

CVE-2018-5410
7.8

CVE-2018-5410 is a stack-based buffer overflow vulnerability in the Dokan file system driver (dokan1.sys) that allows local attackers to execute arbit...

Jan 7, 2019
CVE-2024-47939
7.7

A stack-based buffer overflow vulnerability in Ricoh Web Image Monitor allows attackers to execute arbitrary code or cause denial-of-service by sendin...

Nov 1, 2024
CVE-2025-69195
7.6

A stack-based buffer overflow vulnerability in GNU Wget2's filename sanitization logic allows remote attackers to trigger memory corruption via specia...

Jan 9, 2026
CVE-2024-41630
7.6

A stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by sending specially crafted reque...

Jul 31, 2024
CVE-2019-12266
7.6

A stack-based buffer overflow vulnerability in Wyze Cam devices allows attackers to execute arbitrary code on affected cameras. This affects Wyze Cam ...

Mar 30, 2022
CVE-2019-25340
7.5

CVE-2019-25340 is a stack-based buffer overflow vulnerability in SpotAuditor's Base64 decryption feature that allows attackers to cause denial of serv...

Feb 12, 2026
CVE-2019-25339
7.5

GHIA CamIP 1.2 for iOS contains a denial of service vulnerability where attackers can crash the application by pasting a 33-character buffer of repeat...

Feb 12, 2026
CVE-2019-25329
7.5

CVE-2019-25329 is a buffer overflow vulnerability in FTP Navigator 8.03 that allows attackers to crash the application via denial of service by overwr...

Feb 12, 2026
CVE-2019-25330
7.5

SurfOffline Professional 2.2.0.103 contains a structured exception handler overflow vulnerability in project name input. Attackers can crash the appli...

Feb 12, 2026
CVE-2025-67432
7.5

A stack overflow vulnerability in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause Denial o...

Feb 12, 2026
CVE-2020-37200
7.5

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input field. Attackers can crash the application by supplying...

Feb 11, 2026
CVE-2025-63658
7.5

A stack overflow vulnerability in Monkey web server's mk_http_index_lookup function allows attackers to cause denial of service by sending specially c...

Jan 29, 2026
CVE-2025-70648
7.5

Tenda AX1803 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the security_5g parameter handling. Attackers can send crafte...

Jan 21, 2026
CVE-2025-70644
7.5

Tenda AX-1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the time parameter handling. Attackers can exploit this to c...

Jan 21, 2026
CVE-2025-70646
7.5

Tenda AX1803 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the security parameter handling. Attackers can send crafted r...

Jan 21, 2026
CVE-2025-70645
7.5

This CVE describes a stack overflow vulnerability in Tenda AX-1806 routers that allows attackers to cause Denial of Service (DoS) by sending specially...

Jan 21, 2026
CVE-2025-70650
7.5

CVE-2025-70650 is a stack overflow vulnerability in Tenda AX-1806 routers that allows attackers to cause a Denial of Service (DoS) by sending speciall...

Jan 21, 2026
CVE-2025-70651
7.5

A stack overflow vulnerability in Tenda AX-1803 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted requests to the...

Jan 21, 2026
CVE-2025-70746
7.5

A stack overflow vulnerability in Tenda AX-1806 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted requests to the...

Jan 16, 2026
CVE-2025-71020
7.5

Tenda AX-1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the security parameter handling. Attackers can exploit this ...

Jan 16, 2026
CVE-2025-70307
7.5

A stack overflow vulnerability in GPAC's dump_ttxt_sample function allows attackers to cause Denial of Service by sending specially crafted packets. T...

Jan 15, 2026
CVE-2025-70656
7.5

CVE-2025-70656 is a stack overflow vulnerability in Tenda AX-1806 routers that allows attackers to cause Denial of Service (DoS) by sending specially ...

Jan 15, 2026
CVE-2025-70304
7.5

A buffer overflow vulnerability in GPAC's vobsub_get_subpic_duration() function allows attackers to cause denial of service by sending specially craft...

Jan 15, 2026
CVE-2025-70744
7.5

Tenda AX-1806 routers version 1.0.0.1 contain a stack overflow vulnerability in the cloneType parameter that allows attackers to cause Denial of Servi...

Jan 15, 2026
CVE-2025-71019
7.5

This vulnerability in Tenda AX-1806 routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests that trigger a s...

Jan 15, 2026
CVE-2025-70747
7.5

Tenda AX-1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the serviceName parameter that allows remote attackers to cr...

Jan 14, 2026
CVE-2025-71021
7.5

Tenda AX-1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the serverName parameter that allows attackers to crash the ...

