CWE-121: CWE-121

1,014
Total CVEs
191
Critical
697
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,014)

CVE-2024-32291
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda W30E routers by exploiting a stack overflow in the fromNatlimit function...

Apr 17, 2024
CVE-2024-30392
7.5

A stack-based buffer overflow vulnerability in Juniper's flowd daemon allows unauthenticated network attackers to cause denial of service by sending s...

Apr 12, 2024
CVE-2023-48724
7.5

An unauthenticated memory corruption vulnerability in TP-Link EAP225 V3 access points allows attackers to crash the web interface via specially crafte...

Apr 9, 2024
CVE-2023-0656
7.5

A stack-based buffer overflow vulnerability in SonicOS allows remote unauthenticated attackers to trigger a denial of service by crashing affected fir...

Mar 2, 2023
CVE-2023-22842
7.5

This vulnerability affects F5 BIG-IP systems with specific configurations, causing the Traffic Management Microkernel (TMM) to crash when processing c...

Feb 1, 2023
CVE-2022-34403
7.5

This vulnerability allows a local authenticated attacker to execute arbitrary code in SMRAM (System Management RAM) by exploiting a stack-based buffer...

Feb 1, 2023
CVE-2022-28772
7.5

CVE-2022-28772 is a stack-based buffer overflow vulnerability in SAP Web Dispatcher and Internet Communication Manager. Attackers can send overlong in...

Apr 12, 2022
CVE-2022-22178
7.5

A stack-based buffer overflow in Juniper's flow processing daemon (flowd) allows unauthenticated attackers to cause denial of service by sending speci...

Jan 19, 2022
CVE-2021-31383
7.5

A stack-based buffer overflow vulnerability in Juniper's routing protocol daemon (RPD) allows remote unauthenticated attackers to crash the RPD servic...

Oct 19, 2021
CVE-2020-7837
7.5

This is a stack-based buffer overflow vulnerability in Infraware ML Report Program's MLReportDeamon.exe. Attackers can exploit it by sending specially...

Dec 16, 2020
CVE-2019-10954
7.5

This vulnerability allows an attacker to send specially crafted SMTP packets to Rockwell Automation CompactLogix and Compact GuardLogix controllers, c...

May 1, 2019
CVE-2026-25967
7.4

This vulnerability is a stack-based buffer overflow in ImageMagick's FTXT image reader, allowing crafted FTXT files to cause out-of-bounds writes on t...

Feb 24, 2026
CVE-2025-8477
7.4

A stack-based buffer overflow vulnerability in Alpine iLX-507's vCard parsing allows network-adjacent attackers to execute arbitrary code as root when...

Aug 1, 2025
CVE-2025-8472
7.4

A stack-based buffer overflow vulnerability in Alpine iLX-507 devices allows network-adjacent attackers to execute arbitrary code as root when parsing...

Aug 1, 2025
CVE-2025-8475
7.4

A stack-based buffer overflow vulnerability in the AVRCP Bluetooth protocol implementation of Alpine iLX-507 devices allows network-adjacent attackers...

Aug 1, 2025
CVE-2025-52539
7.3

A buffer overflow vulnerability in Xilinx Run Time Environment allows local attackers to read or corrupt data from the advanced extensible interface (...

Nov 24, 2025
CVE-2025-11918
7.3

Rockwell Automation Arena® has a stack-based buffer overflow vulnerability in DOE file parsing. Local attackers can exploit this by opening malicious...

Nov 14, 2025
CVE-2025-58298
7.3

A stack-based buffer overflow vulnerability (CWE-121) in Huawei's package management module allows attackers to cause denial of service by sending spe...

Oct 11, 2025
CVE-2025-55503
7.3

This CVE describes a stack overflow vulnerability in Tenda AC6 routers that allows attackers to execute arbitrary code by sending specially crafted re...

Aug 20, 2025
CVE-2025-40596
7.3

A stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attackers to cause denial of service or ...

Jul 23, 2025
CVE-2025-50528
7.3

A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code or crash the device by sending specially crafted reque...

Jun 27, 2025
CVE-2025-28032
7.3

This CVE describes a pre-authentication buffer overflow vulnerability in multiple TOTOLINK router models. Attackers can exploit this by sending specia...

Apr 22, 2025
CVE-2024-44386
7.3

A buffer overflow vulnerability in Tenda FH1206 routers allows attackers to execute arbitrary code by sending specially crafted requests to the fromSe...

Aug 23, 2024
CVE-2024-33211
7.3

CVE-2024-33211 is a stack-based buffer overflow vulnerability in Tenda FH1206 routers that allows remote attackers to execute arbitrary code by sendin...

Apr 23, 2024
CVE-2019-1185
7.3

CVE-2019-1185 is a stack corruption vulnerability in Windows Subsystem for Linux that allows local attackers to execute arbitrary code with elevated p...

Aug 14, 2019
CVE-2025-66635
7.2

A stack-based buffer overflow vulnerability in SEIKO EPSON Web Config allows authenticated users to execute arbitrary code by sending specially crafte...

