CWE-121: CWE-121

1,012
Total CVEs
190
Critical
696
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,012)

CVE-2025-60557
7.5

This buffer overflow vulnerability in D-Link DIR600L routers allows attackers to execute arbitrary code by sending specially crafted requests to the f...

Oct 24, 2025
CVE-2025-60555
7.5

This buffer overflow vulnerability in D-Link DIR600L routers allows attackers to execute arbitrary code by sending specially crafted requests to the f...

Oct 24, 2025
CVE-2025-60552
7.5

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers by exploiting a buffer overflow in the formTcpipSetup f...

Oct 24, 2025
CVE-2025-60550
7.5

A buffer overflow vulnerability in D-Link DIR600L Ax router firmware allows attackers to execute arbitrary code by sending specially crafted requests ...

Oct 24, 2025
CVE-2025-60570
7.5

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers via a buffer overflow in the DNS query logging function...

Oct 24, 2025
CVE-2025-60572
7.5

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers by exploiting a buffer overflow in the formAdvNetwork f...

Oct 24, 2025
CVE-2025-60568
7.5

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers via a buffer overflow in the formAdvFirewall function. ...

Oct 24, 2025
CVE-2025-60333
7.5

This vulnerability is a stack overflow in the wepkey2 parameter of the setWiFiMultipleConfig function in TOTOLINK N600R routers. Attackers can exploit...

Oct 22, 2025
CVE-2025-60331
7.5

A buffer overflow vulnerability exists in the FillMacCloneMac parameter of the /EXCU_SHELL endpoint on D-Link DIR-823G A1 routers running firmware v1....

Oct 22, 2025
CVE-2025-60751
7.5

CVE-2025-60751 is a stack-based buffer overflow vulnerability in GeographicLib's GeoConvert DMS::InternalDecode function. Attackers can exploit this b...

Oct 21, 2025
CVE-2025-20350
7.5

A buffer overflow vulnerability in Cisco phone web interfaces allows unauthenticated remote attackers to cause denial of service by sending crafted HT...

Oct 15, 2025
CVE-2025-61577
7.5

A stack overflow vulnerability in D-Link DIR-816A2 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the statusche...

Oct 9, 2025
CVE-2023-28760
7.5

This vulnerability allows unauthenticated attackers on the local network to execute arbitrary code as root on TP-Link AX1800 routers. Attackers can ex...

Oct 2, 2025
CVE-2025-57060
7.5

A stack overflow vulnerability exists in Tenda G3 routers in the dns_forward_rule_store function's rules parameter. Attackers can exploit this by send...

Sep 9, 2025
CVE-2025-57078
7.5

A stack overflow vulnerability exists in Tenda G3 routers through the pppoeServerWhiteMacIndex parameter in the formModifyPppAuthWhiteMac function. At...

Sep 9, 2025
CVE-2025-57087
7.5

This vulnerability in Tenda W30E routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests that trigger a stac...

Sep 9, 2025
CVE-2025-57063
7.5

This vulnerability in Tenda G3 routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests that trigger a stack ...

Sep 9, 2025
CVE-2025-57069
7.5

This vulnerability in Tenda G3 routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests that trigger a stack ...

Sep 9, 2025
CVE-2025-57071
7.5

A stack overflow vulnerability in Tenda G3 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted requests to the VPN ...

Sep 9, 2025
CVE-2025-57058
7.5

This vulnerability in Tenda G3 routers allows attackers to trigger stack overflows via specially crafted requests to the formSetDebugCfg function, lea...

Sep 9, 2025
CVE-2025-57061
7.5

This vulnerability in Tenda G3 routers allows attackers to trigger stack overflows via specially crafted requests to the formIPMacBindModify function....

Sep 9, 2025
CVE-2025-55852
7.5

This buffer overflow vulnerability in Tenda AC8 routers allows attackers to execute arbitrary code by sending specially crafted requests to the formWi...

Sep 3, 2025
CVE-2025-55763
7.5

A buffer overflow vulnerability in CivetWeb's URI parser allows remote attackers to execute arbitrary code via specially crafted HTTP requests. This a...

Aug 29, 2025
CVE-2025-57215
7.5

A stack-based buffer overflow vulnerability exists in Tenda AC10 routers running firmware v16.03.10.20. Attackers can exploit this via the get_parentC...

Aug 28, 2025
CVE-2025-52194
7.5

A buffer overflow vulnerability in libsndfile allows attackers to execute arbitrary code by tricking applications into processing specially crafted IR...

