CWE-121: CWE-121

1,015
Total CVEs
192
Critical
697
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,015)

CVE-2024-0998
7.2

A critical stack-based buffer overflow vulnerability exists in Totolink N200RE routers running firmware version 9.3.5u.6139_B20201216. Attackers can r...

Jan 29, 2024
CVE-2024-0996
7.2

A critical stack-based buffer overflow vulnerability in Tenda i9 routers allows remote attackers to execute arbitrary code by sending specially crafte...

Jan 29, 2024
CVE-2024-0994
7.2

A critical stack-based buffer overflow vulnerability exists in Tenda W6 routers running firmware version 1.0.0.9(4122). Attackers can remotely exploit...

Jan 29, 2024
CVE-2024-0990
7.2

A critical stack-based buffer overflow vulnerability in Tenda i6 routers allows remote attackers to execute arbitrary code by sending specially crafte...

Jan 29, 2024
CVE-2024-0992
7.2

A critical stack-based buffer overflow vulnerability exists in Tenda i6 routers version 1.0.0.9(3857). Remote attackers can exploit this via the HTTP ...

Jan 29, 2024
CVE-2024-0534
7.2

A critical stack-based buffer overflow vulnerability in Tenda A15 routers allows remote attackers to execute arbitrary code by manipulating the 'mac' ...

Jan 15, 2024
CVE-2024-0531
7.2

This critical vulnerability in Tenda A15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the web manage...

Jan 15, 2024
CVE-2023-25118
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25120
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25122
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25124
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25104
7.2

This vulnerability allows authenticated attackers to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that...

Jul 6, 2023
CVE-2023-25106
7.2

Multiple buffer overflow vulnerabilities in the vtysh_ubus binary of Milesight UR32L routers allow arbitrary code execution via specially crafted HTTP...

Jul 6, 2023
CVE-2023-25108
7.2

This vulnerability allows authenticated attackers to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that...

Jul 6, 2023
CVE-2023-25110
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25112
7.2

This vulnerability allows authenticated attackers to execute arbitrary code on Milesight UR32L routers by exploiting buffer overflows in the vtysh_ubu...

Jul 6, 2023
CVE-2023-25114
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25116
7.2

Multiple buffer overflow vulnerabilities in the vtysh_ubus binary of Milesight UR32L routers allow arbitrary code execution via specially crafted HTTP...

Jul 6, 2023
CVE-2023-25090
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25092
7.2

This CVE describes multiple buffer overflow vulnerabilities in the vtysh_ubus binary of Milesight UR32L routers, caused by unsafe sprintf usage. Attac...

Jul 6, 2023
CVE-2023-25094
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25096
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25098
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25100
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25102
7.2

This vulnerability allows attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP reques...

Jul 6, 2023
CVE-2023-25082
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25084
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25086
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-25088
7.2

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially craft...

Jul 6, 2023
CVE-2023-28703
7.2

A stack-based buffer overflow vulnerability in ASUS RT-AC86U routers allows remote attackers with administrator privileges to execute arbitrary system...

Jun 2, 2023
CVE-2023-27498
7.2

CVE-2023-27498 is a memory corruption vulnerability in SAP Host Agent (SAPOSCOL) version 7.22 that allows unauthenticated attackers with network acces...

Mar 14, 2023
CVE-2021-36347
7.2

This CVE describes a stack-based buffer overflow vulnerability in Dell iDRAC9 and iDRAC8 remote management controllers. An authenticated attacker with...

Jan 25, 2022
CVE-2021-21905
7.2

This CVE describes a stack-based buffer overflow in the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0, allowing authentic...

Dec 22, 2021
CVE-2021-44165
7.2

A buffer overflow vulnerability in the web application of Siemens SICAM Q100 power meters allows remote attackers with engineer or admin privileges to...

Dec 14, 2021
CVE-2021-25478
7.2

This vulnerability allows attackers to execute arbitrary code on Samsung devices with Exynos CP chipsets by exploiting a stack-based buffer overflow. ...

Oct 6, 2021
CVE-2021-33547
7.2

This vulnerability allows remote attackers to execute arbitrary code on affected IP cameras by exploiting a stack-based buffer overflow in the profile...

Sep 13, 2021
CVE-2021-33549
7.2

This vulnerability allows remote attackers to execute arbitrary code on affected IP cameras via a stack-based buffer overflow in the action parameter....

Sep 13, 2021
CVE-2021-33545
7.2

This vulnerability affects multiple IP camera devices from UDP Technology, Geutebrück, and other vendors. It allows remote attackers to execute arbit...

Sep 13, 2021
CVE-2021-1340
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1342
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Feb 4, 2021
CVE-2021-1344
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1346
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Feb 4, 2021
CVE-2021-1348
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1328
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1330
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1332
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Feb 4, 2021
CVE-2021-1334
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Feb 4, 2021
CVE-2021-1336
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1338
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1320
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021

About CWE-121 (CWE-121)

Our database tracks 1,015 CVEs classified as CWE-121, with 192 rated critical and 697 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free