Dec 16, 2025
CVE-2025-1547
7.2

A stack-based buffer overflow vulnerability in WatchGuard Fireware OS allows authenticated privileged users to execute arbitrary code via specially cr...

Dec 4, 2025
CVE-2025-8076
7.2

A stack buffer overflow vulnerability in Supermicro BMC web interface allows authenticated attackers to execute arbitrary code on affected servers. Th...

Nov 18, 2025
CVE-2025-8727
7.2

A stack buffer overflow vulnerability in Supermicro BMC web interface allows authenticated attackers to execute arbitrary code on the Baseboard Manage...

Nov 18, 2025
CVE-2024-12803
7.2

A post-authentication stack-based buffer overflow vulnerability in SonicOS management interface allows authenticated attackers to crash firewalls and ...

Jan 9, 2025
CVE-2024-52547
7.2

An authenticated attacker can exploit a stack-based buffer overflow in the DHIP Service on TCP port 80 of affected Lorex security cameras. This could ...

Dec 3, 2024
CVE-2023-50243
7.2

Two stack-based buffer overflow vulnerabilities in Realtek rtl819x Jungle SDK's boa formIpQoS functionality allow remote code execution via specially ...

Jul 8, 2024
CVE-2023-50330
7.2

A stack-based buffer overflow vulnerability in Realtek rtl819x Jungle SDK's boa getInfo functionality allows remote attackers to execute arbitrary cod...

Jul 8, 2024
CVE-2023-49595
7.2

A stack-based buffer overflow vulnerability in Realtek rtl819x Jungle SDK's boa rollback_control_code function allows remote attackers to execute arbi...

Jul 8, 2024
CVE-2023-50239
7.2

Two stack-based buffer overflow vulnerabilities in Realtek rtl819x Jungle SDK's boa set_RadvdInterfaceParam functionality allow remote code execution ...

Jul 8, 2024
CVE-2023-47856
7.2

This CVE describes a stack-based buffer overflow vulnerability in Realtek's Jungle SDK that allows remote code execution. Attackers can exploit it by ...

Jul 8, 2024
CVE-2023-49073
7.2

A stack-based buffer overflow vulnerability in Realtek rtl819x Jungle SDK's boa formFilter functionality allows remote attackers to execute arbitrary ...

Jul 8, 2024
CVE-2023-45215
7.2

A stack-based buffer overflow vulnerability in Realtek rtl819x Jungle SDK's boa setRepeaterSsid function allows remote attackers to execute arbitrary ...

Jul 8, 2024
CVE-2024-31163
7.2

ASUS Download Master has a buffer overflow vulnerability that allows unauthenticated remote attackers with administrative privileges to execute arbitr...

Jun 14, 2024
CVE-2024-3079
7.2

This CVE describes a buffer overflow vulnerability in certain ASUS router models that allows remote attackers with administrative privileges to execut...

Jun 14, 2024
CVE-2023-46714
7.2

A stack-based buffer overflow vulnerability in Fortinet FortiOS allows authenticated administrative users to execute arbitrary code or commands via cr...

May 14, 2024
CVE-2023-49909
7.2

A stack-based buffer overflow vulnerability in TP-Link EAP225 access points allows authenticated attackers to execute arbitrary code remotely via spec...

Apr 9, 2024
CVE-2023-49911
7.2

A stack-based buffer overflow vulnerability in TP-Link EAP225 v3 access points allows authenticated attackers to execute arbitrary code remotely via s...

Apr 9, 2024
CVE-2023-49913
7.2

A stack-based buffer overflow vulnerability in TP-Link EAP225/EAP115 access points allows authenticated attackers to execute arbitrary code via specia...

Apr 9, 2024
CVE-2023-49907
7.2

A stack-based buffer overflow vulnerability in the TP-Link EAP225 v3 access point's web interface allows authenticated attackers to execute arbitrary ...

Apr 9, 2024
CVE-2023-48725
7.2

This CVE describes a stack-based buffer overflow vulnerability in Netgear RAX30 routers' JSON parsing functionality. An authenticated attacker can sen...

Mar 7, 2024
CVE-2024-1004
7.2

A critical stack-based buffer overflow vulnerability exists in the Totolink N200RE router's loginAuth function via the http_host parameter. This allow...

Jan 29, 2024
CVE-2024-1002
7.2

A critical stack-based buffer overflow vulnerability exists in Totolink N200RE routers running firmware version 9.3.5u.6139_B20201216. Attackers can r...

Jan 29, 2024
CVE-2024-1000
7.2

A critical stack-based buffer overflow vulnerability in the Totolink N200RE router's web interface allows remote attackers to execute arbitrary code b...

Jan 29, 2024
CVE-2024-0998
7.2

A critical stack-based buffer overflow vulnerability exists in Totolink N200RE routers running firmware version 9.3.5u.6139_B20201216. Attackers can r...

Jan 29, 2024

About CWE-121 (CWE-121)

Our database tracks 1,014 CVEs classified as CWE-121, with 191 rated critical and 697 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free