Jan 14, 2026
CVE-2025-65805
7.5

OpenAirInterface CN5G AMF versions up to v2.1.9 have a buffer overflow vulnerability when processing NAS messages with overly long IMSI strings. Unaut...

Jan 7, 2026
CVE-2025-66877
7.5

A buffer overflow vulnerability in the dcputchar function of libming 0.4.8 allows attackers to execute arbitrary code or cause denial of service. This...

Dec 29, 2025
CVE-2025-66865
7.5

A stack-based buffer overflow vulnerability exists in the cp-demangle.c file of BinUtils 2.26, specifically in the d_print_comp_inner function. Attack...

Dec 29, 2025
CVE-2023-53886
7.5

Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the app...

Dec 15, 2025
CVE-2025-64344
7.5

A stack overflow vulnerability in Suricata's Lua scripting engine allows attackers to cause denial of service or potentially execute arbitrary code by...

Nov 26, 2025
CVE-2025-64332
7.5

A stack overflow vulnerability in Suricata's SWF decompression feature can cause the IDS/IPS engine to crash when processing malicious SWF files. This...

Nov 26, 2025
CVE-2025-40601
7.5

A stack-based buffer overflow vulnerability in SonicOS SSLVPN service allows remote unauthenticated attackers to cause denial of service by crashing a...

Nov 20, 2025
CVE-2025-58413
7.5

A stack-based buffer overflow vulnerability in Fortinet FortiOS and FortiSASE allows attackers to execute arbitrary code via specially crafted packets...

Nov 18, 2025
CVE-2025-53843
7.5

A stack-based buffer overflow vulnerability in Fortinet FortiOS allows attackers to execute arbitrary code via specially crafted packets. This affects...

Nov 18, 2025
CVE-2025-60694
7.5

A stack-based buffer overflow vulnerability in Linksys E1200 v2 routers allows remote attackers to execute arbitrary code or cause denial of service w...

Nov 13, 2025
CVE-2025-63149
7.5

This CVE describes a stack overflow vulnerability in Tenda AX3 routers running firmware version V16.03.12.10_CN. Attackers can exploit this by sending...

Nov 10, 2025
CVE-2025-63458
7.5

Tenda AX-1803 routers version 1.0.0.1 contain a stack overflow vulnerability in the timeZone parameter of the form_fast_setting_wifi_set function. Att...

Oct 31, 2025
CVE-2025-63459
7.5

This vulnerability is a stack overflow in Totolink A7000R routers that allows attackers to cause a Denial of Service (DoS) by sending a specially craf...

Oct 31, 2025
CVE-2025-63460
7.5

This vulnerability is a stack overflow in Totolink A7000R routers that allows attackers to cause a Denial of Service (DoS) by sending a specially craf...

Oct 31, 2025
CVE-2025-63462
7.5

This CVE describes a stack overflow vulnerability in Totolink A7000R routers via the wifiOff parameter. Attackers can send crafted requests to trigger...

Oct 31, 2025
CVE-2025-63464
7.5

This CVE describes a stack overflow vulnerability in Totolink LR350 routers via the ssid parameter. Attackers can exploit this to cause Denial of Serv...

Oct 31, 2025
CVE-2025-63468
7.5

This CVE describes a stack overflow vulnerability in Totolink LR350 routers via the http_host parameter. Attackers can exploit this to cause Denial of...

Oct 31, 2025
CVE-2025-63466
7.5

This vulnerability is a stack overflow in the Totolink LR350 router's password parameter handling that allows attackers to cause Denial of Service (Do...

Oct 31, 2025
CVE-2025-60565
7.5

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers via a buffer overflow in the schedule configuration fun...

Oct 24, 2025
CVE-2025-60563
7.5

This buffer overflow vulnerability in D-Link DIR600L routers allows attackers to execute arbitrary code by sending specially crafted requests to the f...

Oct 24, 2025
CVE-2025-60561
7.5

This buffer overflow vulnerability in D-Link DIR600L routers allows attackers to execute arbitrary code by sending specially crafted requests to the f...

Oct 24, 2025
CVE-2025-60558
7.5

This buffer overflow vulnerability in D-Link DIR600L routers allows attackers to execute arbitrary code by sending specially crafted requests to the f...

Oct 24, 2025
CVE-2025-60557
7.5

This buffer overflow vulnerability in D-Link DIR600L routers allows attackers to execute arbitrary code by sending specially crafted requests to the f...

Oct 24, 2025

About CWE-121 (CWE-121)

Our database tracks 1,010 CVEs classified as CWE-121, with 190 rated critical and 694 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free