Aug 21, 2025
CVE-2025-55564
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC15 routers via a stack overflow in the fromSetIpMacBind function. Atta...

Aug 21, 2025
CVE-2025-55498
7.5

This buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the time p...

Aug 20, 2025
CVE-2025-55483
7.5

This CVE describes a buffer overflow vulnerability in Tenda AC6 routers, specifically in the formSetMacFilterCfg function. Attackers can exploit it by...

Aug 20, 2025
CVE-2025-46405
7.5

A vulnerability in F5 BIG-IP APM allows undisclosed traffic to cause the Traffic Management Microkernel (TMM) to terminate when Network Access is conf...

Aug 13, 2025
CVE-2025-36097
7.5

A stack-based buffer overflow vulnerability in IBM WebSphere Application Server allows attackers to cause denial of service by sending specially craft...

Jul 16, 2025
CVE-2024-56468
7.5

This vulnerability in IBM InfoSphere Data Replication VSAM for z/OS allows remote attackers to cause denial of service by sending specially crafted in...

Jul 8, 2025
CVE-2025-6072
7.5

A stack-based buffer overflow vulnerability in ABB RMC-100 and RMC-100 LITE devices allows attackers to execute arbitrary code when exploiting CVE-202...

Jul 3, 2025
CVE-2025-43025
7.5

A buffer overflow vulnerability in HP Universal Print Driver versions 7.4 and older could allow attackers to cause denial of service by crashing the p...

Jul 2, 2025
CVE-2024-53621
7.5

A buffer overflow vulnerability in the formSetCfm() function of Tenda AC1206 routers allows attackers to cause Denial of Service (DoS) via specially c...

Jun 30, 2025
CVE-2025-0649
7.5

A stack-based buffer overflow vulnerability in TensorFlow Serving versions up to 2.18.0 allows attackers to cause denial of service through server cra...

May 6, 2025
CVE-2025-25454
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the AdvSetMacMtuWan function. Atta...

Apr 17, 2025
CVE-2025-25457
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the AdvSetMacMtuWan function. Atta...

Apr 17, 2025
CVE-2025-29121
7.5

A stack-based buffer overflow vulnerability exists in Tenda AC6 routers version V15.03.05.16. Attackers can exploit this by sending specially crafted ...

Mar 20, 2025
CVE-2025-29149
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda i12 routers by exploiting a buffer overflow in the ping1 parameter of th...

Mar 20, 2025
CVE-2024-57440
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected D-Link DSL-3788 routers via a buffer overflow in the web interface's ...

Mar 20, 2025
CVE-2025-29214
7.5

Tenda AX12 routers running firmware version 22.03.01.46_CN contain a stack-based buffer overflow vulnerability in the setMacFilterCfg function. This a...

Mar 20, 2025
CVE-2025-29101
7.5

A stack overflow vulnerability in Tenda AC8V4.0 routers allows attackers to execute arbitrary code or cause denial of service by sending specially cra...

Mar 20, 2025
CVE-2024-52924
7.5

This vulnerability in Samsung Exynos processors allows attackers to execute arbitrary code by sending specially crafted Registration Accept messages. ...

Mar 6, 2025
CVE-2024-47072
7.5

This CVE describes a denial-of-service vulnerability in XStream when configured with BinaryStreamDriver. Attackers can send specially crafted binary i...

Nov 8, 2024
CVE-2024-29012
7.5

A stack-based buffer overflow vulnerability in SonicOS HTTP server allows authenticated remote attackers to cause Denial of Service (DoS) by exploitin...

Jun 20, 2024
CVE-2024-30083
7.5

This vulnerability in Windows Standards-Based Storage Management Service allows attackers to cause a denial of service by sending specially crafted re...

Jun 11, 2024
CVE-2024-5242
7.5

A stack-based buffer overflow vulnerability in TP-Link Omada ER605 routers allows network-adjacent attackers to execute arbitrary code as root without...

May 23, 2024
CVE-2024-32317
7.5

This CVE describes a stack overflow vulnerability in Tenda AC10 routers that allows attackers to execute arbitrary code by sending specially crafted r...

Apr 17, 2024
CVE-2024-32291
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda W30E routers by exploiting a stack overflow in the fromNatlimit function...

Apr 17, 2024
CVE-2024-30392
7.5

A stack-based buffer overflow vulnerability in Juniper's flowd daemon allows unauthenticated network attackers to cause denial of service by sending s...

Apr 12, 2024

About CWE-121 (CWE-121)

Our database tracks 1,012 CVEs classified as CWE-121, with 190 rated critical and 696 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free